[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Aug 4 20:13:05 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
4d426331 by security tracker role at 2026-08-04T19:12:58+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,16 +1,290 @@
-CVE-2026-15920 [Potential cross-site scripting via URLField values in the admin]
+CVE-2026-70474 (Flowise is a drag-and-drop user interface for building customized larg ...)
+ TODO: check
+CVE-2026-70473 (Flowise is a drag-and-drop user interface for building customized larg ...)
+ TODO: check
+CVE-2026-70472 (Flowise is a drag & drop user interface to build a customized large la ...)
+ TODO: check
+CVE-2026-70471 (Flowise is a drag-and-drop user interface for building customized larg ...)
+ TODO: check
+CVE-2026-70470 (Flowise is a drag & drop user interface to build a customized large la ...)
+ TODO: check
+CVE-2026-70373 (Koha's reports/issues_stats.pl (the circulation statistics report) bui ...)
+ TODO: check
+CVE-2026-70372 (Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate b ...)
+ TODO: check
+CVE-2026-70371 (Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate ...)
+ TODO: check
+CVE-2026-70370 (Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate ...)
+ TODO: check
+CVE-2026-70369 (Koha's reports/acquisitions_stats.pl builds its per-cell statistics qu ...)
+ TODO: check
+CVE-2026-70368 (A stack-based out-of-bounds read vulnerability exists in the "s_vlog" ...)
+ TODO: check
+CVE-2026-70367 (A Server-Side Request Forgery (SSRF) bypass vulnerability exists in \u ...)
+ TODO: check
+CVE-2026-69704 (Atals-Livre contains a SQL injection vulnerability that allows attacke ...)
+ TODO: check
+CVE-2026-69703 (Atlas-Livre contains an improper access control vulnerability in the a ...)
+ TODO: check
+CVE-2026-69702 (SnailJob 1.7.0 contains a denial of service vulnerability in the FuryU ...)
+ TODO: check
+CVE-2026-69264 (Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled s ...)
+ TODO: check
+CVE-2026-69263 (Flowise is a drag & drop user interface to build a customized large la ...)
+ TODO: check
+CVE-2026-69262 (Flowise is a drag & drop user interface to build a customized large la ...)
+ TODO: check
+CVE-2026-69259 (Flowise is a drag & drop user interface to build a customized large la ...)
+ TODO: check
+CVE-2026-69258 (Flowise is a drag & drop user interface to build a customized large la ...)
+ TODO: check
+CVE-2026-69257 (Flowise is a drag & drop user interface to build a customized large la ...)
+ TODO: check
+CVE-2026-69256 (Flowise is a drag & drop user interface to build a customized large la ...)
+ TODO: check
+CVE-2026-69255 (Flowise is a drag & drop user interface to build a customized large la ...)
+ TODO: check
+CVE-2026-69254 (Flowise is a drag & drop user interface to build a customized large la ...)
+ TODO: check
+CVE-2026-69253 (Flowise is a drag-and-drop user interface for building customized larg ...)
+ TODO: check
+CVE-2026-69252 (Flowise is a drag & drop user interface to build a customized large la ...)
+ TODO: check
+CVE-2026-69251 (Flowise is a drag & drop user interface to build a customized large la ...)
+ TODO: check
+CVE-2026-69250 (Flowise is a drag & drop user interface to build a customized large la ...)
+ TODO: check
+CVE-2026-69110 (OpenCode Studio before 2.4.4 contains a missing authentication vulnera ...)
+ TODO: check
+CVE-2026-69100 (LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27 ...)
+ TODO: check
+CVE-2026-69098 (kotaemon through 0.12.0 contains an insecure deserialization vulnerabi ...)
+ TODO: check
+CVE-2026-68743 (A flaw was found in SSSD. The extract_authtok_v1() function in the PAM ...)
+ TODO: check
+CVE-2026-68494 (The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 ...)
+ TODO: check
+CVE-2026-67618 (marimo before 0.23.15 contains a configuration injection vulnerability ...)
+ TODO: check
+CVE-2026-67243 (freo2 provided by refirio contains an unrestricted upload of file with ...)
+ TODO: check
+CVE-2026-67200 (Perspective 5.0.0 contains a path traversal vulnerability that allows ...)
