[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 5 20:41:00 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1fb40135 by Salvatore Bonaccorso at 2026-08-05T21:40:19+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -119,75 +119,75 @@ CVE-2026-71270 (Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWeb
 CVE-2026-71269 (Node-RED's local-filesystem library storage module (getLibraryEntry()  ...)
 	NOT-FOR-US: Node-RED
 CVE-2026-71268 (OpenPLC Runtime v3's compile_program() function (webserver/openplc.py) ...)
-	TODO: check
+	NOT-FOR-US: OpenPLC
 CVE-2026-71267 (microtar's mtar_write_file_header() and mtar_write_dir_header() functi ...)
-	TODO: check
+	NOT-FOR-US: microtar
 CVE-2026-71266 (tinyobjloader-c's tinyobj_parse_and_index_mtl_file() (tinyobj_loader_c ...)
 	TODO: check
 CVE-2026-71265 (Domoticz's MochadTCP::MatchLine() handler for MOCHAD_RFSEC messages (h ...)
 	TODO: check
 CVE-2026-71264 (WLED's GET /json/cfg endpoint (registered in wled00/wled_server.cpp) c ...)
-	TODO: check
+	NOT-FOR-US: WLED
 CVE-2026-71263 (The LINUXTCP port of FreeModbus contains an off-by-one bounds check in ...)
 	TODO: check
 CVE-2026-71262 (IoTSharp BlobStorageController.cs lacks the [Authorize] attribute appl ...)
-	TODO: check
+	NOT-FOR-US: IoTSharp
 CVE-2026-71261 (dr_libs dr_wav.h (all versions through current master) contains an int ...)
 	TODO: check
 CVE-2026-71260 (ESPHome through 2026.7.0-dev discloses plaintext passwords via its web ...)
-	TODO: check
+	NOT-FOR-US: ESPHome
 CVE-2026-71259 (ESPHome through 2026.7.0-dev contains an operator-precedence bug in th ...)
-	TODO: check
+	NOT-FOR-US: ESPHome
 CVE-2026-71256 (nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leadin ...)
-	TODO: check
+	NOT-FOR-US: nanoMODBUS
 CVE-2026-71255 (nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modb ...)
-	TODO: check
+	NOT-FOR-US: nanoMODBUS
 CVE-2026-71254 (nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modb ...)
-	TODO: check
+	NOT-FOR-US: nanoMODBUS
 CVE-2026-71252 (toner-management's admin state-changing handlers (add.php, edit.php, d ...)
-	TODO: check
+	NOT-FOR-US: toner-management
 CVE-2026-71251 (Akaunting's shared download route (app/Http/Controllers/Common/Uploads ...)
-	TODO: check
+	NOT-FOR-US: Akaunting
 CVE-2026-71250 (Firefly III's webhook URL validator (IsValidWebhookUrl.php) filters mo ...)
-	TODO: check
+	NOT-FOR-US: Firefly
 CVE-2026-71249 (299Ko's public contact form (plugin/contact/controllers/ContactControl ...)
-	TODO: check
+	NOT-FOR-US: 299Ko public contact form
 CVE-2026-71248 (Inventory-Management-System-PHP's login.php constructs its authenticat ...)
-	TODO: check
+	NOT-FOR-US: Inventory-Management-System-PHP
 CVE-2026-71247 (Documenso's sign-field-with-token.ts, used by the live document-signin ...)
-	TODO: check
+	NOT-FOR-US: Documenso
 CVE-2026-71246 (Pixelfed's SearchController (behind the auth middleware) accepts a URL ...)
-	TODO: check
+	NOT-FOR-US: Pixelfed
 CVE-2026-71245 (Mautic's getLeadIdsByFieldValueAction (LeadBundle/Controller/AjaxContr ...)
-	TODO: check
+	NOT-FOR-US: Mautic
 CVE-2026-71244 (Paperless-ngx's MailAccountViewSet.test() action, when called with an  ...)
-	TODO: check
+	NOT-FOR-US: Paperless-ngx
 CVE-2026-71243 (The backmeup npm package assembles shell command strings by directly c ...)
-	TODO: check
+	NOT-FOR-US: backmeup npm package
 CVE-2026-71242 (Crater's NotePolicy checks only a blanket Bouncer ability (manage-all- ...)
-	TODO: check
+	NOT-FOR-US: Crater
 CVE-2026-71241 (Book-Management-System's Flask API endpoints /student, /record, /books ...)
-	TODO: check
+	NOT-FOR-US: Book-Management-System
 CVE-2026-71240 (DjangoCRM's toggle_default_sorting view is the only route in common/ur ...)
-	TODO: check
+	NOT-FOR-US: DjangoCRM
 CVE-2026-71239 (DjangoCRM's massmail module renders user-controlled EmlMessage fields  ...)
-	TODO: check
+	NOT-FOR-US: DjangoCRM
 CVE-2026-71238 (DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the c ...)
-	TODO: check
+	NOT-FOR-US: DjangoCRM
 CVE-2026-71237 (Miantang/IoT-PHP's index.php implements a POST /userlogin route that r ...)
-	TODO: check
+	NOT-FOR-US: Miantang/IoT-PHP
 CVE-2026-71236 (Grocy's API request-body parser (controllers/Api/BaseApiController.php ...)
 	TODO: check
 CVE-2026-71235 (Magistrala's Rules Engine allows authenticated users to create rules w ...)
-	TODO: check
+	NOT-FOR-US: Magistrala
 CVE-2026-71234 (Documize Community's attachment download route (domain/attachment/endp ...)
-	TODO: check
+	NOT-FOR-US: Documize
 CVE-2026-71233 (InvoiceNinja v5-stable renders an invoice or quote's "terms" field in  ...)
-	TODO: check
+	NOT-FOR-US: InvoiceNinja
 CVE-2026-71232 (MacCMS10's admin template editor (application/admin/controller/Templat ...)
-	TODO: check
+	NOT-FOR-US: MacCMS10
 CVE-2026-71231 (IOTSmartHome's gui/login.php checkCookie() function builds an authenti ...)
-	TODO: check
+	NOT-FOR-US: IOTSmartHome
 CVE-2026-71227 (A flaw was found in libkcapi. A local attacker can influence an applic ...)
 	TODO: check
 CVE-2026-71226 (Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1fb40135ad821a5724781db3c325b7f41df78fb7

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1fb40135ad821a5724781db3c325b7f41df78fb7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260805/44dd8502/attachment.htm>


More information about the debian-security-tracker-commits mailing list