[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 6 09:37:36 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1bb5bfd6 by Salvatore Bonaccorso at 2026-08-06T10:37:07+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -147,55 +147,55 @@ CVE-2026-71309 (rclone is a command-line program to sync files and directories t
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-45pq-889g-fcgh
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/cc5a189f00efe68ed0ddb32d3237b42549a9f264 (v1.75.0)
 CVE-2026-70618 (Spacebar Server before commit 51da17c contains a missing authorization ...)
-	TODO: check
+	NOT-FOR-US: Spacebar Server
 CVE-2026-70617 (Spacebar Server before commit dcfd910 contains a missing authorization ...)
-	TODO: check
+	NOT-FOR-US: Spacebar Server
 CVE-2026-70616 (boringproxy through 0.10.0 contains a resource exhaustion vulnerabilit ...)
-	TODO: check
+	NOT-FOR-US: boringproxy
 CVE-2026-70615 (boringproxy through 0.10.0 contains a newline injection vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: boringproxy
 CVE-2026-69111 (Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of  ...)
-	TODO: check
+	NOT-FOR-US: Milvus
 CVE-2026-68746 (Not Failing Securely ('Failing Open') vulnerability in livebook-dev li ...)
-	TODO: check
+	NOT-FOR-US: livebook-dev livebook
 CVE-2026-67873 (A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server- ...)
-	TODO: check
+	NOT-FOR-US: mz-automation lib60870
 CVE-2026-67872 (An issue in Systerel S2OPC 1.7.3 allows a remote attacker to cause a d ...)
-	TODO: check
+	NOT-FOR-US: Systerel S2OPC
 CVE-2026-67871 (Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote  ...)
-	TODO: check
+	NOT-FOR-US: Systerel S2OPC
 CVE-2026-67870 (In open62541 v1.5.5, the server-side AddReferences implementation cont ...)
 	TODO: check
 CVE-2026-67869 (Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote atta ...)
 	TODO: check
 CVE-2026-67867 (Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote  ...)
-	TODO: check
+	NOT-FOR-US: Systerel S2OPC
 CVE-2026-67866 (Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote  ...)
-	TODO: check
+	NOT-FOR-US: Systerel S2OPC
 CVE-2026-67865 (S2OPC 1.7.3 contains an out-of-bounds read in RepublishResponse handli ...)
-	TODO: check
+	NOT-FOR-US: Systerel S2OPC
 CVE-2026-67864 (An issue in open62541 v.1.5.5 and before allows a remote attacker to c ...)
 	TODO: check
 CVE-2026-67863 (In open62541 1.5.5, a server-side use-after-free exists in the local M ...)
 	TODO: check
 CVE-2026-67531 (FrontMCP is a TypeScript-first framework for the Model Context Protoco ...)
-	TODO: check
+	NOT-FOR-US: FrontMCP
 CVE-2026-66885 (Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev livebo ...)
-	TODO: check
+	NOT-FOR-US: livebook-dev livebook
 CVE-2026-66881 (Relative Path Traversal vulnerability in livebook-dev livebook allows  ...)
-	TODO: check
+	NOT-FOR-US: livebook-dev livebook
 CVE-2026-66298 (Origin Validation Error vulnerability in livebook-dev livebook allows  ...)
-	TODO: check
+	NOT-FOR-US: livebook-dev livebook
 CVE-2026-66297 (Improper Neutralization of Special Elements used in an OS Command (OS  ...)
-	TODO: check
+	NOT-FOR-US: livebook-dev livebook
 CVE-2026-55524 (PraisonAI is a multi-agent teams system. In versions prior to 1.6.58,  ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-55523 (PraisonAI is a multi-agent teams system. In versions 1.5.128 through 1 ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-55522 (PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4. ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-52466 (Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toIno ...)
-	TODO: check
+	NOT-FOR-US: Open Library Foundation VuFind
 CVE-2026-34966 (Gitea prior to 1.27.0 contains a server-side request forgery vulnerabi ...)
 	TODO: check
 CVE-2026-21766 (The default login portlet in HCL Digital Experience and Digital Experi ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1bb5bfd6a3b483d024a2ca70cbcb2ec83a5a91b9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1bb5bfd6a3b483d024a2ca70cbcb2ec83a5a91b9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260806/2bd75380/attachment.htm>


More information about the debian-security-tracker-commits mailing list