[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 5 10:11:36 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1cd76a84 by Salvatore Bonaccorso at 2026-08-05T11:11:21+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -133,21 +133,21 @@ CVE-2026-67588 (A pre-authentication attacker could leverage unbounded symbol va
 	- qpid-proton <unfixed>
 	NOTE: https://lists.apache.org/thread/vk4j02dzggfdrdkwvzmqo4jro2tgj0jt
 CVE-2026-67555 (It was not possible to govern the maximum number of transfer frames pe ...)
-	TODO: check
+	NOT-FOR-US: Apache Qpid Proton-Dotnet
 CVE-2026-67554 (An authenticated attacker can craft a disposition frame with large or  ...)
-	TODO: check
+	NOT-FOR-US: Apache Qpid Proton-Dotnet
 CVE-2026-67553 (An authenticated attacker could exceed the session flow control incomi ...)
-	TODO: check
+	NOT-FOR-US: Apache Qpid Proton-Dotnet
 CVE-2026-67552 (A pre-authentication attacker could leverage type nesting to cause a S ...)
-	TODO: check
+	NOT-FOR-US: Apache Qpid Proton-Dotnet
 CVE-2026-67551 (pre-authentication attacker could leverage type size/count handling to ...)
-	TODO: check
+	NOT-FOR-US: Apache Qpid Proton-Dotnet
 CVE-2026-67465 (A pre-authentication attacker could leverage unbounded symbol value ca ...)
-	TODO: check
+	NOT-FOR-US: Apache Qpid Proton-Dotnet
 CVE-2026-66839 (NetKids iMark, provided by Integrated Systems Technologies, Inc., cont ...)
-	TODO: check
+	NOT-FOR-US: NetKids iMark
 CVE-2026-66344 (NetKids iMark, provided by Integrated Systems Technologies, Inc., cont ...)
-	TODO: check
+	NOT-FOR-US: NetKids iMark
 CVE-2026-66277 (It was not possible to govern the maximum number of transfer frames pe ...)
 	- qpid-java <itp> (bug #840131)
 CVE-2026-66276 (An authenticated attacker can craft a disposition frame with large or  ...)
@@ -161,13 +161,13 @@ CVE-2026-66273 (A pre-authentication attacker could leverage type size/count han
 CVE-2026-66257 (A pre-authentication attacker could leverage unbounded symbol value ca ...)
 	- qpid-java <itp> (bug #840131)
 CVE-2026-65986 (CVAT is an open source interactive video and image annotation tool for ...)
-	TODO: check
+	NOT-FOR-US: Computer Vision Annotation Tool (CVAT)
 CVE-2026-5062 (The PrettyLinks \u2013 Affiliate Links, Link Branding, Link Tracking,  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-54020 (Open WebUI is an extensible, feature-rich, and user-friendly self-host ...)
-	TODO: check
+	NOT-FOR-US: Open WebUI
 CVE-2026-52370 (A reflected cross-site scripting (XSS) vulnerability in the Forum post ...)
-	TODO: check
+	NOT-FOR-US: O2OA
 CVE-2026-51401 (An issue in Vim Project v9.2.0389 and earlier allows a local attacker  ...)
 	TODO: check
 CVE-2026-51400 (An issue in Vim Project v9.2.0389 and earlier allows a local attacker  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1cd76a840ecff5b282bf1b9d842b7d9983a92508

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1cd76a840ecff5b282bf1b9d842b7d9983a92508
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260805/3a988392/attachment.htm>


More information about the debian-security-tracker-commits mailing list