Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
5c7e300b by Salvatore Bonaccorso at 2026-09-26T10:05:01+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -15,7 +15,7 @@ CVE-2026-96876 (Improper neutralization of input during web 
page generation ('cr
 CVE-2026-96875 (Improper neutralization of input during web page generation 
('cross-si ...)
        TODO: check
 CVE-2026-96795 (Horilla is an HR and CRM software. Prior to 2.0.0, 
HorillaListView.exp ...)
-       TODO: check
+       NOT-FOR-US: Horilla
 CVE-2026-96533 (The Testimonials Widget WordPress plugin through 4.0.4 does 
not valida ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-96532 (The Testimonials Widget WordPress plugin through 4.0.4 does 
not perfor ...)
@@ -33,9 +33,9 @@ CVE-2026-92411 (The WP Delicious  WordPress plugin before 
1.10.8 does not valida
 CVE-2026-89237 (The Bluff Post WordPress plugin through 1.1.1 does not 
sanitise and es ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-88003 (InvoicePlane is a self-hosted open source application for 
managing inv ...)
-       TODO: check
+       NOT-FOR-US: InvoicePlane
 CVE-2026-86066 (Horilla is an HR and CRM software. Prior to 2.0.0, 
approve_validate_at ...)
-       TODO: check
+       NOT-FOR-US: Horilla
 CVE-2026-85081 (The File Manager WordPress plugin before 8.0.5, FileOrganizer  
WordPre ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-84097 (The wp-review-slider-pro WordPress plugin before 12.7.12 does 
not sani ...)
@@ -49,11 +49,11 @@ CVE-2026-7800
 CVE-2026-7799
        REJECTED
 CVE-2026-71483 (Horilla is an HR and CRM software. Prior to 1.6.0, the search 
paramete ...)
-       TODO: check
+       NOT-FOR-US: Horilla
 CVE-2026-63432 (Horilla is an HR and CRM software. From 1.0.0 until 1.6.0 and 
2.0.0, t ...)
-       TODO: check
+       NOT-FOR-US: Horilla
 CVE-2026-63431 (Horilla is an HR and CRM software. In 1.5.0-85 and earlier, 
payroll/vi ...)
-       TODO: check
+       NOT-FOR-US: Horilla
 CVE-2026-5267 (Ciena Navigator Network Control Suite (NCS) contains an 
information ex ...)
        TODO: check
 CVE-2026-57864
@@ -61,7 +61,7 @@ CVE-2026-57864
 CVE-2026-57861
        REJECTED
 CVE-2026-57449 (Actual is a local-first personal finance tool. Prior to 
26.7.0, Actual ...)
-       TODO: check
+       NOT-FOR-US: Actual
 CVE-2026-57443 (SCBE-AETHERMOORE is a geometric AI governance and evaluation 
framework ...)
        TODO: check
 CVE-2026-53990
@@ -463,7 +463,7 @@ CVE-2026-95699 (Prior to 9/18/2026, the iSteamX mobile 
application's AWS policy
 CVE-2026-94573 (The Repeater Fields for Elementor Forms plugin for WordPress 
is vulner ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-94445 (A malicious txtar could escape the intended execution context 
and forc ...)
-       TODO: check
+       NOT-FOR-US: golang.org/x/playground
 CVE-2026-94376 (The Better Messages \u2013 Chat Rooms, Group Chat, Private 
Messages &  ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-93901 (The Optima Express IDX plugin for WordPress is vulnerable to 
Privilege ...)
@@ -512,7 +512,7 @@ CVE-2026-93306 (IBM Server Firmware FW1120.00 through 
FW1120.01, FW1110.00 throu
 CVE-2026-93303 (The HT Contact Form \u2013 Drag & Drop Form Builder for 
WordPress plug ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-93291 (Omni C20 lacks proper certificate validation which could allow 
an atta ...)
-       TODO: check
+       NOT-FOR-US: Omni C20
 CVE-2026-93290 (Omni C20 uses hard-coded credentials that could allow an 
attacker to m ...)
        NOT-FOR-US: Omni C20
 CVE-2026-93289 (The affected products are vulnerable to command injection 
attack that  ...)