+ TODO: check
+CVE-2026-67199 (Perspective 5.0.0 contains a denial of service vulnerability that allo ...)
+ TODO: check
+CVE-2026-67198 (Perspective 5.0.0 contains a denial-of-service vulnerability in the Vi ...)
+ TODO: check
+CVE-2026-67196 (Perspective 5.0.0 contains a cross-site scripting vulnerability in the ...)
+ TODO: check
+CVE-2026-67195 (Perspective 5.0.0 contains a remote code execution vulnerability that ...)
+ TODO: check
+CVE-2026-66884 (Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundatio ...)
+ TODO: check
+CVE-2026-66883 (Improper Handling of Case Sensitivity vulnerability in Erlang Ecosyste ...)
+ TODO: check
+CVE-2026-66300 (SNOMED International Snowstorm contains a reflected XSS vulnerability ...)
+ TODO: check
+CVE-2026-64634 (A vulnerability allowing local privilege escalation to the Reporter se ...)
+ TODO: check
+CVE-2026-64633 (A vulnerability allowing remote unauthenticated code execution on the ...)
+ TODO: check
+CVE-2026-64631 (A vulnerability allowing a low-privileged user to inject SQL and extra ...)
+ TODO: check
+CVE-2026-64630 (A vulnerability allowing a low-privileged user to retrieve report data ...)
+ TODO: check
+CVE-2026-63456 (Multiple vulnerabilities in the REST API interface of HPE Networking S ...)
+ TODO: check
+CVE-2026-63455 (Multiple vulnerabilities in the REST API interface of HPE Networking S ...)
+ TODO: check
+CVE-2026-63252 (In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport ha ...)
+ TODO: check
+CVE-2026-63248 (In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostic ...)
+ TODO: check
+CVE-2026-62927 (In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatc ...)
+ TODO: check
+CVE-2026-61515 (Puwell IP Camera firmware versions 2.x through 4.x contains an unauthe ...)
+ TODO: check
+CVE-2026-61514 (Puwell IP Camera firmware versions 2.x through 4.x contains an authent ...)
+ TODO: check
+CVE-2026-61387 (In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota acc ...)
+ TODO: check
+CVE-2026-60007 (In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processin ...)
+ TODO: check
+CVE-2026-58080 (In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy( ...)
+ TODO: check
+CVE-2026-58075 (A vulnerability allowing an unauthenticated attacker to read arbitrary ...)
+ TODO: check
+CVE-2026-58074 (A vulnerability allowing a high-privileged user to execute arbitrary c ...)
+ TODO: check
+CVE-2026-58073 (A vulnerability in Veeam Service Provider Console allowing an unauthen ...)
+ TODO: check
+CVE-2026-58072 (A vulnerability in Veeam Service Provider Console allowing arbitrary f ...)
+ TODO: check
+CVE-2026-58071 (A vulnerability in Veeam Service Provider Console allowing an unauthen ...)
+ TODO: check
+CVE-2026-58067 (A vulnerability in Veeam Service Provider Console allowing an unauthen ...)
+ TODO: check
+CVE-2026-49435 (Keysight IxChariot Endpoint and associated products contain a stack-ba ...)
+ TODO: check
+CVE-2026-48121 (@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js Checkp ...)
+ TODO: check
+CVE-2026-47781 (PDM is a Python package and dependency manager. In versions up to and ...)
+ TODO: check
+CVE-2026-47764 (pdm is a Python package and dependency manager supporting the latest P ...)
+ TODO: check
+CVE-2026-47763 (pdm is a Python package and dependency manager supporting the latest P ...)
+ TODO: check
+CVE-2026-47623 (NVIDIA Dynamo for Linux contains a vulnerability where an attacker cou ...)
+ TODO: check
+CVE-2026-47622 (NVIDIA Dynamo for Linux contains a vulnerability where an attacker cou ...)
+ TODO: check
+CVE-2026-47621 (NVIDIA Dynamo for Linux contains a vulnerability where an attacker cou ...)
+ TODO: check
+CVE-2026-47620 (NVIDIA Dynamo for Linux contains a vulnerability where an attacker cou ...)
