Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
5fa71c19 by Salvatore Bonaccorso at 2026-09-27T10:06:30+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -59,101 +59,101 @@ CVE-2026-72668 (Unintended Proxy or Intermediary 
('Confused Deputy') (CWE-441) i
 CVE-2026-72662 (Authorization Bypass Through User-Controlled Key (CWE-639) in 
Kibana c ...)
        NOT-FOR-US: Elastic
 CVE-2026-100865 (Heym before 0.0.53 contains multiple independent 
vulnerabilities. (1)  ...)
-       TODO: check
+       NOT-FOR-US: Heym
 CVE-2026-100864 (heym before 0.0.91 contains a sandbox escape vulnerability in 
the expr ...)
-       TODO: check
+       NOT-FOR-US: Heym
 CVE-2026-100863 (Heym versions 0.0.90 and earlier contain two server-side 
request forge ...)
-       TODO: check
+       NOT-FOR-US: Heym
 CVE-2026-100862 (heym, a workflow automation platform, stores and returns 
multiple capa ...)
-       TODO: check
+       NOT-FOR-US: Heym
 CVE-2026-100861 (heym before 0.0.105 fails to apply egress guards to 
integration servic ...)
-       TODO: check
+       NOT-FOR-US: Heym
 CVE-2026-100860 (heym before 0.0.105 does not act on the result of the 
credential autho ...)
-       TODO: check
+       NOT-FOR-US: Heym
 CVE-2026-100859 (Heym before 0.0.106 contains a credential exfiltration 
vulnerability i ...)
-       TODO: check
+       NOT-FOR-US: Heym
 CVE-2026-100858 (heym before 0.0.109 contains a server-side request forgery 
vulnerabili ...)
-       TODO: check
+       NOT-FOR-US: Heym
 CVE-2026-100857 (AzuraCast before 0.23.4 contains a code injection 
vulnerability in the ...)
-       TODO: check
+       NOT-FOR-US: AzuraCast
 CVE-2026-100856 (AzuraCast before 0.23.6 contains a code injection 
vulnerability in the ...)
-       TODO: check
+       NOT-FOR-US: AzuraCast
 CVE-2026-100855 (AzuraCast before 0.23.6 contains a missing permission check 
vulnerabil ...)
-       TODO: check
+       NOT-FOR-US: AzuraCast
 CVE-2026-100854 (AzuraCast before 0.23.6 lacks RequireInternalConnection 
middleware on  ...)
-       TODO: check
+       NOT-FOR-US: AzuraCast
 CVE-2026-100853 (In AzuraCast before 0.23.8, the public On-Demand download 
endpoint fai ...)
-       TODO: check
+       NOT-FOR-US: AzuraCast
 CVE-2026-100852 (AzuraCast through 0.23.x contains a command injection 
vulnerability in ...)
-       TODO: check
+       NOT-FOR-US: AzuraCast
 CVE-2026-100851 (AzuraCast before 0.23.8 contains a broken access control 
vulnerability ...)
-       TODO: check
+       NOT-FOR-US: AzuraCast
 CVE-2026-100850 (AzuraCast before 0.23.8 contains a server-side request 
forgery and loc ...)
-       TODO: check
+       NOT-FOR-US: AzuraCast
 CVE-2026-100849 (AzuraCast is a self-hosted web radio management suite. In 
AzuraCast be ...)
-       TODO: check
+       NOT-FOR-US: AzuraCast
 CVE-2026-100848 (AzuraCast (Composer package azuracast/azuracast) before 
0.23.8 validat ...)
-       TODO: check
+       NOT-FOR-US: AzuraCast
 CVE-2026-100847 (AzuraCast before 0.23.8 contains a DQL injection 
vulnerability in the  ...)
-       TODO: check
+       NOT-FOR-US: AzuraCast
 CVE-2026-100846 (MONAI before 1.5.2 contains a deserialization of untrusted 
data vulner ...)