@@ -573,7 +573,7 @@ CVE-2026-87721 (Uncontrolled Resource Consumption (CWE-400 
/ CWE-407) in the ANT
 CVE-2026-87720 (Incorrect Authorization (CWE-863) in project name 
normalization (Proje ...)
        TODO: check
 CVE-2026-87118 (The Botslab G980H dash camera firmware contains an out of 
bounds write ...)
-       TODO: check
+       NOT-FOR-US: Botslab G980H dash camera firmware
 CVE-2026-86837 (The Bookly WordPress plugin before 28.3 does not properly 
verify a cus ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-85750 (Piwigo before v16.4.0 is vulnerable to arbitrary file read and 
remote  ...)
@@ -585,19 +585,19 @@ CVE-2026-85496 (The Botslab G980H dash camera firmware 
generates session identif
 CVE-2026-85417 (Incomplete property masking in the SANnav logging subsystem 
permits SN ...)
        NOT-FOR-US: Brocade
 CVE-2026-85293 (InvoicePlane is a self-hosted open source application for 
managing inv ...)
-       TODO: check
+       NOT-FOR-US: Botslab G980H dash camera firmware
 CVE-2026-85292 (InvoicePlane is a self-hosted open source application for 
managing inv ...)
-       TODO: check
+       NOT-FOR-US: InvoicePlane
 CVE-2026-85291 (InvoicePlane is a self-hosted open source application for 
managing inv ...)
-       TODO: check
+       NOT-FOR-US: InvoicePlane
 CVE-2026-85290 (InvoicePlane is a self-hosted open source application for 
managing inv ...)
-       TODO: check
+       NOT-FOR-US: InvoicePlane
 CVE-2026-85289 (InvoicePlane is a self-hosted open source application for 
managing inv ...)
-       TODO: check
+       NOT-FOR-US: InvoicePlane
 CVE-2026-85274 (InvoicePlane is a self-hosted open source application for 
managing inv ...)
-       TODO: check
+       NOT-FOR-US: InvoicePlane
 CVE-2026-85082 (Root Browser Classic 3.3.0 passes the path of a selected 
SQLite databa ...)
-       TODO: check
+       NOT-FOR-US: Root Browser Classic
 CVE-2026-85029 (IBM Guardium Data Protection 12.2 could allow a remote 
attacker to obt ...)
        NOT-FOR-US: IBM
 CVE-2026-84893 (IBM Guardium Data Protection 12.2 is vulnerable to SQL 
injection in th ...)
@@ -623,11 +623,11 @@ CVE-2026-84460 (Zammad is a web based open source 
helpdesk/customer support syst
 CVE-2026-84458 (Zammad is a web based open source helpdesk/customer support 
system. Pr ...)
        - zammad <itp> (bug #841355)
 CVE-2026-84403 (The Botslab G980H dash camera firmware does not require 
authenticated  ...)
-       TODO: check
+       NOT-FOR-US: Botslab G980H dash camera firmware
 CVE-2026-84399 (The Botslab G980H dash camera firmware contains an 
authorization vulne ...)
-       TODO: check
+       NOT-FOR-US: Botslab G980H dash camera firmware
 CVE-2026-84283 (Secure Folder 1.2 stores files selected for its 
password-protected vau ...)
-       TODO: check
+       NOT-FOR-US: Secure Folder
 CVE-2026-84281 (The Fancy Product Designer plugin for WordPress is vulnerable 
to Store ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-84280 (The Fancy Product Designer plugin for WordPress is vulnerable 
to Store ...)
@@ -637,19 +637,19 @@ CVE-2026-84279 (The Fancy Product Designer plugin for 
WordPress is vulnerable to
 CVE-2026-83591 (The AMP for WP \u2013 Accelerated Mobile Pages plugin for 
WordPress is ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-82716 (The Botslab G980H dash camera firmware includes sensitive 
configuratio ...)
-       TODO: check
+       NOT-FOR-US: Botslab G980H dash camera firmware
 CVE-2026-82708 (The Botslab G980H dash camera firmware contains a path 
traversal vulne ...)
-       TODO: check
+       NOT-FOR-US: Botslab G980H dash camera firmware
 CVE-2026-82585 (The Botslab G980H dash camera firmware transmits sensitive 
information ...)
