[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Aug 5 20:59:40 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
8ced0a4d by Salvatore Bonaccorso at 2026-08-05T21:58:53+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -201,31 +201,31 @@ CVE-2026-71225 (A flaw was found in libkcapi. When performing one-shot symmetric
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462011
TODO: check details, AI assisted report
CVE-2026-71215 (art-template's sub-template resolution logic (src/compile/adapter/reso ...)
- TODO: check
+ NOT-FOR-US: art-template
CVE-2026-71214 (The Aerie/PlanDev sequencing-server's authorization middleware (sequen ...)
- TODO: check
+ NOT-FOR-US: NASA-AMMOS
CVE-2026-71213 (Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login()) ...)
- TODO: check
+ NOT-FOR-US: Typemill
CVE-2026-71212 (xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line in ...)
- TODO: check
+ NOT-FOR-US: xidown
CVE-2026-71211 (MLflow's AI Gateway accepts an auth_config.api_base value when creatin ...)
NOT-FOR-US: mlflow
CVE-2026-71210 (Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport ...)
- TODO: check
+ NOT-FOR-US: Mealie
CVE-2026-71209 (audiobookshelf's authentication-exemption check (server/routers/Auth.j ...)
- TODO: check
+ NOT-FOR-US: Audiobookshelf
CVE-2026-71208 (KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclien ...)
- TODO: check
+ NOT-FOR-US: KubeSphere
CVE-2026-71207 (The Stock-Inventory-Management-System application's login.php assigns ...)
- TODO: check
+ NOT-FOR-US: Stock-Inventory-Management-System
CVE-2026-71206 (Shiori's CheckToken function (internal/domains/auth.go) validates only ...)
- TODO: check
+ NOT-FOR-US: Shiori
CVE-2026-71205 (changedetection.io's /login route checks the submitted password agains ...)
- TODO: check
+ NOT-FOR-US: changedetection.io
CVE-2026-71204 (changedetection.io's /settings save handler builds an update dict from ...)
- TODO: check
+ NOT-FOR-US: changedetection.io
CVE-2026-71203 (changedetection.io's REST API resources are protected by an @auth.chec ...)
- TODO: check
+ NOT-FOR-US: changedetection.io
CVE-2026-71202 (The raster Rust crate's crop() function (src/editor.rs) clamps the cro ...)
TODO: check
CVE-2026-70612 (Electron is a framework for writing cross-platform desktop application ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8ced0a4d2c008d0c278347d2b709ce34c19b71f4
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8ced0a4d2c008d0c278347d2b709ce34c19b71f4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260805/669684fd/attachment.htm>
More information about the debian-security-tracker-commits
mailing list