Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
5fa71c19 by Salvatore Bonaccorso at 2026-09-27T10:06:30+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -59,101 +59,101 @@ CVE-2026-72668 (Unintended Proxy or Intermediary
('Confused Deputy') (CWE-441) i
CVE-2026-72662 (Authorization Bypass Through User-Controlled Key (CWE-639) in
Kibana c ...)
NOT-FOR-US: Elastic
CVE-2026-100865 (Heym before 0.0.53 contains multiple independent
vulnerabilities. (1) ...)
- TODO: check
+ NOT-FOR-US: Heym
CVE-2026-100864 (heym before 0.0.91 contains a sandbox escape vulnerability in
the expr ...)
- TODO: check
+ NOT-FOR-US: Heym
CVE-2026-100863 (Heym versions 0.0.90 and earlier contain two server-side
request forge ...)
- TODO: check
+ NOT-FOR-US: Heym
CVE-2026-100862 (heym, a workflow automation platform, stores and returns
multiple capa ...)
- TODO: check
+ NOT-FOR-US: Heym
CVE-2026-100861 (heym before 0.0.105 fails to apply egress guards to
integration servic ...)
- TODO: check
+ NOT-FOR-US: Heym
CVE-2026-100860 (heym before 0.0.105 does not act on the result of the
credential autho ...)
- TODO: check
+ NOT-FOR-US: Heym
CVE-2026-100859 (Heym before 0.0.106 contains a credential exfiltration
vulnerability i ...)
- TODO: check
+ NOT-FOR-US: Heym
CVE-2026-100858 (heym before 0.0.109 contains a server-side request forgery
vulnerabili ...)
- TODO: check
+ NOT-FOR-US: Heym
CVE-2026-100857 (AzuraCast before 0.23.4 contains a code injection
vulnerability in the ...)
- TODO: check
+ NOT-FOR-US: AzuraCast
CVE-2026-100856 (AzuraCast before 0.23.6 contains a code injection
vulnerability in the ...)
- TODO: check
+ NOT-FOR-US: AzuraCast
CVE-2026-100855 (AzuraCast before 0.23.6 contains a missing permission check
vulnerabil ...)
- TODO: check
+ NOT-FOR-US: AzuraCast
CVE-2026-100854 (AzuraCast before 0.23.6 lacks RequireInternalConnection
middleware on ...)
- TODO: check
+ NOT-FOR-US: AzuraCast
CVE-2026-100853 (In AzuraCast before 0.23.8, the public On-Demand download
endpoint fai ...)
- TODO: check
+ NOT-FOR-US: AzuraCast
CVE-2026-100852 (AzuraCast through 0.23.x contains a command injection
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: AzuraCast
CVE-2026-100851 (AzuraCast before 0.23.8 contains a broken access control
vulnerability ...)
- TODO: check
+ NOT-FOR-US: AzuraCast
CVE-2026-100850 (AzuraCast before 0.23.8 contains a server-side request
forgery and loc ...)
- TODO: check
+ NOT-FOR-US: AzuraCast
CVE-2026-100849 (AzuraCast is a self-hosted web radio management suite. In
AzuraCast be ...)
- TODO: check
+ NOT-FOR-US: AzuraCast
CVE-2026-100848 (AzuraCast (Composer package azuracast/azuracast) before
0.23.8 validat ...)
- TODO: check
+ NOT-FOR-US: AzuraCast
CVE-2026-100847 (AzuraCast before 0.23.8 contains a DQL injection
vulnerability in the ...)
- TODO: check
+ NOT-FOR-US: AzuraCast
CVE-2026-100846 (MONAI before 1.5.2 contains a deserialization of untrusted
data vulner ...)
- TODO: check
+ NOT-FOR-US: MONAI
CVE-2026-100845 (MONAI before 1.6.0 contains an unsafe deserialization
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: MONAI
CVE-2026-100844 (MONAI before 1.6.0 is vulnerable to OS command injection in
the nnUNet ...)
- TODO: check
+ NOT-FOR-US: MONAI
CVE-2026-100843 (MONAI versions before 1.6.0 contain a remote code execution
vulnerabil ...)
- TODO: check
+ NOT-FOR-US: MONAI
CVE-2026-100842 (MONAI through 1.6.0 contains an eval injection vulnerability
in _get_f ...)
- TODO: check
+ NOT-FOR-US: MONAI
CVE-2026-100841 (In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py)
explicitly r ...)
- TODO: check
+ NOT-FOR-US: MONAI
CVE-2026-100840 (MONAI through 1.6.0 contains a remote code execution
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: MONAI
CVE-2026-100839 (Contrast is a confidential-computing runtime for Kubernetes.
In versio ...)
- TODO: check
+ NOT-FOR-US: Contrast
CVE-2026-100838 (Contrast is a confidential-computing runtime for Kubernetes.
In versio ...)
- TODO: check
+ NOT-FOR-US: Contrast
CVE-2026-100837 (Contrast (Edgeless Systems) through 1.20.0 performs
unanchored suffix ...)