-       TODO: check
+       NOT-FOR-US: MONAI
 CVE-2026-100845 (MONAI before 1.6.0 contains an unsafe deserialization 
vulnerability in ...)
-       TODO: check
+       NOT-FOR-US: MONAI
 CVE-2026-100844 (MONAI before 1.6.0 is vulnerable to OS command injection in 
the nnUNet ...)
-       TODO: check
+       NOT-FOR-US: MONAI
 CVE-2026-100843 (MONAI versions before 1.6.0 contain a remote code execution 
vulnerabil ...)
-       TODO: check
+       NOT-FOR-US: MONAI
 CVE-2026-100842 (MONAI through 1.6.0 contains an eval injection vulnerability 
in _get_f ...)
-       TODO: check
+       NOT-FOR-US: MONAI
 CVE-2026-100841 (In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) 
explicitly r ...)
-       TODO: check
+       NOT-FOR-US: MONAI
 CVE-2026-100840 (MONAI through 1.6.0 contains a remote code execution 
vulnerability in  ...)
-       TODO: check
+       NOT-FOR-US: MONAI
 CVE-2026-100839 (Contrast is a confidential-computing runtime for Kubernetes. 
In versio ...)
-       TODO: check
+       NOT-FOR-US: Contrast
 CVE-2026-100838 (Contrast is a confidential-computing runtime for Kubernetes. 
In versio ...)
-       TODO: check
+       NOT-FOR-US: Contrast
 CVE-2026-100837 (Contrast (Edgeless Systems) through 1.20.0 performs 
unanchored suffix  ...)
-       TODO: check
+       NOT-FOR-US: Contrast
 CVE-2026-100836 (Contrast through 1.20.0 contains a panic vulnerability in the 
transit- ...)
-       TODO: check
+       NOT-FOR-US: Contrast
 CVE-2026-100835 (Contrast before 1.16.0 is susceptible to remote attestation 
relay atta ...)
-       TODO: check
+       NOT-FOR-US: Contrast
 CVE-2026-100834 (http4k's Digest authentication module 
(org.http4k:http4k-security-dige ...)
-       TODO: check
+       NOT-FOR-US: http4k
 CVE-2026-100833 (Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 
generate ...)
-       TODO: check
+       NOT-FOR-US: Contrast
 CVE-2026-100746 (A vulnerability was found in coollabsio Coolify up to 4.1.0. 
This affe ...)
-       TODO: check
+       NOT-FOR-US: Coolify
 CVE-2026-100745 (A vulnerability has been found in Edimax BR-6428nC 1.16. The 
impacted  ...)
        NOT-FOR-US: Edimax
 CVE-2026-100744 (A flaw has been found in coollabsio Coolify up to 4.1.2. The 
affected  ...)
-       TODO: check
+       NOT-FOR-US: Coolify
 CVE-2026-100740 (A vulnerability was detected in D-Link DIR-895L A1_102b07. 
Impacted is ...)
        NOT-FOR-US: D-Link
 CVE-2026-100739 (A vulnerability was detected in mathurvishal 
CloudClassroom-PHP-Projec ...)
-       TODO: check
+       NOT-FOR-US: mathurvishal CloudClassroom-PHP-Project
 CVE-2026-100725 (http4k (Maven artifact org.http4k:http4k-core) before 
6.48.0.0, 5.42.0 ...)
-       TODO: check
+       NOT-FOR-US: http4k
 CVE-2026-100724 (http4k (Maven package org.http4k:http4k-core) before 
6.49.0.0, 5.42.0. ...)
-       TODO: check
+       NOT-FOR-US: http4k
 CVE-2026-100723 (vm2 before 3.12.2 does not apply its Buffer backing-store 
ownership in ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-100722 (vm2 before 3.12.2 does not apply host-side Promise rejection 
handling  ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-100721 (vm2 before 3.12.2 contains an authorization bypass in the 
NodeVM exter ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2025-71426 (Contrast is a confidential-computing runtime for Kubernetes. 
In versio ...)
