Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
9bbe16b6 by Salvatore Bonaccorso at 2026-09-21T05:45:36+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -7205,11 +7205,11 @@ CVE-2026-76551 (The WP Import Export Lite WordPress
plugin before 3.9.33 does no
CVE-2026-76550 (The WP Import Export Lite WordPress plugin before 3.9.34 does
not vali ...)
NOT-FOR-US: WordPress plugin
CVE-2026-76420 (A vulnerability in the internal configuration of the Apache
JServ Prot ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-76187 (Apache Airflow Keycloak provider: the unauthenticated token
endpoint a ...)
- TODO: check
+ NOT-FOR-US: Apache Airflow Keycloak provider
CVE-2026-76186 (Apache Airflow Keycloak provider: from Airflow 3.3 the
Keycloak auth m ...)
- TODO: check
+ NOT-FOR-US: Apache Airflow Keycloak provider
CVE-2026-76151 (Out-of-bounds read (buffer over-read) in the HTTP
Cache-Control respon ...)
TODO: check
CVE-2026-76104 (Dell ObjectScale, versions prior to 4.4.0.0, contains an
Incorrect Per ...)
@@ -7415,15 +7415,15 @@ CVE-2026-69202 (Http4s is a Scala interface for HTTP
services. Prior to 0.23.35
CVE-2026-69201 (Http4s is a Scala interface for HTTP services. Prior to
0.23.35 and 1. ...)
NOT-FOR-US: Http4s
CVE-2026-69200 (node-opcua is an OPC UA implementation for TypeScript and
Node.js. Pri ...)
- TODO: check
+ NOT-FOR-US: node-opcua/node-opcua
CVE-2026-69147 (vLLM is an inference and serving engine for large language
models. Pri ...)
- vllm <itp> (bug #1095237)
CVE-2026-68953 (The affected products are vulnerable to an authentication
bypass that ...)
- TODO: check
+ NOT-FOR-US: Watchdog
CVE-2026-68950 (The affected products use hard-coded credentials, which could
allow an ...)
- TODO: check
+ NOT-FOR-US: Watchdog
CVE-2026-68904 (node-opcua is an OPC UA implementation for TypeScript and
Node.js. Fro ...)
- TODO: check
+ NOT-FOR-US: node-opcua/node-opcua
CVE-2026-68536 (Server-Side Request Forgery / Local File Inclusion in Apache
MyFace Co ...)
TODO: check
CVE-2026-68531 (Concrete CMS 9 before 9.5.3 did not escape SQL LIKE wildcard
character ...)
@@ -7433,19 +7433,19 @@ CVE-2026-68530 (Concrete CMS 9 through 9.5.2 did not
perform an authorization ch
CVE-2026-68529 (Concrete CMS 9.0.0 through 9.5.2 was missing an authorization
check on ...)
NOT-FOR-US: Concrete CMS
CVE-2026-68491 (An insufficient check allowed for the overwrite of arbitrary
files via ...)
- TODO: check
+ NOT-FOR-US: SolusVM
CVE-2026-68070 (The affected products are missing authentication for a
critical functi ...)
- TODO: check
+ NOT-FOR-US: Watchdog
CVE-2026-66890 (The affected products use hard-coded credentials, which could
allow re ...)
- TODO: check
+ NOT-FOR-US: Watchdog
CVE-2026-66887 (The affected products are missing authorization on
state-changing CGIs ...)
- TODO: check
+ NOT-FOR-US: Watchdog
CVE-2026-66790
REJECTED
CVE-2026-66789
REJECTED
CVE-2026-66372 (The affected products use insufficiently random values, which
allows w ...)
- TODO: check
+ NOT-FOR-US: Watchdog
CVE-2026-63671 (MDC is a tool to take regular Markdown and write documents
interacting ...)
TODO: check
CVE-2026-63128 (RMCP is an official Rust SDK for the Model Context Protocol.
Prior to ...)
@@ -7473,15 +7473,15 @@ CVE-2026-61560 (`@zereight/mcp-gitlab` is a Model
Context Protocol server for Gi
CVE-2026-61559 (`@zereight/mcp-gitlab` is a Model Context Protocol server for
GitLab. ...)
NOT-FOR-US: zereight/mcp-gitlab
CVE-2026-61554 (emp3r0r is a C2 designed by Linux users for Linux
environments. Prior ...)
- TODO: check
+ NOT-FOR-US: emp3r0r
CVE-2026-61544 (libp2p-rust is the official Rust language implementation of
the libp2p ...)
- TODO: check
+ NOT-FOR-US: libp2p-rust
CVE-2026-61396
REJECTED
CVE-2026-5920 (The Bold Page Builder plugin for WordPress is vulnerable to
Stored Cro ...)
NOT-FOR-US: WordPress plugin
CVE-2026-59974 (Stanza is a Stanford NLP Python library for tokenization,
sentence seg ...)
- TODO: check
+ NOT-FOR-US: Stanza
CVE-2026-59969 (Apache ZooKeeper quorum TLS fails to enforce peer hostname
verificatio ...)
TODO: check
CVE-2026-59823 (LiteLLM is a proxy server (AI Gateway) to call LLM APIs in
OpenAI (or ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9bbe16b6285176b0b73a7101c380e412d2abb437
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9bbe16b6285176b0b73a7101c380e412d2abb437
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits