[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 5 20:59:40 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8ced0a4d by Salvatore Bonaccorso at 2026-08-05T21:58:53+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -201,31 +201,31 @@ CVE-2026-71225 (A flaw was found in libkcapi. When performing one-shot symmetric
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462011
 	TODO: check details, AI assisted report
 CVE-2026-71215 (art-template's sub-template resolution logic (src/compile/adapter/reso ...)
-	TODO: check
+	NOT-FOR-US: art-template
 CVE-2026-71214 (The Aerie/PlanDev sequencing-server's authorization middleware (sequen ...)
-	TODO: check
+	NOT-FOR-US: NASA-AMMOS
 CVE-2026-71213 (Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login()) ...)
-	TODO: check
+	NOT-FOR-US: Typemill
 CVE-2026-71212 (xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line in ...)
-	TODO: check
+	NOT-FOR-US: xidown
 CVE-2026-71211 (MLflow's AI Gateway accepts an auth_config.api_base value when creatin ...)
 	NOT-FOR-US: mlflow
 CVE-2026-71210 (Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport ...)
-	TODO: check
+	NOT-FOR-US: Mealie
 CVE-2026-71209 (audiobookshelf's authentication-exemption check (server/routers/Auth.j ...)
-	TODO: check
+	NOT-FOR-US: Audiobookshelf
 CVE-2026-71208 (KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclien ...)
-	TODO: check
+	NOT-FOR-US: KubeSphere
 CVE-2026-71207 (The Stock-Inventory-Management-System application's login.php assigns  ...)
-	TODO: check
+	NOT-FOR-US: Stock-Inventory-Management-System
 CVE-2026-71206 (Shiori's CheckToken function (internal/domains/auth.go) validates only ...)
-	TODO: check
+	NOT-FOR-US: Shiori
 CVE-2026-71205 (changedetection.io's /login route checks the submitted password agains ...)
-	TODO: check
+	NOT-FOR-US: changedetection.io
 CVE-2026-71204 (changedetection.io's /settings save handler builds an update dict from ...)
-	TODO: check
+	NOT-FOR-US: changedetection.io
 CVE-2026-71203 (changedetection.io's REST API resources are protected by an @auth.chec ...)
-	TODO: check
+	NOT-FOR-US: changedetection.io
 CVE-2026-71202 (The raster Rust crate's crop() function (src/editor.rs) clamps the cro ...)
 	TODO: check
 CVE-2026-70612 (Electron is a framework for writing cross-platform desktop application ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8ced0a4d2c008d0c278347d2b709ce34c19b71f4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8ced0a4d2c008d0c278347d2b709ce34c19b71f4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260805/669684fd/attachment.htm>


More information about the debian-security-tracker-commits mailing list