[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 5 21:43:08 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ebe019cb by Salvatore Bonaccorso at 2026-08-05T22:42:48+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -227,7 +227,7 @@ CVE-2026-71204 (changedetection.io's /settings save handler builds an update dic
 CVE-2026-71203 (changedetection.io's REST API resources are protected by an @auth.chec ...)
 	NOT-FOR-US: changedetection.io
 CVE-2026-71202 (The raster Rust crate's crop() function (src/editor.rs) clamps the cro ...)
-	TODO: check
+	NOT-FOR-US: raster Rust crate
 CVE-2026-70612 (Electron is a framework for writing cross-platform desktop application ...)
 	- electron <itp> (bug #842420)
 CVE-2026-70611 (Electron is a framework for writing cross-platform desktop application ...)
@@ -311,11 +311,11 @@ CVE-2026-70427 (Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safe
 CVE-2026-70426 (In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c99 ...)
 	NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70378 (imagecli's `carve <ratio>` pipeline operation (Carve::apply() in src/i ...)
-	TODO: check
+	NOT-FOR-US: imagecli
 CVE-2026-70377 (imagecli's `scale <ratio>` pipeline operation (Scale::apply() in src/i ...)
-	TODO: check
+	NOT-FOR-US: imagecli
 CVE-2026-70376 (Pluck CMS's admin panel relies solely on a Referer-header comparison ( ...)
-	TODO: check
+	NOT-FOR-US: Pluck CMS
 CVE-2026-6972 (The SKT Skill Bar plugin for WordPress is vulnerable to Stored Cross-S ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-6639 (The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is v ...)
@@ -329,21 +329,21 @@ CVE-2026-6079 (The Material Dashboard plugin for WordPress is vulnerable to unau
 CVE-2026-6020 (The ShopLentor plugin for WordPress is vulnerable to arbitrary functio ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-67623 (Mistral Vibe before 2.23.3 contains a remote code execution vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: Mistral Vibe
 CVE-2026-66747 (Zbtlink router firmware ships an embedded remote-control implant, ENDL ...)
-	TODO: check
+	NOT-FOR-US: Zbtlink router firmware
 CVE-2026-63457 (A potential denial of service vulnerability exists in HPE Integrated L ...)
 	NOT-FOR-US: HPE
 CVE-2026-61891 (In Eclipse Theia versions up to and including 1.73.1, the `@theia/file ...)
 	NOT-FOR-US: Eclipse
 CVE-2026-61486 (** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-61485 (** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-61484 (** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vuln ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-61483 (** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability i ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-60053 (Insufficient Session Expiration vulnerability in Apache Answer.  This  ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-60023 (Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...)
@@ -359,29 +359,29 @@ CVE-2026-5116 (The Contact Form 7 \u2013 Dynamic Text Extension plugin for WordP
 CVE-2026-5108 (The Super Progressive Web Apps plugin for WordPress is vulnerable to S ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-59675 (When API audit logging is enabled, the middleware reads the entire HTT ...)
-	TODO: check
+	NOT-FOR-US: Rancher
 CVE-2026-55998 (The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster ...)
-	TODO: check
+	NOT-FOR-US: Rancher
 CVE-2026-55997 (Rancher issues long-lived registration tokens to authenticate nodes an ...)
 	NOT-FOR-US: SUSE
 CVE-2026-55996 (A denial-of-service vulnerability was identified in multiple TLS liste ...)
-	TODO: check
+	NOT-FOR-US: Rancher
 CVE-2026-55747 (The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow  ...)
-	TODO: check
+	NOT-FOR-US: The-Pocket/PocketFlow
 CVE-2026-55739 (Crater isolates data per company_id, and its Invoice/Estimate/Payment/ ...)
-	TODO: check
+	NOT-FOR-US: Crater
 CVE-2026-54418 (Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA ...)
-	TODO: check
+	NOT-FOR-US: Leantime
 CVE-2026-54416 (Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin ...)