- TODO: check
+ NOT-FOR-US: Contrast
CVE-2026-100836 (Contrast through 1.20.0 contains a panic vulnerability in the
transit- ...)
- TODO: check
+ NOT-FOR-US: Contrast
CVE-2026-100835 (Contrast before 1.16.0 is susceptible to remote attestation
relay atta ...)
- TODO: check
+ NOT-FOR-US: Contrast
CVE-2026-100834 (http4k's Digest authentication module
(org.http4k:http4k-security-dige ...)
- TODO: check
+ NOT-FOR-US: http4k
CVE-2026-100833 (Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1
generate ...)
- TODO: check
+ NOT-FOR-US: Contrast
CVE-2026-100746 (A vulnerability was found in coollabsio Coolify up to 4.1.0.
This affe ...)
- TODO: check
+ NOT-FOR-US: Coolify
CVE-2026-100745 (A vulnerability has been found in Edimax BR-6428nC 1.16. The
impacted ...)
NOT-FOR-US: Edimax
CVE-2026-100744 (A flaw has been found in coollabsio Coolify up to 4.1.2. The
affected ...)
- TODO: check
+ NOT-FOR-US: Coolify
CVE-2026-100740 (A vulnerability was detected in D-Link DIR-895L A1_102b07.
Impacted is ...)
NOT-FOR-US: D-Link
CVE-2026-100739 (A vulnerability was detected in mathurvishal
CloudClassroom-PHP-Projec ...)
- TODO: check
+ NOT-FOR-US: mathurvishal CloudClassroom-PHP-Project
CVE-2026-100725 (http4k (Maven artifact org.http4k:http4k-core) before
6.48.0.0, 5.42.0 ...)
- TODO: check
+ NOT-FOR-US: http4k
CVE-2026-100724 (http4k (Maven package org.http4k:http4k-core) before
6.49.0.0, 5.42.0. ...)
- TODO: check
+ NOT-FOR-US: http4k
CVE-2026-100723 (vm2 before 3.12.2 does not apply its Buffer backing-store
ownership in ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-100722 (vm2 before 3.12.2 does not apply host-side Promise rejection
handling ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-100721 (vm2 before 3.12.2 contains an authorization bypass in the
NodeVM exter ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2025-71426 (Contrast is a confidential-computing runtime for Kubernetes.
In versio ...)
- TODO: check
+ NOT-FOR-US: Contrast
CVE-2025-71425 (Contrast (Edgeless Systems) before 1.8.1 logs the workload
secret to s ...)
- TODO: check
+ NOT-FOR-US: Contrast
CVE-2025-71424 (Contrast, Edgeless Systems' runtime for confidential
containers on Kub ...)
- TODO: check
+ NOT-FOR-US: Contrast
CVE-2025-71423 (Edgelesssys Contrast is a confidential-computing runtime for
Kubernete ...)
- TODO: check
+ NOT-FOR-US: Contrast
CVE-2025-71422 (Contrast is a Kubernetes runtime for confidential containers.
In versi ...)
- TODO: check
+ NOT-FOR-US: Contrast
CVE-2026-XXXX [TROVE-2026-051]
- tor <unfixed>
NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41381
@@ -531,15 +531,15 @@ CVE-2026-9652
CVE-2026-9313
REJECTED
CVE-2026-96879 (Improper removal of sensitive information before storage or
transfer v ...)
- TODO: check
+ NOT-FOR-US: Mediawiki extension
CVE-2026-96878 (Improper neutralization of input during web page generation
('cross-si ...)
- TODO: check
+ NOT-FOR-US: Mediawiki extension
CVE-2026-96877 (Improper neutralization of input during web page generation
('cross-si ...)
- TODO: check
+ NOT-FOR-US: Mediawiki extension
CVE-2026-96876 (Improper neutralization of input during web page generation
('cross-si ...)
- TODO: check
+ NOT-FOR-US: Mediawiki extension
CVE-2026-96875 (Improper neutralization of input during web page generation
('cross-si ...)
- TODO: check
+ NOT-FOR-US: Mediawiki extension
CVE-2026-96795 (Horilla is an HR and CRM software. Prior to 2.0.0,
HorillaListView.exp ...)
NOT-FOR-US: Horilla
CVE-2026-96533 (The Testimonials Widget WordPress plugin through 4.0.4 does
not valida ...)
@@ -819,19 +819,19 @@ CVE-2026-100387 (pgPointcloud through 1.2.5 contains a
heap out-of-bounds read v
CVE-2026-100383 (Improper Neutralization of Input During Web Page Generation
(XSS or 'C ...)
NOT-FOR-US: MediaWiki extensions/skins not packaged in Debian
CVE-2026-100382 (Improper Neutralization of Special Elements used in an OS
Command ('OS ...)
- TODO: check
+ NOT-FOR-US: Mediawiki extension
CVE-2026-100381 (Improper Neutralization of Input During Web Page Generation
(XSS or 'C ...)
- TODO: check
+ NOT-FOR-US: Mediawiki extension
CVE-2026-100380 (Improper Neutralization of Input During Web Page Generation
(XSS or 'C ...)