+ TODO: check
+CVE-2026-47619 (NVIDIA Dynamo for Linux examples and recipes contain a vulnerability w ...)
+ TODO: check
+CVE-2026-47618 (NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimoda ...)
+ TODO: check
+CVE-2026-47617 (NVIDIA Dynamo for Linux contains a vulnerability in the multimodal med ...)
+ TODO: check
+CVE-2026-47616 (NVIDIA Dynamo for Linux contains a vulnerability in the multimodal med ...)
+ TODO: check
+CVE-2026-47615 (NVIDIA Dynamo for Linux contains a vulnerability where an attacker may ...)
+ TODO: check
+CVE-2026-47614 (NVIDIA Dynamo for Linux contains a vulnerability where an attacker may ...)
+ TODO: check
+CVE-2026-47613 (NVIDIA Dynamo for Linux contains a vulnerability where an attacker may ...)
+ TODO: check
+CVE-2026-47612 (NVIDIA Dynamo for Linux contains a vulnerability in the image loading ...)
+ TODO: check
+CVE-2026-47487 (NVIDIA Triton Inference Server for Linux contains a vulnerability wher ...)
+ TODO: check
+CVE-2026-25292 (Memory Corruption when processing untrusted user input in the fastboot ...)
+ TODO: check
+CVE-2026-25289 (Memory Corruption when processing Device Capability Extended attribute ...)
+ TODO: check
+CVE-2026-25288 (Transient DOS when processing a short target wake time channel usage r ...)
+ TODO: check
+CVE-2026-24255 (NVIDIA Dynamo for Linux contains a vulnerability in the multimodal emb ...)
+ TODO: check
+CVE-2026-24254 (NVIDIA Dynamo for Linux contains a vulnerability in the multimodal ser ...)
+ TODO: check
+CVE-2026-24253 (NVIDIA Dynamo for Linux contains a vulnerability where an attacker cou ...)
+ TODO: check
+CVE-2026-24084 (Weak configuration when UE does not verify the consistency of its addi ...)
+ TODO: check
+CVE-2026-24083 (Memory Corruption while processing IOCTL device driver requests with i ...)
+ TODO: check
+CVE-2026-24080 (Memory Corruption when handling malformed request parameters in the fi ...)
+ TODO: check
+CVE-2026-24079 (Cryptographic Issue while processing registration requests with malfor ...)
+ TODO: check
+CVE-2026-24078 (Information Disclosure when IPSec negotiation fails or is not establis ...)
+ TODO: check
+CVE-2026-24077 (Information Disclosure when processing wireless network channel switch ...)
+ TODO: check
+CVE-2026-24076 (Memory Corruption when processing registry values with incorrect types ...)
+ TODO: check
+CVE-2026-21366 (Memory corruption while processing a packet with a size close to the m ...)
+ TODO: check
+CVE-2026-18830 (Insufficient input validation in Amazon Bedrock AgentCore harness migh ...)
+ TODO: check
+CVE-2026-18809 (Information disclosure in Firefox for Android and Firefox Focus for An ...)
+ TODO: check
+CVE-2026-18806 (External control of file name or path vulnerability in T\xdcB\u0130TAK ...)
+ TODO: check
+CVE-2026-18801 (OpenMeter contains a stored, or second-order, SQL injection vulnerabil ...)
+ TODO: check
+CVE-2026-18790 (A weakness has been identified in Systerel S2OPC up to 1.7.3. This aff ...)
+ TODO: check
+CVE-2026-18788 (A security flaw has been discovered in Trippo ResponsiveFilemanager up ...)
+ TODO: check
+CVE-2026-18787 (A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affe ...)
+ TODO: check
+CVE-2026-18785 (A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4 ...)
+ TODO: check
+CVE-2026-18784 (A vulnerability was found in o6 open62541 up to 1.5.5. This issue affe ...)
+ TODO: check
+CVE-2026-18775 (A vulnerability has been found in NousResearch hermes-agent up to 0.16 ...)
+ TODO: check
+CVE-2026-18774 (A flaw has been found in NousResearch hermes-agent up to 0.16.0. This ...)