-	TODO: check
+	NOT-FOR-US: Pluck CMS
 CVE-2026-53992 (ProjectSend r2029 contains a reflected cross-site scripting vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: ProjectSend
 CVE-2026-50749 (Improper Authorization vulnerability in Apache Answer.  This issue aff ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-4431 (The Easy Post Submission plugin for WordPress is vulnerable to unautho ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-49331 (A flaw was found in openshift/oauth-proxy. On paths configured to bypa ...)
-	TODO: check
+	NOT-FOR-US: openshift/oauth-proxy
 CVE-2026-48912 (Improper Input Validation vulnerability in Apache Answer.  This issue  ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-48911 (Insufficient Verification of Data Authenticity vulnerability in Apache ...)
@@ -389,41 +389,41 @@ CVE-2026-48911 (Insufficient Verification of Data Authenticity vulnerability in
 CVE-2026-48834 (Improper Handling of Length Parameter Inconsistency vulnerability in A ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-48168 (PraisonAI is a multi-agent teams system. In versions prior to 4.6.40,  ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-46581 (In Eclipse Mojarra versions 2.3 and following, URL handing in `Default ...)
 	TODO: check
 CVE-2026-44945 (A privilege escalation vulnerability exists in Rancher's impersonation ...)
-	TODO: check
+	NOT-FOR-US: Rancher
 CVE-2026-39924 (Flarum before 1.8.16 contains an improper session invalidation vulnera ...)
-	TODO: check
+	NOT-FOR-US: Flarum
 CVE-2026-39923 (Flarum before 1.8.16 contains a password reset token expiry bypass vul ...)
-	TODO: check
+	NOT-FOR-US: Flarum
 CVE-2026-32835
 	REJECTED
 CVE-2026-25703 (NeuVector through 5.4.9 is can potentially leak information from manag ...)
-	TODO: check
+	NOT-FOR-US: NeuVector
 CVE-2026-20313 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20312 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20311 (A vulnerability in the web-based management interface of Cisco IOS XE  ...)
 	NOT-FOR-US: Cisco
 CVE-2026-20310 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20308 (A vulnerability in the web-based management interface of Cisco IOS XE  ...)
 	NOT-FOR-US: Cisco
 CVE-2026-20304 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20303 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20301 (A vulnerability in the Extensible Messaging Client Protocol (XMCP), al ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20294 (A vulnerability in the web-based management interface of Cisco Catalys ...)
 	NOT-FOR-US: Cisco
 CVE-2026-20289 (A vulnerability in the logging subsystem of Cisco RoomOS could allow a ...)
 	NOT-FOR-US: Cisco
 CVE-2026-20288 (A vulnerability in the web-based management interface of Cisco IMC cou ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20273 (As part of Cisco's ongoing commitment to proactive security and produc ...)
 	NOT-FOR-US: Cisco
 CVE-2026-20272 (As part of Cisco's ongoing commitment to proactive security and produc ...)
@@ -441,17 +441,17 @@ CVE-2026-20267 (As part of Cisco's ongoing commitment to proactive security and
 CVE-2026-20263 (A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feat ...)
 	NOT-FOR-US: Cisco
 CVE-2026-20200 (A vulnerability in the web-based management interface of Cisco IMC cou ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20198 (A vulnerability in the web-based management interface of Cisco Integra ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20124 (A vulnerability in the Simple Network Management Protocol (SNMP) subsy ...)
 	NOT-FOR-US: Cisco
 CVE-2026-20028 (A vulnerability in the network driver of Cisco Terminal Service (TS) A ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-18933 (The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affe ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18927 (A vulnerability was determined in imranrisal-dev Student-Management-Sy ...)
-	TODO: check
+	NOT-FOR-US: imranrisal-dev Student-Management-System
 CVE-2026-18881 (The TableOn \u2013 WordPress Posts Table Filterable plugin for WordPre ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-18531 (IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote at ...)
