[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 4 12:00:19 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
be878ab8 by Salvatore Bonaccorso at 2026-08-04T12:59:57+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -79,9 +79,9 @@ CVE-2026-68744 (A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() fun
 CVE-2026-67978 (An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers  ...)
 	NOT-FOR-US: NASA cFS
 CVE-2026-67977 (An integer overflow in the Svc::FileDownlink::SendPartial component of ...)
-	TODO: check
+	NOT-FOR-US: fprime framework
 CVE-2026-67976 (The Ref::SignalGen component of fprime framework v4.2.2 does not valid ...)
-	TODO: check
+	NOT-FOR-US: fprime framework
 CVE-2026-67975 (Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitr ...)
 	NOT-FOR-US: NASA cFS
 CVE-2026-67974 (A parser boundary flaw in the Software Bus Network (SBN) application's ...)
@@ -131,9 +131,9 @@ CVE-2026-66311 (Missing authorization in Microsoft Edge (Chromium-based) allows
 CVE-2026-66310 (External control of file name or path in Microsoft Edge for Android al ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-66296 (Improper Neutralization of Input During Web Page Generation (XSS) vuln ...)
-	TODO: check
+	NOT-FOR-US: lud oaskit
 CVE-2026-66065 (Ouroboros is a local-first runtime for AI coding agents that records t ...)
-	TODO: check
+	NOT-FOR-US: Ouroboros (not the same as rust-ouroboros)
 CVE-2026-65804 (Improper control of generation of code ('code injection') in Microsoft ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-65802 (External control of file name or path in Microsoft Edge for Android al ...)
@@ -158,23 +158,23 @@ CVE-2026-62870 (Use after free in Microsoft Office Excel allows an unauthorized
 CVE-2026-62354 (Authorization handling for Parameter Context validation requests in Ap ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-58139 (The DuckDB AWS extension for DuckDB contains a security policy bypass  ...)
-	TODO: check
+	NOT-FOR-US: DuckDB AWS extension for DuckDB
 CVE-2026-56845 (An unauthenticated path traversal (LFI) vulnerability exists under /cu ...)
-	TODO: check
+	NOT-FOR-US: CustomSounds storage
 CVE-2026-52521 (A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated  ...)
 	NOT-FOR-US: Z-BlogPHP
 CVE-2026-52520 (Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulne ...)
 	NOT-FOR-US: Emlog
 CVE-2026-52102 (An OS command injection vulnerability in the openmediavault-md plugin  ...)
-	TODO: check
+	NOT-FOR-US: openmediavault-md plugin of OpenMediaVault
 CVE-2026-51775 (SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an at ...)
-	TODO: check
+	NOT-FOR-US: Fastadmin
 CVE-2026-51190 (The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 p ...)
 	NOT-FOR-US: Serverless-Devs @serverless-devs/s
 CVE-2026-49132 (OPNsense before 26.1.9 contains a stored cross-site scripting vulnerab ...)
-	TODO: check
+	NOT-FOR-US: OPNsense
 CVE-2026-49131 (OPNsense before 26.1.9 contains a stored cross-site scripting vulnerab ...)
-	TODO: check
+	NOT-FOR-US: OPNsense
 CVE-2026-48399 (Adobe Campaign Classic (ACC) is affected by a Violation of Secure Desi ...)
 	NOT-FOR-US: Adobe
 CVE-2026-48333 (Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization ...)
@@ -190,85 +190,85 @@ CVE-2026-48323 (Adobe Campaign Classic (ACC) is affected by an Improper Neutrali
 CVE-2026-48317 (Adobe Campaign Classic (ACC) is affected by an Improper Neutralization ...)
 	NOT-FOR-US: Adobe
 CVE-2026-48115 (Misskey is an open source, federated social media platform. All Misske ...)
-	TODO: check
+	NOT-FOR-US: Misskey
 CVE-2026-48113 (Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. ...)
-	TODO: check
+	NOT-FOR-US: Chisel
 CVE-2026-48063 (Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versi ...)
-	TODO: check
+	NOT-FOR-US: Baileys
 CVE-2026-48061 (Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. ...)
-	TODO: check
+	NOT-FOR-US: Litestar
 CVE-2026-48031 (go-base is a Go RESTful API Boilerplate template with JWT Authenticati ...)
-	TODO: check
+	NOT-FOR-US: dhax go-base
 CVE-2026-47746 (Misskey is an open source, federated social media platform. Versions 1 ...)
-	TODO: check
+	NOT-FOR-US: Misskey
 CVE-2026-47211 (Ouroboros is a local-first runtime for AI coding agents that records t ...)
-	TODO: check
+	NOT-FOR-US: Ouroboros (not the same as rust-ouroboros)
 CVE-2026-46714 (Misskey is an open source, federated social media platform. IVersions  ...)
-	TODO: check
+	NOT-FOR-US: Misskey
 CVE-2026-46713 (Misskey is an open source, federated social media platform. Versions 1 ...)
-	TODO: check
+	NOT-FOR-US: Misskey
 CVE-2026-46712 (Misskey is an open source, federated social media platform. Versions 2 ...)
-	TODO: check
+	NOT-FOR-US: Misskey
 CVE-2026-42169 (A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) ...)
 	TODO: check
 CVE-2026-41447 (FirmaCheck for Windows before 1.3.16 contains a dll hijacking vulnerab ...)
-	TODO: check
+	NOT-FOR-US: FirmaCheck for Windows
 CVE-2026-18739 (A flaw was found in popt, a command-line option parsing library. An of ...)