-       TODO: check
+       NOT-FOR-US: Contrast
 CVE-2025-71425 (Contrast (Edgeless Systems) before 1.8.1 logs the workload 
secret to s ...)
-       TODO: check
+       NOT-FOR-US: Contrast
 CVE-2025-71424 (Contrast, Edgeless Systems' runtime for confidential 
containers on Kub ...)
-       TODO: check
+       NOT-FOR-US: Contrast
 CVE-2025-71423 (Edgelesssys Contrast is a confidential-computing runtime for 
Kubernete ...)
-       TODO: check
+       NOT-FOR-US: Contrast
 CVE-2025-71422 (Contrast is a Kubernetes runtime for confidential containers. 
In versi ...)
-       TODO: check
+       NOT-FOR-US: Contrast
 CVE-2026-XXXX [TROVE-2026-051]
        - tor <unfixed>
        NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41381
@@ -531,15 +531,15 @@ CVE-2026-9652
 CVE-2026-9313
        REJECTED
 CVE-2026-96879 (Improper removal of sensitive information before storage or 
transfer v ...)
-       TODO: check
+       NOT-FOR-US: Mediawiki extension
 CVE-2026-96878 (Improper neutralization of input during web page generation 
('cross-si ...)
-       TODO: check
+       NOT-FOR-US: Mediawiki extension
 CVE-2026-96877 (Improper neutralization of input during web page generation 
('cross-si ...)
-       TODO: check
+       NOT-FOR-US: Mediawiki extension
 CVE-2026-96876 (Improper neutralization of input during web page generation 
('cross-si ...)
-       TODO: check
+       NOT-FOR-US: Mediawiki extension
 CVE-2026-96875 (Improper neutralization of input during web page generation 
('cross-si ...)
-       TODO: check
+       NOT-FOR-US: Mediawiki extension
 CVE-2026-96795 (Horilla is an HR and CRM software. Prior to 2.0.0, 
HorillaListView.exp ...)
        NOT-FOR-US: Horilla
 CVE-2026-96533 (The Testimonials Widget WordPress plugin through 4.0.4 does 
not valida ...)
@@ -819,19 +819,19 @@ CVE-2026-100387 (pgPointcloud through 1.2.5 contains a 
heap out-of-bounds read v
 CVE-2026-100383 (Improper Neutralization of Input During Web Page Generation 
(XSS or 'C ...)
        NOT-FOR-US: MediaWiki extensions/skins not packaged in Debian
 CVE-2026-100382 (Improper Neutralization of Special Elements used in an OS 
Command ('OS ...)
-       TODO: check
+       NOT-FOR-US: Mediawiki extension
 CVE-2026-100381 (Improper Neutralization of Input During Web Page Generation 
(XSS or 'C ...)
-       TODO: check
+       NOT-FOR-US: Mediawiki extension
 CVE-2026-100380 (Improper Neutralization of Input During Web Page Generation 
(XSS or 'C ...)
        NOT-FOR-US: MediaWiki extensions/skins not packaged in Debian
 CVE-2026-100379 (Exposure of Sensitive Information to an Unauthorized Actor 
vulnerabili ...)
-       TODO: check
+       NOT-FOR-US: Mediawiki extension
 CVE-2026-100378 (Missing Authorization vulnerability in Wikimedia Foundation 
Mediawiki  ...)
        NOT-FOR-US: MediaWiki extensions/skins not packaged in Debian
 CVE-2026-100377 (Exposure of Sensitive Information to an Unauthorized Actor 
vulnerabili ...)
        NOT-FOR-US: MediaWiki extensions/skins not packaged in Debian
 CVE-2026-100376 (Improper Neutralization of Input During Web Page Generation 
(XSS or 'C ...)
-       TODO: check
+       NOT-FOR-US: Mediawiki extension
 CVE-2026-100373 (OpenMetadata through 2.0.2 contains a server-side request 
forgery vuln ...)
        NOT-FOR-US: OpenMetadata
 CVE-2026-100372 (ClipBucket v5 before 5.5.3-#197 contains a path traversal 
vulnerabilit ...)