@@ -475,9 +475,9 @@ CVE-2026-17623 (IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authe
 CVE-2026-17617 (IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to S ...)
 	NOT-FOR-US: IBM
 CVE-2026-17613 (Penpot\u2019s ::import-binfile RPC command lacks authorization on the  ...)
-	TODO: check
+	NOT-FOR-US: Penpot
 CVE-2026-17578 (Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enfor ...)
-	TODO: check
+	NOT-FOR-US: Kong Event Gateway
 CVE-2026-17532 (The Seraphinite Accelerator plugin for WordPress is vulnerable to Refl ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-17506 (The Independent Analytics plugin for WordPress is vulnerable to Stored ...)
@@ -495,13 +495,13 @@ CVE-2026-16100 (A flaw was found in the user-event metrics recording of Keycloak
 CVE-2026-16071 (A flaw was found in the LDAP storage provider of Keycloak, which is us ...)
 	TODO: check
 CVE-2026-16022 (@oblique/cli 15.4.0 contains an OS command injection vulnerability in  ...)
-	TODO: check
+	NOT-FOR-US: oblique/cli
 CVE-2026-15979 (The Content Egg \u2013 Affiliate Product Importer & Price Comparison p ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-15656 (IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure ...)
 	NOT-FOR-US: IBM
 CVE-2026-15587 (Improper Privilege Management in Google SecOps (Chronicle SOAR) versio ...)
-	TODO: check
+	NOT-FOR-US: Google SecOps (Chronicle SOAR)
 CVE-2026-15573 (A flaw was found in Keycloak's Authorization Services. The component r ...)
 	TODO: check
 CVE-2026-15572 (A flaw was found in Keycloak's Dynamic Client Registration (DCR) secur ...)
@@ -525,7 +525,7 @@ CVE-2026-12730 (IBM Business Automation Workflow containers and traditional 26.0
 CVE-2026-12609 (In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@ ...)
 	NOT-FOR-US: Eclipse
 CVE-2026-12410 (Link following vulnerability in the Uninstaller component in CCleaner  ...)
-	TODO: check
+	NOT-FOR-US: CCleaner
 CVE-2026-12000 (The Page and Post Restriction plugin for WordPress is vulnerable to Se ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-11977 (The WP Post Author \u2013 Author Box, Multiple Authors, Guest Authors  ...)
@@ -543,9 +543,9 @@ CVE-2026-10547 (IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate
 CVE-2026-10128 (IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can e ...)
 	NOT-FOR-US: IBM
 CVE-2026-10090 (A flaw was found in the Application Subscription controller (multiclus ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes (ACM)
 CVE-2026-10059 (A flaw was found in the Multicluster Engine for Kubernetes ClusterCura ...)
-	TODO: check
+	NOT-FOR-US: ulticluster Engine for Kubernetes ClusterCurator controller (Red Hat)
 CVE-2026-10025 (IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Inte ...)
 	NOT-FOR-US: IBM
 CVE-2026-0931 (Denial-of-service vulnerability in M-Files Server versions before26.5. ...)
@@ -553,7 +553,7 @@ CVE-2026-0931 (Denial-of-service vulnerability in M-Files Server versions before
 CVE-2026-0516 (A improper neutralization of HTTP Headers for Scripting Syntax vulnera ...)
 	NOT-FOR-US: SonicWall
 CVE-2025-70962 (Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Contro ...)
-	TODO: check
+	NOT-FOR-US: Zosi C519M
 CVE-2026-54876 (Issue summary: A malicious TLS server can cause a memory leak in a TLS ...)
 	- openssl <unfixed>
 	[trixie] - openssl <not-affected> (Vulnerable code not present)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ebe019cb247ab256a3ae62182e97337789bd49ff

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ebe019cb247ab256a3ae62182e97337789bd49ff
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260805/19000f96/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list