[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 4 21:26:39 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ec027db9 by Salvatore Bonaccorso at 2026-08-04T22:26:04+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -87,9 +87,9 @@ CVE-2026-67196 (Perspective 5.0.0 contains a cross-site scripting vulnerability
 CVE-2026-67195 (Perspective 5.0.0 contains a remote code execution vulnerability that  ...)
 	NOT-FOR-US: Perspective
 CVE-2026-66884 (Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundatio ...)
-	TODO: check
+	NOT-FOR-US: Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.AuthorizationCallback module)
 CVE-2026-66883 (Improper Handling of Case Sensitivity vulnerability in Erlang Ecosyste ...)
-	TODO: check
+	NOT-FOR-US: Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.AuthorizationCallback module)
 CVE-2026-66300 (SNOMED International Snowstorm contains a reflected XSS vulnerability  ...)
 	NOT-FOR-US: SNOMED International Snowstorm
 CVE-2026-64634 (A vulnerability allowing local privilege escalation to the Reporter se ...)
@@ -204,31 +204,31 @@ CVE-2026-18830 (Insufficient input validation in Amazon Bedrock AgentCore harnes
 CVE-2026-18809 (Information disclosure in Firefox for Android and Firefox Focus for An ...)
 	TODO: check
 CVE-2026-18806 (External control of file name or path vulnerability in T\xdcB\u0130TAK ...)
-	TODO: check
+	NOT-FOR-US: pardus-image-writer
 CVE-2026-18801 (OpenMeter contains a stored, or second-order, SQL injection vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: OpenMeter
 CVE-2026-18790 (A weakness has been identified in Systerel S2OPC up to 1.7.3. This aff ...)
-	TODO: check
+	NOT-FOR-US: Systerel S2OPC
 CVE-2026-18788 (A security flaw has been discovered in Trippo ResponsiveFilemanager up ...)
-	TODO: check
+	NOT-FOR-US: Trippo ResponsiveFilemanager
 CVE-2026-18787 (A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affe ...)
-	TODO: check
+	NOT-FOR-US: GL.iNet
 CVE-2026-18785 (A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4 ...)
 	TODO: check
 CVE-2026-18784 (A vulnerability was found in o6 open62541 up to 1.5.5. This issue affe ...)
 	TODO: check
 CVE-2026-18775 (A vulnerability has been found in NousResearch hermes-agent up to 0.16 ...)
-	TODO: check
+	NOT-FOR-US: NousResearch
 CVE-2026-18774 (A flaw has been found in NousResearch hermes-agent up to 0.16.0. This  ...)
-	TODO: check
+	NOT-FOR-US: NousResearch
 CVE-2026-18773 (A vulnerability was detected in NousResearch hermes-agent up to 2026.6 ...)
-	TODO: check
+	NOT-FOR-US: NousResearch
 CVE-2026-18772 (Improper input validation vulnerability in Samsung Open Source rlottie ...)
 	TODO: check
 CVE-2026-18770 (A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d5 ...)
-	TODO: check
+	NOT-FOR-US: vibesurf-ai VibeSurf
 CVE-2026-18766 (A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5a ...)
-	TODO: check
+	NOT-FOR-US: chetans9 core-php-admin-panel
 CVE-2026-18759 (The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and i ...)
 	NOT-FOR-US: Asustor
 CVE-2026-18755 (A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local ...)
@@ -238,7 +238,7 @@ CVE-2026-18754 (The product firmware contains an embedded, static RSA private ke
 CVE-2026-18753 (The product firmware contains an embedded, static RSA private key util ...)
 	NOT-FOR-US: GeoVision
 CVE-2026-18650 (Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows  ...)
-	TODO: check
+	NOT-FOR-US: Liman MYS
 CVE-2026-18401 (The non-blocking (asynchronous) JSON parser in jackson-core does not e ...)
 	- jackson-core <unfixed>
 	NOTE: https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq
@@ -246,29 +246,29 @@ CVE-2026-18401 (The non-blocking (asynchronous) JSON parser in jackson-core does
 	NOTE: Fixed by: https://github.com/FasterXML/jackson-core/commit/b0c428e6f993e1b5ece5c1c3cb2523e887cd52cf (jackson-core-2.18.6)
 	NOTE: When fixing this issue make sure to make it complete to not open up CVE-2026-68494.
 CVE-2026-17070 (Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows  ...)
-	TODO: check
+	NOT-FOR-US: Liman MYS
 CVE-2026-15721 (Cleartext storage of sensitive information vulnerability in Bilin Soft ...)
-	TODO: check
+	NOT-FOR-US: HUMANIST Digital Human Resources
 CVE-2026-15314 (Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation ...)
 	NOT-FOR-US: TPLink
 CVE-2026-14838 (Use of GET request method with sensitive query strings vulnerability i ...)
-	TODO: check
+	NOT-FOR-US: HUMANIST Digital Human Resources
 CVE-2026-14804 (Use of hard-coded cryptographic key vulnerability in Bilin Software an ...)
-	TODO: check
+	NOT-FOR-US: HUMANIST Digital Human Resources
 CVE-2026-14465 (Insufficient session expiration vulnerability in Bilin Software and In ...)
-	TODO: check
+	NOT-FOR-US: HUMANIST Digital Human Resources
 CVE-2026-14337 (Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored ...)
-	TODO: check
+	NOT-FOR-US: Pega Platform
 CVE-2026-14219 (URL redirection to untrusted site ('open redirect') vulnerability in B ...)
-	TODO: check
+	NOT-FOR-US: HUMANIST Digital Human Resources
 CVE-2026-14202 (Observable response discrepancy vulnerability in Bilin Software and In ...)
-	TODO: check
+	NOT-FOR-US: HUMANIST Digital Human Resources
 CVE-2026-14194 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
-	TODO: check
+	NOT-FOR-US: HUMANIST Digital Human Resources
 CVE-2026-14192 (Improper neutralization of input during web page generation ('cross-si ...)
-	TODO: check
+	NOT-FOR-US: HUMANIST Digital Human Resources
 CVE-2026-14175 (Unrestricted upload of file with dangerous type vulnerability in Bilin ...)
-	TODO: check
+	NOT-FOR-US: HUMANIST Digital Human Resources
 CVE-2026-13229 (Zammad 7.1.0 contains an authenticated improper authorization vulnerab ...)
 	TODO: check
 CVE-2026-11368 (The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates  ...)
@@ -280,13 +280,13 @@ CVE-2026-10709 (A maliciously crafted FBX file, when parsed through Autodesk FBX
 CVE-2026-10050 (In Eclipse Jetty, the Digest authentication server-side component uses ...)
 	TODO: check
 CVE-2026-10032 (The openUrl function in @a2ui/web_core passes an agent-controlled URL  ...)
-	TODO: check
+	NOT-FOR-US: a2ui/web_core passes
 CVE-2025-29296 (H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V10 ...)
-	TODO: check
+	NOT-FOR-US: H3C
 CVE-2017-20242 (Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buff ...)
-	TODO: check
+	NOT-FOR-US: Keysight IxChariot Endpoint
 CVE-2017-20241 (Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffe ...)
-	TODO: check
+	NOT-FOR-US: Keysight IxChariot Endpoint
 CVE-2026-15920 (An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0 ...)
 	- python-django <unfixed> (bug #1143611)
 	NOTE: https://www.djangoproject.com/weblog/2026/aug/04/security-releases/



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ec027db9b2cc3d4823992bbab97f325a1763ca67

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ec027db9b2cc3d4823992bbab97f325a1763ca67
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260804/772172a2/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list