[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 6 21:05:03 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1e850af3 by Salvatore Bonaccorso at 2026-08-06T22:03:07+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3,19 +3,19 @@ CVE-2026-61477
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2512068
 	TODO: wait and update entry once RH has updated records, reference upstream issue
 CVE-2026-8166 (Improper neutralization of input during web page generation ('cross-si ...)
-	TODO: check
+	NOT-FOR-US: e-Logo Purchasing Portal
 CVE-2026-70646 (aiosend is a synchronous and asynchronous Crypto Pay API client. Pror  ...)
-	TODO: check
+	NOT-FOR-US: aiosend
 CVE-2026-70637 (LightFTP through 2.4 contains multiple data race vulnerabilities in ft ...)
-	TODO: check
+	NOT-FOR-US: LightFTP
 CVE-2026-70556 (Hubzilla 11.2.1 contains a cross-site request forgery vulnerability in ...)
-	TODO: check
+	NOT-FOR-US: Hubzilla
 CVE-2026-68750 (Inefficient Algorithmic Complexity vulnerability in the traversal engi ...)
-	TODO: check
+	NOT-FOR-US: rrrene html_sanitize_ex
 CVE-2026-68749 (Inefficient Regular Expression Complexity vulnerability in the CSS scr ...)
-	TODO: check
+	NOT-FOR-US: rrrene html_sanitize_ex
 CVE-2026-68747 (Improper Neutralization of Special Elements in Output Used by a Downst ...)
-	TODO: check
+	NOT-FOR-US: rrrene html_sanitize_ex
 CVE-2026-68481 (In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tok ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-68079 (In Apache CXF's DefaultEncryptingCodeDataProvider,a captured authoriza ...)
@@ -25,13 +25,13 @@ CVE-2026-67261 (Dell Virtual Storage Integrator for VMware vSphere Client, versi
 CVE-2026-66909 (Apache CXF's JMS transport deserializes the body of any inbound JMS Ob ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-66843 (Inclusion of Functionality from Untrusted Control Sphere vulnerability ...)
-	TODO: check
+	NOT-FOR-US: rrrene html_sanitize_ex
 CVE-2026-66829 (URL Redirection to Untrusted Site ('Open Redirect') vulnerability in t ...)
-	TODO: check
+	NOT-FOR-US: rrrene html_sanitize_ex
 CVE-2026-66733 (Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allo ...)
-	TODO: check
+	NOT-FOR-US: Sonic 3 A.I.R.
 CVE-2026-66732 (Sonic 3 A.I.R. before commit 2492d18 contains a missing source address ...)
-	TODO: check
+	NOT-FOR-US: Sonic 3 A.I.R.
 CVE-2026-66712 (Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 ve ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66711 (Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Mu ...)
@@ -105,7 +105,7 @@ CVE-2026-66439 (Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Prod
 CVE-2026-66425 (Unauthenticated Broken Authentication in Gutena Forms \u2013 Contact F ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66370 (URL Redirection to Untrusted Site ('Open Redirect') vulnerability in t ...)
-	TODO: check
+	NOT-FOR-US: rrrene html_sanitize_ex
 CVE-2026-65583 (Apache CXF\u2019s OIDC relying-party token validation could accept sel ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-65581 (Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.)
@@ -211,7 +211,7 @@ CVE-2026-61466 (In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the
 CVE-2026-5430 (The JWT authentication mechanism accepts tokens signed with algorithms ...)
 	NOT-FOR-US: WSO2
 CVE-2026-5423 (@neo4j/graphqllibrary versions prior to 7.5.6 fail to verify the authe ...)
-	TODO: check
+	NOT-FOR-US: neo4j/graphql
 CVE-2026-5391 (The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-5158 (The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites \u20 ...)
@@ -225,23 +225,23 @@ CVE-2026-57818 (A race condition in JCacheCodeDataProvider allows an attacker to
 CVE-2026-57817 (The OpenID Connect Core 1.0 specification mandates that the RP MUST va ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-55980 (A denial-of-service vulnerability inCatchPulsecould allow an attacker  ...)
-	TODO: check
+	NOT-FOR-US: CatchPulse
 CVE-2026-55979 (An improper access control check inCatchPulse'snamed pipe communicatio ...)
-	TODO: check
+	NOT-FOR-US: CatchPulse
 CVE-2026-55978 (An improper access control vulnerability inCatchPulsecould allow a non ...)
-	TODO: check
+	NOT-FOR-US: CatchPulse
 CVE-2026-54489 (Dell Virtual Storage Integrator for VMware vSphere Client, versions pr ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-54225 (Apache CXF allows to control the maximum attachment size via the"attac ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-53985 (Ground Station prior to 0.6.0contains an unauthenticated denial-of-ser ...)
-	TODO: check
+	NOT-FOR-US: Ground Station
 CVE-2026-53977 (OpenChamber 1.11.7 contains an authentication bypass vulnerability tha ...)
-	TODO: check
+	NOT-FOR-US: OpenChamber
 CVE-2026-53976 (OpenChamber 1.11.7 contains a path traversal vulnerability in the file ...)
-	TODO: check
+	NOT-FOR-US: OpenChamber
 CVE-2026-53975 (OpenChamber 1.11.7 contains an unauthenticated remote code execution v ...)
-	TODO: check
+	NOT-FOR-US: OpenChamber
 CVE-2026-43622 (llama.cpp builds b1886 through b7445 contain a double free vulnerabili ...)
 	TODO: check
 CVE-2026-3430 (The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not saniti ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1e850af3f50f4355c93593fca0b041ef3b1744d6

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1e850af3f50f4355c93593fca0b041ef3b1744d6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260806/1b84a0ef/attachment.htm>


More information about the debian-security-tracker-commits mailing list