+ TODO: check
+CVE-2026-18773 (A vulnerability was detected in NousResearch hermes-agent up to 2026.6 ...)
+ TODO: check
+CVE-2026-18772 (Improper input validation vulnerability in Samsung Open Source rlottie ...)
+ TODO: check
+CVE-2026-18770 (A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d5 ...)
+ TODO: check
+CVE-2026-18766 (A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5a ...)
+ TODO: check
+CVE-2026-18759 (The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and i ...)
+ TODO: check
+CVE-2026-18755 (A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local ...)
+ TODO: check
+CVE-2026-18754 (The product firmware contains an embedded, static RSA private key util ...)
+ TODO: check
+CVE-2026-18753 (The product firmware contains an embedded, static RSA private key util ...)
+ TODO: check
+CVE-2026-18650 (Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows ...)
+ TODO: check
+CVE-2026-18401 (The non-blocking (asynchronous) JSON parser in jackson-core does not e ...)
+ TODO: check
+CVE-2026-17070 (Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows ...)
+ TODO: check
+CVE-2026-15721 (Cleartext storage of sensitive information vulnerability in Bilin Soft ...)
+ TODO: check
+CVE-2026-15314 (Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation ...)
+ TODO: check
+CVE-2026-14838 (Use of GET request method with sensitive query strings vulnerability i ...)
+ TODO: check
+CVE-2026-14804 (Use of hard-coded cryptographic key vulnerability in Bilin Software an ...)
+ TODO: check
+CVE-2026-14465 (Insufficient session expiration vulnerability in Bilin Software and In ...)
+ TODO: check
+CVE-2026-14337 (Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored ...)
+ TODO: check
+CVE-2026-14219 (URL redirection to untrusted site ('open redirect') vulnerability in B ...)
+ TODO: check
+CVE-2026-14202 (Observable response discrepancy vulnerability in Bilin Software and In ...)
+ TODO: check
+CVE-2026-14194 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
+ TODO: check
+CVE-2026-14192 (Improper neutralization of input during web page generation ('cross-si ...)
+ TODO: check
+CVE-2026-14175 (Unrestricted upload of file with dangerous type vulnerability in Bilin ...)
+ TODO: check
+CVE-2026-13229 (Zammad 7.1.0 contains an authenticated improper authorization vulnerab ...)
+ TODO: check
+CVE-2026-11368 (The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates ...)
+ TODO: check
+CVE-2026-10710 (A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, ...)
+ TODO: check
+CVE-2026-10709 (A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, ...)
+ TODO: check
+CVE-2026-10050 (In Eclipse Jetty, the Digest authentication server-side component uses ...)
+ TODO: check
+CVE-2026-10032 (The openUrl function in @a2ui/web_core passes an agent-controlled URL ...)
+ TODO: check
+CVE-2025-29296 (H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V10 ...)
+ TODO: check
+CVE-2017-20242 (Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buff ...)
+ TODO: check
+CVE-2017-20241 (Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffe ...)
+ TODO: check
+CVE-2026-15920 (An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0 ...)
- python-django <unfixed>
NOTE: https://www.djangoproject.com/weblog/2026/aug/04/security-releases/
NOTE: Fixed by: https://github.com/django/django/commit/b9adb81339cc418f8f56b1050cca6dfec3ab6349 (5.2.17)
-CVE-2026-15830 [Potential denial-of-service vulnerability via nested geometry collections]
+CVE-2026-15830 (An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0 ...)
- python-django <unfixed>
NOTE: https://www.djangoproject.com/weblog/2026/aug/04/security-releases/
NOTE: Fixed by: https://github.com/django/django/commit/ba80833fa656dd09660b97c4429331067db1b080 (5.2.17)
-CVE-2026-15337 [Potential denial-of-service vulnerability in check_for_language()]
+CVE-2026-15337 (An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0 ...)
- python-django <unfixed>
NOTE: https://www.djangoproject.com/weblog/2026/aug/04/security-releases/
NOTE: Fixed by: https://github.com/django/django/commit/c72a5dbb64d0777f3f471f1be94e8b2ca91e0959 (5.2.17)
-CVE-2026-15307 [Server-side file-write and request forgery via spatial lookups]
+CVE-2026-15307 (An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0 ...)