-       TODO: check
+       NOT-FOR-US: Botslab G980H dash camera firmware
 CVE-2026-82566 (The Botslab G980H dash camera firmware contains a session 
management v ...)
-       TODO: check
+       NOT-FOR-US: Botslab G980H dash camera firmware
 CVE-2026-82372 (Improper handling of sensitive data during IPsec policy 
creation and m ...)
        NOT-FOR-US: Brocade
 CVE-2026-82164 (Dell Trusted Device Client, versions prior to 8.1.359.0, 
contain an In ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-81630 (The Botslab G980H dash camera firmware does not adequately 
verify the  ...)
-       TODO: check
+       NOT-FOR-US: Botslab G980H dash camera firmware
 CVE-2026-80514 (The wpForo Forum WordPress plugin from 3.0.0 before 3.1.6 does 
not ver ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-80432 (Missing Authorization in the drop handling path of the drag 
and drop p ...)
@@ -659,11 +659,11 @@ CVE-2026-80431 (Out-of-bounds Write in the natural width 
branch of the text sizi
 CVE-2026-80430 (Improper Link Resolution Before File Access in the drag source 
staging ...)
        TODO: check
 CVE-2026-79959 (The Botslab G980H dash camera firmware contains a hard-coded 
root acco ...)
-       TODO: check
+       NOT-FOR-US: Botslab G980H dash camera firmware
 CVE-2026-79153 (Seclore FileSecure Desktop Client before 3.25.1.0 contains 
improper ac ...)
-       TODO: check
+       NOT-FOR-US: Seclore FileSecure Desktop Client
 CVE-2026-78902 (Cross Site Scripting vulnerability in Netgate pfSense 
26.03.1-RELEASE  ...)
-       TODO: check
+       NOT-FOR-US: Netgate pfSense
 CVE-2026-78397 (The Link Library WordPress plugin before 7.9.6 does not 
validate the d ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-78394 (The Link Library WordPress plugin before 7.9.6 does not 
sanitize a use ...)
@@ -671,25 +671,25 @@ CVE-2026-78394 (The Link Library WordPress plugin before 
7.9.6 does not sanitize
 CVE-2026-78393 (The Link Library WordPress plugin before 7.9.6 does not 
properly escap ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-77967 (The Botslab G980H dash camera firmware accepts a reusable 
authenticati ...)
-       TODO: check
+       NOT-FOR-US: Botslab G980H dash camera firmware
 CVE-2026-75558 (The Botslab G980H dash camera firmware uses a hard-coded 
cryptographic ...)
-       TODO: check
+       NOT-FOR-US: Botslab G980H dash camera firmware
 CVE-2026-75553 (Smartphone application Tohoku Electric Power "Yorisou e Net" 
uses a ha ...)
-       TODO: check
+       NOT-FOR-US: Smartphone application Tohoku Electric Power "Yorisou e Net"
 CVE-2026-6088 (Stored Cross-Site Scripting (XSS) vulnerability in StockAgile 
API and  ...)
-       TODO: check
+       NOT-FOR-US: StockAgile
 CVE-2026-6087 (Stored Cross-Site Scripting (XSS) vulnerability in StockAgile 
API and  ...)
-       TODO: check
+       NOT-FOR-US: StockAgile
 CVE-2026-6086 (Stored Cross-Site Scripting (XSS) vulnerability in StockAgile 
API and  ...)
-       TODO: check
+       NOT-FOR-US: StockAgile
 CVE-2026-6085 (Stored Cross-Site Scripting (XSS) vulnerability in StockAgile 
API and  ...)
-       TODO: check
+       NOT-FOR-US: StockAgile
 CVE-2026-6084 (Stored Cross-Site Scripting (XSS) vulnerability in StockAgile 
API and  ...)
-       TODO: check
+       NOT-FOR-US: StockAgile
 CVE-2026-6083 (Stored Cross-Site Scripting (XSS) vulnerability in StockAgile 
API and  ...)
-       TODO: check
+       NOT-FOR-US: StockAgile
 CVE-2026-6082 (Stored Cross-Site Scripting (XSS) vulnerability in StockAgile 
API and  ...)
