[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Aug 1 09:03:48 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
cb3f2e5f by Salvatore Bonaccorso at 2026-08-01T10:03:23+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3,67 +3,67 @@ CVE-2026-9044 (An OS command injection vulnerability exists in the VPN module of
 CVE-2026-7623 (The SureForms \u2013 Contact Form, Payment Form & Other Custom Form Bu ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-68771 (ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in th ...)
-	TODO: check
+	NOT-FOR-US: ComfyUI
 CVE-2026-68770 (sentence-transformers contains a security control bypass vulnerability ...)
-	TODO: check
+	NOT-FOR-US: sentence-transformers
 CVE-2026-65981 (Coturn is a free open source implementation of TURN and STUN Server. P ...)
 	TODO: check
 CVE-2026-65841 (Jodit Editor is a WYSIWYG editor with a built-in file browser & image  ...)
-	TODO: check
+	NOT-FOR-US: Jodit Editor
 CVE-2026-62999 (Copier is a library and CLI app for rendering project templates. From  ...)
-	TODO: check
+	NOT-FOR-US: Copier library and CLI app
 CVE-2026-62959 (Coturn is a free open source implementation of TURN and STUN Server. F ...)
 	TODO: check
 CVE-2026-62324 (Jodit Editor is a WYSIWYG editor with a built-in file browser & image  ...)
-	TODO: check
+	NOT-FOR-US: Jodit Editor
 CVE-2026-55825 (Contao is an Open Source CMS. In versions 5.7.0 through 5.7.6, an auth ...)
-	TODO: check
+	NOT-FOR-US: Contao CMS
 CVE-2026-54909 (pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAdd ...)
 	TODO: check
 CVE-2026-54787 (sigstore-go is a Go library for Sigstore signing and verification. Pri ...)
 	TODO: check
 CVE-2026-54785 (gemini-bridge is a lightweight MCP server bridging AI agents to Google ...)
-	TODO: check
+	NOT-FOR-US: gemini-bridge
 CVE-2026-54768 (WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until ...)
-	TODO: check
+	NOT-FOR-US: WPGraphQL
 CVE-2026-53599 (REDAXO is a PHP-based content management system. From 5.18.2 until 5.2 ...)
-	TODO: check
+	NOT-FOR-US: REDAXO CMS
 CVE-2026-53573 (GeoNetwork is a catalog application to manage spatially referenced res ...)
-	TODO: check
+	NOT-FOR-US: GeoNetwork
 CVE-2026-53551 (free5GC is an open-source implementation of the 5G core network. Prior ...)
-	TODO: check
+	NOT-FOR-US: free5GC
 CVE-2026-53510 (Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .al ...)
-	TODO: check
+	NOT-FOR-US: Savon Ruby SOAP client
 CVE-2026-52371 (A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trig ...)
-	TODO: check
+	NOT-FOR-US: xxl-job
 CVE-2026-52232 (A reflected cross-site scripting (XSS) vulnerability in the /logo.asp  ...)
-	TODO: check
+	NOT-FOR-US: FS Inc S3150-8T2F Switch 2.2.0D
 CVE-2026-52134 (An issue in the parseGoosePayload() function (/goose/goose_receiver.c) ...)
-	TODO: check
+	NOT-FOR-US: MZ Automation libiec61850
 CVE-2026-51953 (An issue in FeehiCMS v.2.1.1 allows an attacker to escalate privileges ...)
-	TODO: check
+	NOT-FOR-US: FeehiCMS
 CVE-2026-51785 (An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote at ...)
-	TODO: check
+	NOT-FOR-US: Hugo Leisink Hiawatha
 CVE-2026-50986 (PrestaShop module, totadministrativemandate <1.8.1 is vulnerable to Cr ...)
-	TODO: check
+	NOT-FOR-US: PrestaShop module
 CVE-2026-45377 (Decidim is a participatory democracy framework. Prior to 0.30.9, from  ...)
-	TODO: check
+	NOT-FOR-US: Decidim
 CVE-2026-45376 (Decidim is a participatory democracy framework. Prior to 0.30.9, from  ...)
-	TODO: check
+	NOT-FOR-US: Decidim
 CVE-2026-45330 (Decidim is a participatory democracy framework. Prior to 0.30.9, from  ...)
-	TODO: check
+	NOT-FOR-US: Decidim
 CVE-2026-45086 (Decidim is a participatory democracy framework. From 0.31.1 before 0.3 ...)
-	TODO: check
+	NOT-FOR-US: Decidim
 CVE-2026-3141 (The FormGent plugin for WordPress is vulnerable to unauthorized arbitr ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-38713 (TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300  ...)
-	TODO: check
+	NOT-FOR-US: AX3000 2.5G Wi-Fi 6 Mini VPN Router, TR3000 1.0
 CVE-2026-38711 (TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300  ...)
-	TODO: check
+	NOT-FOR-US: AX3000 2.5G Wi-Fi 6 Mini VPN Router, TR3000 1.0
 CVE-2026-38710 (TR1200 v2.4.15 and TR3000 v2.4.21 were discovered to contain a command ...)
-	TODO: check
+	NOT-FOR-US: AX3000 2.5G Wi-Fi 6 Mini VPN Router, TR3000 1.0
 CVE-2026-38708 (TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300  ...)
-	TODO: check
+	NOT-FOR-US: AX3000 2.5G Wi-Fi 6 Mini VPN Router, TR3000 1.0
 CVE-2026-34641 (Premiere Pro is affected by an out-of-bounds write vulnerability that  ...)
 	NOT-FOR-US: Adobe
 CVE-2026-18394 (Incorrect authorization in the http_request tool in Strands Agents Too ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb3f2e5f110d2795abc5be97a544ef82aa489e3c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb3f2e5f110d2795abc5be97a544ef82aa489e3c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260801/b3b07605/attachment.htm>


More information about the debian-security-tracker-commits mailing list