[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Aug 5 20:41:00 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
1fb40135 by Salvatore Bonaccorso at 2026-08-05T21:40:19+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -119,75 +119,75 @@ CVE-2026-71270 (Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWeb
CVE-2026-71269 (Node-RED's local-filesystem library storage module (getLibraryEntry() ...)
NOT-FOR-US: Node-RED
CVE-2026-71268 (OpenPLC Runtime v3's compile_program() function (webserver/openplc.py) ...)
- TODO: check
+ NOT-FOR-US: OpenPLC
CVE-2026-71267 (microtar's mtar_write_file_header() and mtar_write_dir_header() functi ...)
- TODO: check
+ NOT-FOR-US: microtar
CVE-2026-71266 (tinyobjloader-c's tinyobj_parse_and_index_mtl_file() (tinyobj_loader_c ...)
TODO: check
CVE-2026-71265 (Domoticz's MochadTCP::MatchLine() handler for MOCHAD_RFSEC messages (h ...)
TODO: check
CVE-2026-71264 (WLED's GET /json/cfg endpoint (registered in wled00/wled_server.cpp) c ...)
- TODO: check
+ NOT-FOR-US: WLED
CVE-2026-71263 (The LINUXTCP port of FreeModbus contains an off-by-one bounds check in ...)
TODO: check
CVE-2026-71262 (IoTSharp BlobStorageController.cs lacks the [Authorize] attribute appl ...)
- TODO: check
+ NOT-FOR-US: IoTSharp
CVE-2026-71261 (dr_libs dr_wav.h (all versions through current master) contains an int ...)
TODO: check
CVE-2026-71260 (ESPHome through 2026.7.0-dev discloses plaintext passwords via its web ...)
- TODO: check
+ NOT-FOR-US: ESPHome
CVE-2026-71259 (ESPHome through 2026.7.0-dev contains an operator-precedence bug in th ...)
- TODO: check
+ NOT-FOR-US: ESPHome
CVE-2026-71256 (nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leadin ...)
- TODO: check
+ NOT-FOR-US: nanoMODBUS
CVE-2026-71255 (nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modb ...)
- TODO: check
+ NOT-FOR-US: nanoMODBUS
CVE-2026-71254 (nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modb ...)
- TODO: check
+ NOT-FOR-US: nanoMODBUS
CVE-2026-71252 (toner-management's admin state-changing handlers (add.php, edit.php, d ...)
- TODO: check
+ NOT-FOR-US: toner-management
CVE-2026-71251 (Akaunting's shared download route (app/Http/Controllers/Common/Uploads ...)
- TODO: check
+ NOT-FOR-US: Akaunting
CVE-2026-71250 (Firefly III's webhook URL validator (IsValidWebhookUrl.php) filters mo ...)
- TODO: check
+ NOT-FOR-US: Firefly
CVE-2026-71249 (299Ko's public contact form (plugin/contact/controllers/ContactControl ...)
- TODO: check
+ NOT-FOR-US: 299Ko public contact form
CVE-2026-71248 (Inventory-Management-System-PHP's login.php constructs its authenticat ...)
- TODO: check
+ NOT-FOR-US: Inventory-Management-System-PHP
CVE-2026-71247 (Documenso's sign-field-with-token.ts, used by the live document-signin ...)
- TODO: check
+ NOT-FOR-US: Documenso
CVE-2026-71246 (Pixelfed's SearchController (behind the auth middleware) accepts a URL ...)
- TODO: check
+ NOT-FOR-US: Pixelfed
CVE-2026-71245 (Mautic's getLeadIdsByFieldValueAction (LeadBundle/Controller/AjaxContr ...)
- TODO: check
+ NOT-FOR-US: Mautic
CVE-2026-71244 (Paperless-ngx's MailAccountViewSet.test() action, when called with an ...)
- TODO: check
+ NOT-FOR-US: Paperless-ngx
CVE-2026-71243 (The backmeup npm package assembles shell command strings by directly c ...)
- TODO: check
+ NOT-FOR-US: backmeup npm package
CVE-2026-71242 (Crater's NotePolicy checks only a blanket Bouncer ability (manage-all- ...)
- TODO: check
+ NOT-FOR-US: Crater
CVE-2026-71241 (Book-Management-System's Flask API endpoints /student, /record, /books ...)
- TODO: check
+ NOT-FOR-US: Book-Management-System
CVE-2026-71240 (DjangoCRM's toggle_default_sorting view is the only route in common/ur ...)
- TODO: check
+ NOT-FOR-US: DjangoCRM
CVE-2026-71239 (DjangoCRM's massmail module renders user-controlled EmlMessage fields ...)
- TODO: check
+ NOT-FOR-US: DjangoCRM
CVE-2026-71238 (DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the c ...)
- TODO: check
+ NOT-FOR-US: DjangoCRM
CVE-2026-71237 (Miantang/IoT-PHP's index.php implements a POST /userlogin route that r ...)
- TODO: check
+ NOT-FOR-US: Miantang/IoT-PHP
CVE-2026-71236 (Grocy's API request-body parser (controllers/Api/BaseApiController.php ...)
TODO: check
CVE-2026-71235 (Magistrala's Rules Engine allows authenticated users to create rules w ...)
- TODO: check
+ NOT-FOR-US: Magistrala
CVE-2026-71234 (Documize Community's attachment download route (domain/attachment/endp ...)
- TODO: check
+ NOT-FOR-US: Documize
CVE-2026-71233 (InvoiceNinja v5-stable renders an invoice or quote's "terms" field in ...)
- TODO: check
+ NOT-FOR-US: InvoiceNinja
CVE-2026-71232 (MacCMS10's admin template editor (application/admin/controller/Templat ...)
- TODO: check
+ NOT-FOR-US: MacCMS10
CVE-2026-71231 (IOTSmartHome's gui/login.php checkCookie() function builds an authenti ...)
- TODO: check
+ NOT-FOR-US: IOTSmartHome
CVE-2026-71227 (A flaw was found in libkcapi. A local attacker can influence an applic ...)
TODO: check
CVE-2026-71226 (Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1fb40135ad821a5724781db3c325b7f41df78fb7
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1fb40135ad821a5724781db3c325b7f41df78fb7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260805/44dd8502/attachment.htm>
More information about the debian-security-tracker-commits
mailing list