@@ -1498,7 +1498,7 @@ CVE-2026-100303 (TDuck survey form through 6.0 lacks 
authorization checks on For
 CVE-2026-100248 (The Rattadan Cosmowarp smart contract before 56c6147 can have 
a compar ...)
        NOT-FOR-US: Rattadan Cosmowarp smart contract
 CVE-2026-100237 (Improper neutralization of input during web page generation 
('cross-si ...)
-       TODO: check
+       NOT-FOR-US: Mediawiki extension
 CVE-2026-100230 (Input Leap (aka input-leap) through 3.0.3, when the 
non-default --enab ...)
        - input-leap <itp> (bug #1128410)
 CVE-2026-100192 (X-SpringBoot through 6.0 exposes appKey and appSecret 
credentials in t ...)
@@ -3012,7 +3012,7 @@ CVE-2026-97058 (sprintf-js through 1.1.3 passes unbounded 
precision specifiers t
 CVE-2026-97057 (redis-parser through 3.0.0 fails to validate the multi-bulk 
length val ...)
        NOT-FOR-US: Node redis-parser
 CVE-2026-96873 (Improper neutralization of input during web page generation 
('cross-si ...)
-       TODO: check
+       NOT-FOR-US: Mediawiki extension
 CVE-2026-96750 (MongoDB Compass can interpolate a database name without 
escaping into  ...)
        NOT-FOR-US: mongodb-js (not same as node-mongodb)
 CVE-2026-96749 (An integer overflow in the BSON document encoding component of 
the Mon ...)
@@ -4607,9 +4607,9 @@ CVE-2026-94457 (Unauthenticated Bypass Vulnerability in 
Captcha Code <= 3.32 ver
 CVE-2026-94391 (Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 
2.4.14 versi ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-94251 (A vulnerability in Apache Sling Security 
Bundle:ContentDispositionFilt ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-94243 (A vulnerability in Apache Sling Security Bundle: the 
ReferrerFilter ac ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-94183 (Arc Search for Android before version 1.12.10 does not display 
a fulls ...)
        NOT-FOR-US: The Browser Company of New York
 CVE-2026-94181 (An address bar spoofing issue in affected versions of Arc 
could allow  ...)
@@ -4697,13 +4697,13 @@ CVE-2026-92164 (Streamlink is a CLI utility which pipes 
video streams from vario
        NOTE: 
https://github.com/streamlink/streamlink/security/advisories/GHSA-vf2x-4v53-pm7v
        NOTE: 
https://github.com/streamlink/streamlink/commit/4b99c64dde21ea70c24d9ffdbd15849b05f465c6
 (8.6.0)
 CVE-2026-92001 (Improper restriction of recursive entity references in DTDs 
('XML enti ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-91999 (Improper neutralization of input during web page generation 
('cross-si ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-91928 (Improper neutralization of input during web page generation 
('cross-si ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-91852 (Improper neutralization of input during web page generation 
('cross-si ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-91818 (A use-after-free vulnerability exists in Foxit PDF 
Editor/Reader\u2019 ...)
        NOT-FOR-US: Foxit
 CVE-2026-91817 (A heap-based out-of-bounds read vulnerability exists in Foxit 
PDF Edit ...)
@@ -5062,7 +5062,7 @@ CVE-2026-73587 (Dell Secure Connect Gateway (SCG) Policy 
Manager, versions prior
 CVE-2026-73586 (Dell Secure Connect Gateway (SCG) Policy Manager, versions 
prior to 5. ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-73192 (An improper neutralization of input during web page generation 
('Cross ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-71465 (RunAdHocCommand.build_args() appends limit as bare             
  posit ...)
        NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2026-71464 (LaunchConfigurationBaseSerializer.scm_branch has no            
   vali ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5fa71c19e35f4a51a7421af3715bf8bd906cd96e

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5fa71c19e35f4a51a7421af3715bf8bd906cd96e
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to