[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Aug 1 21:08:07 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
ebe8c36c by Salvatore Bonaccorso at 2026-08-01T22:00:14+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -10,44 +10,44 @@ CVE-2026-67353 (guzzlehttp/guzzle versions before 7.15.1 contain a denial of ser
- guzzle 7.15.1-1
NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-f283-ghqc-fg79
CVE-2026-67352 (luci-app-https-dns-proxy contains a stored cross-site scripting vulner ...)
- TODO: check
+ NOT-FOR-US: luci-app-https-dns-proxy
CVE-2026-67344 (ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database per ...)
- TODO: check
+ NOT-FOR-US: ArcadeDB
CVE-2026-67343 (ArcadeDB versions before 26.7.2 fail to properly redact the cluster to ...)
- TODO: check
+ NOT-FOR-US: ArcadeDB
CVE-2026-67342 (ArcadeDB versions before 26.7.2 contain an authorization bypass vulner ...)
- TODO: check
+ NOT-FOR-US: ArcadeDB
CVE-2026-67341 (ArcadeDB versions before 26.7.2 fail to enforce scripting authorizatio ...)
- TODO: check
+ NOT-FOR-US: ArcadeDB
CVE-2026-67340 (ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to loo ...)
- TODO: check
+ NOT-FOR-US: ArcadeDB
CVE-2026-67339 (guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Prox ...)
- guzzle 7.14.2-1
NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-94pj-82f3-465w
CVE-2026-67338 (JupyterLab before 4.5.9 contains a stored cross-site scripting vulnera ...)
TODO: check
CVE-2026-67337 (better-auth versions before 1.4.9 contain a two-factor authentication ...)
- TODO: check
+ NOT-FOR-US: Better Auth
CVE-2026-67336 (better-auth versions before 1.6.11 contain insecure cryptographic defa ...)
- TODO: check
+ NOT-FOR-US: Better Auth
CVE-2026-67335 (better-auth versions before 1.6.2 fail to validate the OAuth state par ...)
- TODO: check
+ NOT-FOR-US: Better Auth
CVE-2026-67334 (better-auth versions before 1.6.11 fail to delete cached sessions when ...)
- TODO: check
+ NOT-FOR-US: Better Auth
CVE-2026-67333 (better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through ...)
- TODO: check
+ NOT-FOR-US: Better Auth
CVE-2026-67332 (@better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-t ...)
- TODO: check
+ NOT-FOR-US: Better Auth (oauth-provider)
CVE-2026-67331 (better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind ...)
- TODO: check
+ NOT-FOR-US: Better Auth
CVE-2026-67330 (@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 thr ...)
- TODO: check
+ NOT-FOR-US: Better Auth
CVE-2026-67329 (@better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta ...)
- TODO: check
+ NOT-FOR-US: Better Auth
CVE-2026-67328 (@better-auth/sso versions before 1.6.21 contain multiple authenticatio ...)
- TODO: check
+ NOT-FOR-US: Better Auth
CVE-2026-67327 (better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions > ...)
- TODO: check
+ NOT-FOR-US: Better Auth
CVE-2026-67326 (GitPython before 3.1.50 fails to validate newline characters in the se ...)
TODO: check
CVE-2026-67325 (GitPython before 3.1.51 contains an incomplete command injection block ...)
@@ -79,15 +79,15 @@ CVE-2026-67313 (axios versions 0.28.0 and later contain uncontrolled recursion i
CVE-2026-67312 (axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 ...)
TODO: check
CVE-2026-67311 (Budibase before 3.38.1 contains a server-side request forgery vulnerab ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-67310 (OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an i ...)
- TODO: check
+ NOT-FOR-US: OpenRemote
CVE-2026-67309 (Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vuln ...)
TODO: check
CVE-2026-67308 (Wazuh workflows before 44bf114 contain a shell injection vulnerability ...)
- TODO: check
+ NOT-FOR-US: Wazuh
CVE-2026-67307 (Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override ...)
- TODO: check
+ NOT-FOR-US: Wazuh
CVE-2026-67306 (FreeRDP versions 3.28.0 and earlier contain an out-of-bounds read vuln ...)
TODO: check
CVE-2026-67305 (FreeRDP Windows client before 3.29.0 contains a heap buffer overflow v ...)
@@ -131,13 +131,13 @@ CVE-2026-66402 (FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains mul
CVE-2026-66401 (FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerabilit ...)
TODO: check
CVE-2026-55735 (Improper Verification of Cryptographic Signature in ueberauth guardian ...)
- TODO: check
+ NOT-FOR-US: ueberauth guardian
CVE-2026-55734 (Allocation of Resources Without Limits or Throttling vulnerability in ...)
- TODO: check
+ NOT-FOR-US: ueberauth guardian
CVE-2026-55733 (Allocation of Resources Without Limits or Throttling in ueberauth guar ...)
- TODO: check
+ NOT-FOR-US: ueberauth guardian
CVE-2026-54894 (Allocation of Resources Without Limits or Throttling in ueberauth guar ...)
- TODO: check
+ NOT-FOR-US: ueberauth guardian
CVE-2026-2916 (The Jeg Kit for Elementor plugin for WordPress is vulnerable to Sensit ...)
NOT-FOR-US: WordPress plugin
CVE-2026-2411 (Zephyr's Bluetooth host declares a GATT characteristic as two consecut ...)
@@ -209,11 +209,11 @@ CVE-2026-10773 (The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/ne
CVE-2026-10772
REJECTED
CVE-2025-71404 (better-auth versions after v0.0.2 and before 1.1.16 contain a reflecte ...)
- TODO: check
+ NOT-FOR-US: Better Auth
CVE-2025-71403 (better-auth versions before 1.1.20 contain a bypass vulnerability in t ...)
- TODO: check
+ NOT-FOR-US: Better Auth
CVE-2025-71402 (better-auth versions greater than 1.3.34 and before 1.4.0 contain a vu ...)
- TODO: check
+ NOT-FOR-US: Better Auth
CVE-2025-14469 (The Theme Editor plugin for WordPress is vulnerable to Cross-Site Requ ...)
NOT-FOR-US: WordPress plugin
CVE-2025-14073 (The WooCommerce PayPal Payments plugin for WordPress is vulnerable to ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ebe8c36c080b3e9723987879ac5277bb157c069d
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ebe8c36c080b3e9723987879ac5277bb157c069d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260801/aaca740e/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list