-       TODO: check
+       NOT-FOR-US: StockAgile
 CVE-2026-67421 (RabbitMQ is a messaging and streaming broker. From 3.13.0 
until 3.13.1 ...)
        - rabbitmq-server <unfixed>
        NOTE: 
https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-6256-27fm-4rgr
@@ -2776,7 +2776,7 @@ CVE-2026-6544 (IBM Concert 1.0.0 through 3.0.0 allows 
recursive copying of direc
 CVE-2026-67233 (RabbitMQ is a messaging and streaming broker. Prior to 
versions 3.13.1 ...)
        TODO: check
 CVE-2026-65827 (Docmost is open-source collaborative wiki and documentation 
software.  ...)
-       TODO: check
+       NOT-FOR-US: Docmost
 CVE-2026-65422 (A flaw in the authorization mechanism for Media Gateway API in 
Genetec ...)
        NOT-FOR-US: Genetec
 CVE-2026-63645 (OpenObserve is a cloud-native observability platform. Prior to 
0.90.3, ...)
@@ -2788,35 +2788,35 @@ CVE-2026-63498 (Snipe-IT is an IT asset/license 
management system. Prior to 8.7.
 CVE-2026-63493 (Snipe-IT is an IT asset/license management system. Prior to 
8.7.0, a p ...)
        - snipe-it <itp> (bug #1005172)
 CVE-2026-63203 (Logto is the modern, open-source auth infrastructure for SaaS 
and AI a ...)
-       TODO: check
+       NOT-FOR-US: Logto
 CVE-2026-62368 (Snipe-IT is an IT asset/license management system. Prior to 
8.7.0, a u ...)
        - snipe-it <itp> (bug #1005172)
 CVE-2026-62286 (Dozzle is a realtime log viewer for docker containers. Prior 
to 10.6.7 ...)
-       TODO: check
+       NOT-FOR-US: Dozzle
 CVE-2026-61825 (code16 Sharp is a Laravel-based framework for building 
content-managem ...)
-       TODO: check
+       NOT-FOR-US: code16 Sharp
 CVE-2026-61823 (code16 Sharp is a Laravel-based framework for building 
content-managem ...)
-       TODO: check
+       NOT-FOR-US: code16 Sharp
 CVE-2026-61816 (zbateson/mail-mime-parser is a mail mime parser alternative to 
PHP's i ...)
-       TODO: check
+       NOT-FOR-US: zbateson/mail-mime-parser
 CVE-2026-61815 (zbateson/mail-mime-parser is a mail mime parser alternative to 
PHP's i ...)
-       TODO: check
+       NOT-FOR-US: zbateson/mail-mime-parser
 CVE-2026-61811 (Wazuh is an open-source security platform providing unified 
XDR and SI ...)
        NOT-FOR-US: Wazuh
 CVE-2026-61788 (DBHub is a database MCP server for Postgres, MySQL, SQL 
Server, Oracle ...)
-       TODO: check
+       NOT-FOR-US: DBHub
 CVE-2026-61784 (xhtml-purifier is a Node.js library to take in 
raw/unknown/untrusted H ...)
-       TODO: check
+       NOT-FOR-US: xhtml-purifier Node.js module
 CVE-2026-61782 (Rsdoctor is a build analyzer tailored for projects built with 
Rspack.  ...)
-       TODO: check
+       NOT-FOR-US: Rsdoctor
 CVE-2026-61742 (DBHub is a database MCP server for Postgres, MySQL, SQL 
Server, Oracle ...)
-       TODO: check
+       NOT-FOR-US: DBHub
 CVE-2026-61741 (http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` 
instances ...)
-       TODO: check
+       NOT-FOR-US: http4s-scala-xml
 CVE-2026-61732 (Decepticon is an autonomous hacking agent for red teams. 
Versions prio ...)
-       TODO: check
+       NOT-FOR-US: Decepticon
 CVE-2026-61604 (The ixo Blockchain is a Layer 1 blockchain that runs on both 
Testnet a ...)
-       TODO: check
+       NOT-FOR-US: ixo Blockchain
 CVE-2026-58008 (Stack-based buffer overflow vulnerability in Altera Trusted 
Firmware o ...)
