[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Aug 1 21:08:07 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ebe8c36c by Salvatore Bonaccorso at 2026-08-01T22:00:14+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -10,44 +10,44 @@ CVE-2026-67353 (guzzlehttp/guzzle versions before 7.15.1 contain a denial of ser
 	- guzzle 7.15.1-1
 	NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-f283-ghqc-fg79
 CVE-2026-67352 (luci-app-https-dns-proxy contains a stored cross-site scripting vulner ...)
-	TODO: check
+	NOT-FOR-US: luci-app-https-dns-proxy
 CVE-2026-67344 (ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database per ...)
-	TODO: check
+	NOT-FOR-US: ArcadeDB
 CVE-2026-67343 (ArcadeDB versions before 26.7.2 fail to properly redact the cluster to ...)
-	TODO: check
+	NOT-FOR-US: ArcadeDB
 CVE-2026-67342 (ArcadeDB versions before 26.7.2 contain an authorization bypass vulner ...)
-	TODO: check
+	NOT-FOR-US: ArcadeDB
 CVE-2026-67341 (ArcadeDB versions before 26.7.2 fail to enforce scripting authorizatio ...)
-	TODO: check
+	NOT-FOR-US: ArcadeDB
 CVE-2026-67340 (ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to loo ...)
-	TODO: check
+	NOT-FOR-US: ArcadeDB
 CVE-2026-67339 (guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Prox ...)
 	- guzzle 7.14.2-1
 	NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-94pj-82f3-465w
 CVE-2026-67338 (JupyterLab before 4.5.9 contains a stored cross-site scripting vulnera ...)
 	TODO: check
 CVE-2026-67337 (better-auth versions before 1.4.9 contain a two-factor authentication  ...)
-	TODO: check
+	NOT-FOR-US: Better Auth
 CVE-2026-67336 (better-auth versions before 1.6.11 contain insecure cryptographic defa ...)
-	TODO: check
+	NOT-FOR-US: Better Auth
 CVE-2026-67335 (better-auth versions before 1.6.2 fail to validate the OAuth state par ...)
-	TODO: check
+	NOT-FOR-US: Better Auth
 CVE-2026-67334 (better-auth versions before 1.6.11 fail to delete cached sessions when ...)
-	TODO: check
+	NOT-FOR-US: Better Auth
 CVE-2026-67333 (better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through ...)
-	TODO: check
+	NOT-FOR-US: Better Auth
 CVE-2026-67332 (@better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-t ...)
-	TODO: check
+	NOT-FOR-US: Better Auth (oauth-provider)
 CVE-2026-67331 (better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind  ...)
-	TODO: check
+	NOT-FOR-US: Better Auth
 CVE-2026-67330 (@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 thr ...)
-	TODO: check
+	NOT-FOR-US: Better Auth
 CVE-2026-67329 (@better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta ...)
-	TODO: check
+	NOT-FOR-US: Better Auth
 CVE-2026-67328 (@better-auth/sso versions before 1.6.21 contain multiple authenticatio ...)
-	TODO: check
+	NOT-FOR-US: Better Auth
 CVE-2026-67327 (better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions > ...)
-	TODO: check
+	NOT-FOR-US: Better Auth
 CVE-2026-67326 (GitPython before 3.1.50 fails to validate newline characters in the se ...)
 	TODO: check
 CVE-2026-67325 (GitPython before 3.1.51 contains an incomplete command injection block ...)
@@ -79,15 +79,15 @@ CVE-2026-67313 (axios versions 0.28.0 and later contain uncontrolled recursion i
 CVE-2026-67312 (axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0  ...)
 	TODO: check
 CVE-2026-67311 (Budibase before 3.38.1 contains a server-side request forgery vulnerab ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-67310 (OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an i ...)
-	TODO: check
+	NOT-FOR-US: OpenRemote
 CVE-2026-67309 (Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vuln ...)
 	TODO: check
 CVE-2026-67308 (Wazuh workflows before 44bf114 contain a shell injection vulnerability ...)
-	TODO: check
+	NOT-FOR-US: Wazuh
 CVE-2026-67307 (Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override ...)
-	TODO: check
+	NOT-FOR-US: Wazuh
 CVE-2026-67306 (FreeRDP versions 3.28.0 and earlier contain an out-of-bounds read vuln ...)
 	TODO: check
 CVE-2026-67305 (FreeRDP Windows client before 3.29.0 contains a heap buffer overflow v ...)
@@ -131,13 +131,13 @@ CVE-2026-66402 (FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains mul
 CVE-2026-66401 (FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerabilit ...)
 	TODO: check
 CVE-2026-55735 (Improper Verification of Cryptographic Signature in ueberauth guardian ...)
-	TODO: check
+	NOT-FOR-US: ueberauth guardian
 CVE-2026-55734 (Allocation of Resources Without Limits or Throttling vulnerability in  ...)
-	TODO: check
+	NOT-FOR-US: ueberauth guardian
 CVE-2026-55733 (Allocation of Resources Without Limits or Throttling in ueberauth guar ...)
-	TODO: check
+	NOT-FOR-US: ueberauth guardian
 CVE-2026-54894 (Allocation of Resources Without Limits or Throttling in ueberauth guar ...)
-	TODO: check
+	NOT-FOR-US: ueberauth guardian
 CVE-2026-2916 (The Jeg Kit for Elementor plugin for WordPress is vulnerable to Sensit ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-2411 (Zephyr's Bluetooth host declares a GATT characteristic as two consecut ...)
@@ -209,11 +209,11 @@ CVE-2026-10773 (The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/ne
 CVE-2026-10772
 	REJECTED
 CVE-2025-71404 (better-auth versions after v0.0.2 and before 1.1.16 contain a reflecte ...)
-	TODO: check
+	NOT-FOR-US: Better Auth
 CVE-2025-71403 (better-auth versions before 1.1.20 contain a bypass vulnerability in t ...)
-	TODO: check
+	NOT-FOR-US: Better Auth
 CVE-2025-71402 (better-auth versions greater than 1.3.34 and before 1.4.0 contain a vu ...)
-	TODO: check
+	NOT-FOR-US: Better Auth
 CVE-2025-14469 (The Theme Editor plugin for WordPress is vulnerable to Cross-Site Requ ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2025-14073 (The WooCommerce PayPal Payments plugin for WordPress is vulnerable to  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ebe8c36c080b3e9723987879ac5277bb157c069d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ebe8c36c080b3e9723987879ac5277bb157c069d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260801/aaca740e/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list