[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 5 20:25:06 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e9807efd by Salvatore Bonaccorso at 2026-08-05T21:24:35+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -69,55 +69,55 @@ CVE-2026-7326 (A cross-site request forgery vulnerability in the Admin UI of Pro
 CVE-2026-7105 (The Xpro Addons plugin for WordPress is vulnerable to unauthorized cre ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-71294 (Cotonti CMS's Comments plugin deserializes user-supplied data without  ...)
-	TODO: check
+	NOT-FOR-US: Cotonti CMS
 CVE-2026-71293 (Statamic CMS's user-augmentation resolver, AugmentedUser::get() in src ...)
-	TODO: check
+	NOT-FOR-US: Statamic CMS
 CVE-2026-71292 (Subrion CMS's admin grid sorting helper, _gridGetSorting() in includes ...)
-	TODO: check
+	NOT-FOR-US: Subrion CMS
 CVE-2026-71291 (Bolt CMS renders content field values through Twig's full application- ...)
-	TODO: check
+	NOT-FOR-US: Bolt CMS
 CVE-2026-71289 (The NASA-AMMOS Asynchronous Network Management System (ANMS) reference ...)
-	TODO: check
+	NOT-FOR-US: NASA-AMMOS
 CVE-2026-71288 (Koha's guided report builder (reports/guided_reports.pl) reads the `or ...)
-	TODO: check
+	NOT-FOR-US: Koha Library Management System
 CVE-2026-71287 (Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-suppl ...)
 	TODO: check
 CVE-2026-71286 (The render-template component of ember-dynamic-render-template (addon/ ...)
-	TODO: check
+	NOT-FOR-US: ember-dynamic-render-template
 CVE-2026-71285 (Uptime Kuma's Matomo analytics integration (server/analytics/matomo-an ...)
-	TODO: check
+	NOT-FOR-US: Uptime Kuma
 CVE-2026-71284 (Fledge's backup-restore upload handler, upload_backup() (python/fledge ...)
-	TODO: check
+	NOT-FOR-US: Fledge
 CVE-2026-71283 (Fledge's backup-restore upload handler, upload_backup() (python/fledge ...)
-	TODO: check
+	NOT-FOR-US: Fledge
 CVE-2026-71282 (ChirpStack's SQLite-backend device tag filtering (chirpstack/src/stora ...)
-	TODO: check
+	NOT-FOR-US: ChirpStack
 CVE-2026-71281 (Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft ...)
-	TODO: check
+	NOT-FOR-US: Hugging Face peft
 CVE-2026-71280 (go-shiori's DownloadBookmark() (internal/core/download.go) fetches a c ...)
-	TODO: check
+	NOT-FOR-US: go-shiori
 CVE-2026-71279 (Zigbee2MQTT's ExternalJSExtension.getFilePath() (lib/extension/externa ...)
-	TODO: check
+	NOT-FOR-US: Zigbee2MQTT
 CVE-2026-71278 (rust-iot-platform allows creating a "calc rule" via POST /calc-rule/cr ...)
-	TODO: check
+	NOT-FOR-US: rust-iot-platform
 CVE-2026-71277 (rust-iot-platform's AuthToken request-guard implementation (api/src/ma ...)
-	TODO: check
+	NOT-FOR-US: rust-iot-platform
 CVE-2026-71276 (Magistrala (formerly Mainflux)'s message-readers API reads a `format`  ...)
-	TODO: check
+	NOT-FOR-US: Magistrala
 CVE-2026-71275 (OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects  ...)
-	TODO: check
+	NOT-FOR-US: OpenBK7231T
 CVE-2026-71274 (OpenBK7231T's CHANNEL_SetLabel() (src/cmnds/cmd_channels.c) stores cha ...)
-	TODO: check
+	NOT-FOR-US: OpenBK7231T
 CVE-2026-71273 (OpenBK7231T's /cfg_wifi_set endpoint (src/httpserver/http_fns.c) accep ...)
-	TODO: check
+	NOT-FOR-US: OpenBK7231T
 CVE-2026-71272 (Memos' webhook dispatch function safeDialContext() (internal/webhook/w ...)
-	TODO: check
+	NOT-FOR-US: Memos
 CVE-2026-71271 (Memos' webhook URL validation, isReservedIP() (internal/webhook/valida ...)
-	TODO: check
+	NOT-FOR-US: Memos
 CVE-2026-71270 (Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteTo ...)
-	TODO: check
+	NOT-FOR-US: Stirling-PDF
 CVE-2026-71269 (Node-RED's local-filesystem library storage module (getLibraryEntry()  ...)
-	TODO: check
+	NOT-FOR-US: Node-RED
 CVE-2026-71268 (OpenPLC Runtime v3's compile_program() function (webserver/openplc.py) ...)
 	TODO: check
 CVE-2026-71267 (microtar's mtar_write_file_header() and mtar_write_dir_header() functi ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e9807efd477d7e3968dca194825176e401045234

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e9807efd477d7e3968dca194825176e401045234
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260805/56ad7de3/attachment.htm>


More information about the debian-security-tracker-commits mailing list