- python-django <unfixed>
NOTE: https://www.djangoproject.com/weblog/2026/aug/04/security-releases/
NOTE: Fixed by: https://github.com/django/django/commit/115ffd0463a765ab1cc93de18e94b5459b8a300e (5.2.17)
@@ -2483,7 +2757,7 @@ CVE-2026-58042 (A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js
CVE-2026-58041 (A flaw in Node.js node:sqlite allows a stale StatementSyncIterator cre ...)
- nodejs <unfixed>
NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#nodesqlite-sqltagstore-iterator-replay-can-re-execute-writes-cve-2026-58041---medium
-CVE-2026-56848
+CVE-2026-56848 (A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` ...)
- nodejs <unfixed>
NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#http2-re-entrant-send-can-cause-heap-use-after-free-cve-2026-56848---high
CVE-2026-56846 (A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blo ...)
@@ -32481,7 +32755,8 @@ CVE-2026-13426 (The Mattermost Go module github.com/mattermost/mattermost/server
NOT-FOR-US: Mattermost Go module
CVE-2026-13372 (Incorrect link resolution by display name in the custom PowerShell VPN ...)
NOT-FOR-US: Devolutions
-CVE-2026-13325 (A flaw was found in KubeVirt's migration proxy. When spec.configuratio ...)
+CVE-2026-13325
+ REJECTED
NOT-FOR-US: KubeVirt
CVE-2026-12411 (Broken Access Control in the devLXDInstancePatchHandler component of C ...)
- lxd <not-affected> (Only affects LXD 6.6 and later)
@@ -39802,7 +40077,7 @@ CVE-2026-47178 (libheif is a HEIF and AVIF file format decoder and encoder. In v
NOTE: Fixed by: https://github.com/strukturag/libheif/commit/62d60530610110fc7bc6d08ff30f2cf23917a1eb (v1.22.0)
CVE-2026-46655
NOT-FOR-US: virtio drivers for Windows
-CVE-2026-0163
+CVE-2026-0163 (In multiple functions of vpu_ioctl.c, there is a possible use after fr ...)
NOT-FOR-US: Intel vpu driver
NOTE: https://project-zero.issues.chromium.org/issues/493643407
CVE-2026-8317
@@ -80370,7 +80645,7 @@ CVE-2026-39110 (SQL Injection vulnerability in Apartment Visitors Management Sys
NOT-FOR-US: Apartment Visitors Management System
CVE-2026-39109 (SQL Injection vulnerability in Apartment Visitors Management System Ap ...)
NOT-FOR-US: Apartment Visitors Management System
-CVE-2026-35154 (Dell PowerProtect Data Domain appliances, versions 7.7.1.0 through 8.7 ...)
+CVE-2026-35154 (Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through ...)
NOT-FOR-US: Dell / EMC
CVE-2026-34429 (Vvveb prior to1.0.8.1 contains a stored cross-site scripting vulnerabi ...)
NOT-FOR-US: Vvveb
@@ -81017,13 +81292,13 @@ CVE-2026-3464 (The WP Customer Area plugin for WordPress is vulnerable to arbitr
NOT-FOR-US: WordPress plugin
CVE-2026-37749 (A SQL injection vulnerability in CodeAstro Simple Attendance Managemen ...)
NOT-FOR-US: CodeAstro
-CVE-2026-35153 (Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS20 ...)
+CVE-2026-35153 (Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through ...)
NOT-FOR-US: Dell / EMC
-CVE-2026-35074 (Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS20 ...)
+CVE-2026-35074 (Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through ...)
NOT-FOR-US: Dell / EMC
-CVE-2026-35073 (Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS20 ...)
+CVE-2026-35073 (Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through ...)
NOT-FOR-US: Dell / EMC
-CVE-2026-35072 (Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS20 ...)
+CVE-2026-35072 (Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through ...)
NOT-FOR-US: Dell / EMC
CVE-2026-33392 (In JetBrains YouTrack before 2025.3.131383 high privileged user can ac ...)
NOT-FOR-US: JetBrains
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4d426331543264d6a5a54c828103233ccd952265
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4d426331543264d6a5a54c828103233ccd952265
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260804/a5228bd1/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list