        NOT-FOR-US: Altera
 CVE-2026-58007 (Untrusted pointer dereference vulnerability in Altera Trusted 
Firmware ...)
@@ -2830,7 +2830,7 @@ CVE-2026-58004 (Out-of-bounds read vulnerability in 
Altera Trusted Firmware on H
 CVE-2026-57590 (A missing authorization vulnerability exists in the Task Group 
APIs of ...)
        NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-57440 (The EmbedVideo Extension is a MediaWiki extension which adds a 
parser  ...)
-       TODO: check
+       NOT-FOR-US: SCBE-AETHERMOORE
 CVE-2026-57179 (Python Social Auth is a social authentication/registration 
mechanism.  ...)
        TODO: check
 CVE-2026-57178 (Python Social Auth is a social authentication/registration 
mechanism.  ...)
@@ -4629,25 +4629,32 @@ CVE-2026-63000 (REDAXO is a PHP-based content 
management system. Prior to 5.21.2
 CVE-2026-62998 (REDAXO is a PHP-based content management system. Prior to 
5.21.2, rex_ ...)
        NOT-FOR-US: REDAXO
 CVE-2026-61834 (scim-patch is a library for applying SCIM patch operations. 
Prior to 0 ...)
-       TODO: check
+       NOT-FOR-US: scim-patch
 CVE-2026-61814 (Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's 
AsyncParser ...)
-       TODO: check
+       - jawn <unfixed>
+       NOTE: 
https://github.com/typelevel/jawn/security/advisories/GHSA-w4cm-gvhj-cgw6
+       NOTE: Fixed by: 
https://github.com/typelevel/jawn/commit/cddcd5e3387c356b05953f7b2af103d309687e4b
 (v1.7.0)
 CVE-2026-61695 (Wire provides gRPC and protocol buffers for Android, Kotlin, 
Swift, an ...)
-       TODO: check
+       NOT-FOR-US: Wire
 CVE-2026-61413 (Dell Secure Connect Gateway (SCG) Policy Manager, versions 
prior to 5. ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-5696 (Reflected Cross-Site Scripting (XSS) in Microweber. The 
vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: Microweber. CMS
 CVE-2026-5695 (Arbitrary file upload vulnerability due to a lack of proper 
validation ...)
-       TODO: check
+       NOT-FOR-US: Microweber. CMS
 CVE-2026-59990 (Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse 
methods ...)
-       TODO: check
+       - jawn <unfixed>
+       NOTE: 
https://github.com/typelevel/jawn/security/advisories/GHSA-cc4v-rvgp-2pf3
+       NOTE: Fixed by: 
https://github.com/typelevel/jawn/commit/191cb3a44e77f1afab439ee636bf66bdf3c54a04
 (v1.7.0)
+       NOTE: Fixed by: 
https://github.com/typelevel/jawn/commit/6219666641f9408498f85868f835e17bd8a72fed
 (v1.7.0)
+       NOTE: Fxied by: 
https://github.com/typelevel/jawn/commit/93ac93e9c992c11b4c03d5455d8551f9fb24da1b
 (v1.7.0)
+       NOTE: Fixed by: 
https://github.com/typelevel/jawn/commit/f6ace7e0db715de1a8c4618bed9378333a5c2214
 (v1.7.0)
 CVE-2026-59980 (hpack is an HTTP/2 Header Encoding for Python. Prior to 
version 4.2.0, ...)
        - python-hpack <unfixed> (bug #1148944)
        NOTE: 
https://github.com/python-hyper/hpack/security/advisories/GHSA-8v8h-hg4w-mvq2
        NOTE: 
https://github.com/python-hyper/hpack/commit/8cfb02c547740e16dbfe7aba77bad84b297cec2c
 (v4.2.0)
 CVE-2026-59167 (SunEditor is a lightweight and powerful WYSIWYG editor in 
vanilla Java ...)
-       TODO: check
+       NOT-FOR-US: SunEditor
 CVE-2026-57854
        REJECTED
 CVE-2026-57168



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5c7e300b150a3b2c04c69500aaed91a59209565f

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5c7e300b150a3b2c04c69500aaed91a59209565f
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to