Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
9bbe16b6 by Salvatore Bonaccorso at 2026-09-21T05:45:36+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -7205,11 +7205,11 @@ CVE-2026-76551 (The WP Import Export Lite WordPress 
plugin before 3.9.33 does no
 CVE-2026-76550 (The WP Import Export Lite WordPress plugin before 3.9.34 does 
not vali ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-76420 (A vulnerability in the internal configuration of the Apache 
JServ Prot ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-76187 (Apache Airflow Keycloak provider: the unauthenticated token 
endpoint a ...)
-       TODO: check
+       NOT-FOR-US: Apache Airflow Keycloak provider
 CVE-2026-76186 (Apache Airflow Keycloak provider: from Airflow 3.3 the 
Keycloak auth m ...)
-       TODO: check
+       NOT-FOR-US: Apache Airflow Keycloak provider
 CVE-2026-76151 (Out-of-bounds read (buffer over-read) in the HTTP 
Cache-Control respon ...)
        TODO: check
 CVE-2026-76104 (Dell ObjectScale, versions prior to 4.4.0.0, contains an 
Incorrect Per ...)
@@ -7415,15 +7415,15 @@ CVE-2026-69202 (Http4s is a Scala interface for HTTP 
services. Prior to 0.23.35
 CVE-2026-69201 (Http4s is a Scala interface for HTTP services. Prior to 
0.23.35 and 1. ...)
        NOT-FOR-US: Http4s
 CVE-2026-69200 (node-opcua is an OPC UA implementation for TypeScript and 
Node.js. Pri ...)
-       TODO: check
+       NOT-FOR-US: node-opcua/node-opcua
 CVE-2026-69147 (vLLM is an inference and serving engine for large language 
models. Pri ...)
        - vllm <itp> (bug #1095237)
 CVE-2026-68953 (The affected products are vulnerable to an authentication 
bypass that  ...)
-       TODO: check
+       NOT-FOR-US: Watchdog
 CVE-2026-68950 (The affected products use hard-coded credentials, which could 
allow an ...)
-       TODO: check
+       NOT-FOR-US: Watchdog
 CVE-2026-68904 (node-opcua is an OPC UA implementation for TypeScript and 
Node.js. Fro ...)
-       TODO: check
+       NOT-FOR-US: node-opcua/node-opcua
 CVE-2026-68536 (Server-Side Request Forgery / Local File Inclusion in Apache 
MyFace Co ...)
        TODO: check
 CVE-2026-68531 (Concrete CMS 9 before 9.5.3 did not escape SQL LIKE wildcard 
character ...)
@@ -7433,19 +7433,19 @@ CVE-2026-68530 (Concrete CMS 9 through 9.5.2 did not 
perform an authorization ch
 CVE-2026-68529 (Concrete CMS 9.0.0 through 9.5.2 was missing an authorization 
check on ...)
        NOT-FOR-US: Concrete CMS
 CVE-2026-68491 (An insufficient check allowed for the overwrite of arbitrary 
files via ...)
-       TODO: check
+       NOT-FOR-US: SolusVM
 CVE-2026-68070 (The affected products are missing authentication for a 
critical functi ...)
-       TODO: check
+       NOT-FOR-US: Watchdog
 CVE-2026-66890 (The affected products use hard-coded credentials, which could 
allow re ...)
-       TODO: check
+       NOT-FOR-US: Watchdog
 CVE-2026-66887 (The affected products are missing authorization on 
state-changing CGIs ...)
-       TODO: check
+       NOT-FOR-US: Watchdog
 CVE-2026-66790
        REJECTED
 CVE-2026-66789
        REJECTED
 CVE-2026-66372 (The affected products use insufficiently random values, which 
allows w ...)
-       TODO: check
+       NOT-FOR-US: Watchdog
 CVE-2026-63671 (MDC is a tool to take regular Markdown and write documents 
interacting ...)
        TODO: check
 CVE-2026-63128 (RMCP is an official Rust SDK for the Model Context Protocol. 
Prior to  ...)
@@ -7473,15 +7473,15 @@ CVE-2026-61560 (`@zereight/mcp-gitlab` is a Model 
Context Protocol server for Gi
 CVE-2026-61559 (`@zereight/mcp-gitlab` is a Model Context Protocol server for 
GitLab.  ...)
        NOT-FOR-US: zereight/mcp-gitlab
 CVE-2026-61554 (emp3r0r is a C2 designed by Linux users for Linux 
environments. Prior  ...)
-       TODO: check
+       NOT-FOR-US: emp3r0r
 CVE-2026-61544 (libp2p-rust is the official Rust language implementation of 
the libp2p ...)
-       TODO: check
+       NOT-FOR-US: libp2p-rust
 CVE-2026-61396
        REJECTED
 CVE-2026-5920 (The Bold Page Builder plugin for WordPress is vulnerable to 
Stored Cro ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-59974 (Stanza is a Stanford NLP Python library for tokenization, 
sentence seg ...)
-       TODO: check
+       NOT-FOR-US: Stanza
 CVE-2026-59969 (Apache ZooKeeper quorum TLS fails to enforce peer hostname 
verificatio ...)
        TODO: check
 CVE-2026-59823 (LiteLLM is a proxy server (AI Gateway) to call LLM APIs in 
OpenAI (or  ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9bbe16b6285176b0b73a7101c380e412d2abb437

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9bbe16b6285176b0b73a7101c380e412d2abb437
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to