 	TODO: check
 CVE-2026-18738 (Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vu ...)
-	TODO: check
+	NOT-FOR-US: Shlink
 CVE-2026-18737 (Shlink contains a blind SQL injection vulnerability that allows any au ...)
-	TODO: check
+	NOT-FOR-US: Shlink
 CVE-2026-18736 (Shlink contains a server-side request forgery vulnerability that allow ...)
-	TODO: check
+	NOT-FOR-US: Shlink
 CVE-2026-18733 (A prompt injection vulnerability in the shell tool in Amazon Strands A ...)
 	NOT-FOR-US: Amazon
 CVE-2026-18723 (A vulnerability was determined in diaowen DWSurvey up to 6.14.0. The a ...)
-	TODO: check
+	NOT-FOR-US: diaowen DWSurvey
 CVE-2026-18722 (A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted i ...)
-	TODO: check
+	NOT-FOR-US: diaowen DWSurvey
 CVE-2026-18721 (A vulnerability has been found in kalcaddle kodbox 1.67 Build 02. This ...)
-	TODO: check
+	NOT-FOR-US: kalcaddle kodbox
 CVE-2026-18720 (A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerab ...)
-	TODO: check
+	NOT-FOR-US: kalcaddle kodbox
 CVE-2026-18719 (A vulnerability was detected in cemtan sar2html 4.0.0. This affects an ...)
-	TODO: check
+	NOT-FOR-US: cemtan sar2html
 CVE-2026-18686 (A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The aff ...)
-	TODO: check
+	NOT-FOR-US: GL.iNet
 CVE-2026-18685 (A security vulnerability has been detected in GL.iNet GL-MT3000 up to  ...)
-	TODO: check
+	NOT-FOR-US: GL.iNet
 CVE-2026-18684 (A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This  ...)
-	TODO: check
+	NOT-FOR-US: GL.iNet
 CVE-2026-18682 (A security flaw has been discovered in OpenAkita up to 1.27.12. This v ...)
-	TODO: check
+	NOT-FOR-US: OpenAkita
 CVE-2026-18667 (A vulnerability in Tenable Sensor Proxy allows a remote attacker to ex ...)
-	TODO: check
+	NOT-FOR-US: Tenable Sensor Proxy
 CVE-2026-18655 (Improper restriction of intended endpoints in the RabbitMQ broker conn ...)
 	NOT-FOR-US: Amazon
 CVE-2026-18654 (Key exchange without entity authentication in the EMR SSH helper comma ...)
 	NOT-FOR-US: Amazon
 CVE-2026-18648 (A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2. ...)
-	TODO: check
+	NOT-FOR-US: Blix Email Blue Mail Calendar App
 CVE-2026-18647 (A security vulnerability has been detected in jina-ai reader up to 157 ...)
-	TODO: check
+	NOT-FOR-US: jina-ai reader
 CVE-2026-18646 (A weakness has been identified in danpros HTMLy up to 3.1.1. This vuln ...)
-	TODO: check
+	NOT-FOR-US: HTMLy
 CVE-2026-18645 (A security flaw has been discovered in danpros HTMLy up to 3.1.1. This ...)
-	TODO: check
+	NOT-FOR-US: HTMLy
 CVE-2026-18644 (A vulnerability was identified in danpros HTMLy up to 3.1.1. Affected  ...)
-	TODO: check
+	NOT-FOR-US: HTMLy
 CVE-2026-18641 (A vulnerability was determined in Sangfor Operation and Maintenance Se ...)
-	TODO: check
+	NOT-FOR-US: Sangfor Operation and Maintenance Security Management System
 CVE-2026-18632 (A security flaw has been discovered in langgenius dify up to 1.14.2. T ...)
-	TODO: check
+	NOT-FOR-US: langgenius dify
 CVE-2026-18631 (A vulnerability was identified in jeequan jeepay up to 3.2.9. This vul ...)
-	TODO: check
+	NOT-FOR-US: jeequan jeepay
 CVE-2026-18569 (A flaw was found in the backchannel logout endpoint of the keycloak-se ...)
 	TODO: check
 CVE-2026-17614 (A path traversal flaw was found in WildFly's domain mode   implementat ...)
 	TODO: check
 CVE-2026-16881 (A code injection vulnerability exists in the LINE Android app prior to ...)
-	TODO: check
+	NOT-FOR-US: LINE Android app
 CVE-2026-16623 (The Create Block  WordPress plugin before 2.10.0 does not correctly es ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-16618 (The Improve SEO WordPress plugin through 2.0.11 does not properly vali ...)
@@ -316,9 +316,9 @@ CVE-2026-14816 (The GDPR Framework By Data443 WordPress plugin before 2.4.0 does
 CVE-2026-12698 (The wpForo Forum WordPress plugin before 3.1.3 does not restrict which ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-11836 (Insufficient verification of data authenticity in Caliptra Core ROM an ...)
-	TODO: check
+	NOT-FOR-US: Caliptra
 CVE-2026-11835 (Time-of-check time-of-use (TOCTOU) vulnerability combined with missing ...)
-	TODO: check
+	NOT-FOR-US: Caliptra
 CVE-2026-11366 (The MonsterInsights  WordPress plugin before 11.1.0 does not correctly ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-10849 (The hawkBit device management client in subsys/mgmt/hawkbit accumulate ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/be878ab829133409a13c2661eeb2057ae448e0b7

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/be878ab829133409a13c2661eeb2057ae448e0b7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260804/238a271b/attachment.htm>


More information about the debian-security-tracker-commits mailing list