[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Aug 3 20:36:29 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e093cc3a by Salvatore Bonaccorso at 2026-08-03T21:35:57+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
CVE-2026-8794 (PaperCut NG/MF contains an observable timing discrepancy in its authen ...)
- TODO: check
+ NOT-FOR-US: PaperCut
CVE-2026-8793 (PaperCut NG/MF does not properly restrict excessive authentication att ...)
- TODO: check
+ NOT-FOR-US: PaperCut
CVE-2026-69153 (PostCSS takes a CSS file and provides an API to analyze and modify its ...)
TODO: check
CVE-2026-69152 (The brace-expansion library generates arbitrary strings containing a c ...)
@@ -13,41 +13,41 @@ CVE-2026-69149 (Angular is a development platform for building mobile and deskto
CVE-2026-69097 (GitPython before 3.1.53 fails to properly escape section names in git ...)
TODO: check
CVE-2026-69096 (OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots co ...)
- TODO: check
+ NOT-FOR-US: OpenWrt luci-app-dockerman
CVE-2026-69095 (OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779 ...)
- TODO: check
+ NOT-FOR-US: OpenWrt
CVE-2026-69094 (Admidio before 5.0.11 contains an insecure direct object reference vul ...)
- TODO: check
+ NOT-FOR-US: Admidio
CVE-2026-69093 (Admidio before 5.0.11 does not validate the adm_csrf_token in modules/ ...)
- TODO: check
+ NOT-FOR-US: Admidio
CVE-2026-69092 (Admidio versions before 5.0.11 contain a reflected cross-site scriptin ...)
- TODO: check
+ NOT-FOR-US: Admidio
CVE-2026-69091 (Admidio before 5.0.11 contains an authentication bypass vulnerability ...)
- TODO: check
+ NOT-FOR-US: Admidio
CVE-2026-69090 (Admidio before 5.0.11 fails to validate target organization membership ...)
- TODO: check
+ NOT-FOR-US: Admidio
CVE-2026-69089 (Grav CMS 2.0.10 contains a path traversal vulnerability in ImageMedium ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-69088 (Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualifie ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-69087 (The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains ...)
- TODO: check
+ NOT-FOR-US: Grav form plugin (getgrav/grav-plugin-form)
CVE-2026-69086 (SiYuan versions before v3.7.3 fail to validate the avID parameter on a ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-69085 (SiYuan before v3.7.3 contains a SQL injection vulnerability in the /ap ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-69084 (SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endp ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-69083 (SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-69082 (CTI-Transmute contained a cross-site request forgery vulnerability in ...)
- TODO: check
+ NOT-FOR-US: CTI-Transmute
CVE-2026-69079 (CTI-Transmute contains an uncontrolled resource-consumption vulnerabil ...)
- TODO: check
+ NOT-FOR-US: CTI-Transmute
CVE-2026-69078 (CTI-Transmute is affected by a server-side request forgery vulnerabili ...)
- TODO: check
+ NOT-FOR-US: CTI-Transmute
CVE-2026-69075 (FlowIntel is affected by a stored cross-site scripting vulnerability t ...)
- TODO: check
+ NOT-FOR-US: FlowIntel
CVE-2026-68945 (Angular is a development platform for building mobile and desktop web ...)
TODO: check
CVE-2026-68930 (Russh is a Rust SSH client & server library. Prior to 0.62.5, russh di ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e093cc3aeb4b324d001ff25651b6dec6924898f5
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e093cc3aeb4b324d001ff25651b6dec6924898f5
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260803/ec29605e/attachment.htm>
More information about the debian-security-tracker-commits
mailing list