[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 4 10:12:44 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e8a822fa by Salvatore Bonaccorso at 2026-08-04T11:12:08+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -43,7 +43,7 @@ CVE-2026-69243 (AIOHTTP is an asynchronous HTTP client/server framework for asyn
 	NOTE: https://github.com/aio-libs/aiohttp/pull/13017
 	NOTE: Fixed by: https://github.com/aio-libs/aiohttp/commit/6ae358f0983c3f4d6f67692b2f8e65dc8e091c98 (v3.14.2)
 CVE-2026-69240 (Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is pos ...)
-	TODO: check
+	NOT-FOR-US: Sequelize
 CVE-2026-69198 (ip-address is a library for parsing and manipulating IPv4 and IPv6 add ...)
 	- node-ip-address 10.3.1-1
 	[trixie] - node-ip-address <not-affected> (Vulnerable code introduced later)
@@ -88,11 +88,11 @@ CVE-2026-67969 (An issue in the HS_MonitorApplications() component of NASA cFS v
 CVE-2026-67673 (A stack-based buffer overflow vulnerability exists in the cmd_edl func ...)
 	TODO: check
 CVE-2026-67617 (Microweber CMS through 2.0.20 contains a stored cross-site scripting v ...)
-	TODO: check
+	NOT-FOR-US: Microweber CMS
 CVE-2026-67616 (Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missin ...)
-	TODO: check
+	NOT-FOR-US: Camaleon CMS
 CVE-2026-67599 (ClearOS 7.9 contains an OS command injection vulnerability in the Log  ...)
-	TODO: check
+	NOT-FOR-US: ClearOS
 CVE-2026-67598 (Emlog Pro through 2.6.23 contains a disabled TLS certificate validatio ...)
 	NOT-FOR-US: Emlog
 CVE-2026-66326 (Missing authorization in Microsoft Edge (Chromium-based) allows an una ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e8a822fad296b702a50b798c90ea57b5fefbacff

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e8a822fad296b702a50b798c90ea57b5fefbacff
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260804/7c3cf514/attachment.htm>


More information about the debian-security-tracker-commits mailing list