NOT-FOR-US: MediaWiki extensions/skins not packaged in Debian
CVE-2026-100379 (Exposure of Sensitive Information to an Unauthorized Actor
vulnerabili ...)
- TODO: check
+ NOT-FOR-US: Mediawiki extension
CVE-2026-100378 (Missing Authorization vulnerability in Wikimedia Foundation
Mediawiki ...)
NOT-FOR-US: MediaWiki extensions/skins not packaged in Debian
CVE-2026-100377 (Exposure of Sensitive Information to an Unauthorized Actor
vulnerabili ...)
NOT-FOR-US: MediaWiki extensions/skins not packaged in Debian
CVE-2026-100376 (Improper Neutralization of Input During Web Page Generation
(XSS or 'C ...)
- TODO: check
+ NOT-FOR-US: Mediawiki extension
CVE-2026-100373 (OpenMetadata through 2.0.2 contains a server-side request
forgery vuln ...)
NOT-FOR-US: OpenMetadata
CVE-2026-100372 (ClipBucket v5 before 5.5.3-#197 contains a path traversal
vulnerabilit ...)
@@ -1498,7 +1498,7 @@ CVE-2026-100303 (TDuck survey form through 6.0 lacks
authorization checks on For
CVE-2026-100248 (The Rattadan Cosmowarp smart contract before 56c6147 can have
a compar ...)
NOT-FOR-US: Rattadan Cosmowarp smart contract
CVE-2026-100237 (Improper neutralization of input during web page generation
('cross-si ...)
- TODO: check
+ NOT-FOR-US: Mediawiki extension
CVE-2026-100230 (Input Leap (aka input-leap) through 3.0.3, when the
non-default --enab ...)
- input-leap <itp> (bug #1128410)
CVE-2026-100192 (X-SpringBoot through 6.0 exposes appKey and appSecret
credentials in t ...)
@@ -3012,7 +3012,7 @@ CVE-2026-97058 (sprintf-js through 1.1.3 passes unbounded
precision specifiers t
CVE-2026-97057 (redis-parser through 3.0.0 fails to validate the multi-bulk
length val ...)
NOT-FOR-US: Node redis-parser
CVE-2026-96873 (Improper neutralization of input during web page generation
('cross-si ...)
- TODO: check
+ NOT-FOR-US: Mediawiki extension
CVE-2026-96750 (MongoDB Compass can interpolate a database name without
escaping into ...)
NOT-FOR-US: mongodb-js (not same as node-mongodb)
CVE-2026-96749 (An integer overflow in the BSON document encoding component of
the Mon ...)
@@ -4607,9 +4607,9 @@ CVE-2026-94457 (Unauthenticated Bypass Vulnerability in
Captcha Code <= 3.32 ver
CVE-2026-94391 (Contributor Cross Site Scripting (XSS) in Ultimate FAQ <=
2.4.14 versi ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-94251 (A vulnerability in Apache Sling Security
Bundle:ContentDispositionFilt ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-94243 (A vulnerability in Apache Sling Security Bundle: the
ReferrerFilter ac ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-94183 (Arc Search for Android before version 1.12.10 does not display
a fulls ...)
NOT-FOR-US: The Browser Company of New York
CVE-2026-94181 (An address bar spoofing issue in affected versions of Arc
could allow ...)
@@ -4697,13 +4697,13 @@ CVE-2026-92164 (Streamlink is a CLI utility which pipes
video streams from vario
NOTE:
https://github.com/streamlink/streamlink/security/advisories/GHSA-vf2x-4v53-pm7v
NOTE:
https://github.com/streamlink/streamlink/commit/4b99c64dde21ea70c24d9ffdbd15849b05f465c6
(8.6.0)
CVE-2026-92001 (Improper restriction of recursive entity references in DTDs
('XML enti ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-91999 (Improper neutralization of input during web page generation
('cross-si ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-91928 (Improper neutralization of input during web page generation
('cross-si ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-91852 (Improper neutralization of input during web page generation
('cross-si ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-91818 (A use-after-free vulnerability exists in Foxit PDF
Editor/Reader\u2019 ...)
NOT-FOR-US: Foxit
CVE-2026-91817 (A heap-based out-of-bounds read vulnerability exists in Foxit
PDF Edit ...)
@@ -5062,7 +5062,7 @@ CVE-2026-73587 (Dell Secure Connect Gateway (SCG) Policy
Manager, versions prior
CVE-2026-73586 (Dell Secure Connect Gateway (SCG) Policy Manager, versions
prior to 5. ...)
NOT-FOR-US: Dell / EMC
CVE-2026-73192 (An improper neutralization of input during web page generation
('Cross ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-71465 (RunAdHocCommand.build_args() appends limit as bare
posit ...)
NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-71464 (LaunchConfigurationBaseSerializer.scm_branch has no
vali ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5fa71c19e35f4a51a7421af3715bf8bd906cd96e
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5fa71c19e35f4a51a7421af3715bf8bd906cd96e
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits