[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 7 20:20:32 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
47eaa6f8 by security tracker role at 2026-08-07T19:20:25+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -13,11 +13,11 @@ CVE-2026-71848 (Hono is a Web application framework that provides support for an
 CVE-2026-71847 (Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, ...)
 	TODO: check
 CVE-2026-71560 (Out-of-bounds Read vulnerability in Apache Fory C++ deserialization.   ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-71559 (Deserialization of Untrusted Data vulnerability in the Go implementati ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-71558 (Heap type confusion vulnerability in Apache Fory C++ deserialization.  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-71557 (go-git is an extensible git implementation library written in pure Go. ...)
 	TODO: check
 CVE-2026-71556 (go-git is an extensible git implementation library written in pure Go. ...)
@@ -31,17 +31,17 @@ CVE-2026-68772 (ZenML 0.94.6 contains a remote code execution vulnerability in t
 CVE-2026-67585 (Allocation of Resources Without Limits or Throttling vulnerability in  ...)
 	TODO: check
 CVE-2026-66914 (Joomla Extension - seblod.com - Unauthenticated path traversal in SEBL ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-66838 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
 	TODO: check
 CVE-2026-66494 (Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shap ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-66493 (Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Co ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-66492 (Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Co ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-66491 (Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1 ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-66062 (SvelteKit is a framework for rapidly developing robust, performant web ...)
 	TODO: check
 CVE-2026-66059 (Frappe is a full-stack web application framework. Prior to 16.20.0 and ...)
@@ -59,9 +59,9 @@ CVE-2026-62996 (Smarty is a template engine for PHP, facilitating the separation
 CVE-2026-62992 (Smarty is a template engine for PHP, facilitating the separation of pr ...)
 	TODO: check
 CVE-2026-56794 (Dell OpenManage Server Administrator, versions prior to 11.1.0.2, cont ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-56793 (Dell OpenManage Server Administrator, versions prior to 11.1.0.2, cont ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-54218 (Use of hard-coded cryptographic key vulnerability in Tobit Laboratorie ...)
 	TODO: check
 CVE-2026-54217 (Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to  ...)
@@ -103,11 +103,11 @@ CVE-2026-54200 (Tobit Laboratories AG TeamDavid's Webbox  is vulnerable to a loc
 CVE-2026-54199 (Tobit Laboratories AG TeamDavid's Webbox  is vulnerable to HTTP header ...)
 	TODO: check
 CVE-2026-49008 (By accessing unencrypted information in the device firmware, an attack ...)
-	TODO: check
+	NOT-FOR-US: ZTE
 CVE-2026-49007 (By accessing unencrypted information in the device firmware, an attack ...)
-	TODO: check
+	NOT-FOR-US: ZTE
 CVE-2026-49006 (By accessing unencrypted information in the device firmware, an attack ...)
-	TODO: check
+	NOT-FOR-US: ZTE
 CVE-2026-48098 (NexTor IP Changer is a command-line tool that leverages the Tor networ ...)
 	TODO: check
 CVE-2026-48097 (NexTor IP Changer is a command-line tool that leverages the Tor networ ...)
@@ -147,25 +147,25 @@ CVE-2026-20337 (A vulnerability in the zip archive parser of ClamAV could allow
 CVE-2026-19264 (Postiz is an open-source social media scheduling tool. The route that  ...)
 	TODO: check
 CVE-2026-19231 (A security flaw has been discovered in SourceCodester Simple Doctors A ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-19230 (A vulnerability was identified in SourceCodester Photo Share Website 1 ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-19229 (A vulnerability was determined in SourceCodester Online Clothing Store ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-19213 (A vulnerability was identified in WonderTrader up to 0.9.9. Affected i ...)
 	TODO: check
 CVE-2026-19212 (A vulnerability was determined in WonderTrader up to 0.9.9. This impac ...)
 	TODO: check
 CVE-2026-19211 (A vulnerability was found in SourceCodester Photo Share Website 1.0. T ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-19210 (A vulnerability has been found in SourceCodester Photo Share Website 1 ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-19209 (A flaw has been found in SourceCodester Photo Share Website 1.0. The a ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-19208 (A vulnerability was detected in WonderTrader up to 0.9.9. Impacted is  ...)
 	TODO: check
 CVE-2026-19207 (A security vulnerability has been detected in PHPGurukul Company Visit ...)
-	TODO: check
+	NOT-FOR-US: PHPGurukul
 CVE-2026-19206 (A security flaw has been discovered in MZ Automation libiec61850 up to ...)
 	TODO: check
 CVE-2026-19082 (Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent ...)
@@ -175,25 +175,25 @@ CVE-2026-19079 (A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerabilit
 CVE-2026-18497 (A heap-buffer-overflow vulnerability exists in the nothings stb TrueTy ...)
 	TODO: check
 CVE-2026-17603 (Nexus Repository 3 did not sufficiently restrict which HikariCP connec ...)
-	TODO: check
+	NOT-FOR-US: Sonatype
 CVE-2026-17601 (A user holding a permission to update privilege definitions could modi ...)
-	TODO: check
+	NOT-FOR-US: Sonatype
 CVE-2026-17600 (Sonatype Nexus Repository 3 did not immediately terminate a user's act ...)
-	TODO: check
+	NOT-FOR-US: Sonatype
 CVE-2026-17599 (Nexus Repository 3 contained an endpoint used to change the administra ...)
-	TODO: check
+	NOT-FOR-US: Sonatype
 CVE-2026-17598 (Sonatype Nexus Repository 3 did not properly filter internal configura ...)
-	TODO: check
+	NOT-FOR-US: Sonatype
 CVE-2026-17597 (Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulne ...)
-	TODO: check
+	NOT-FOR-US: Sonatype
 CVE-2026-17596 (Nexus Repository 3 was found to be vulnerable to stored cross-site scr ...)
-	TODO: check
+	NOT-FOR-US: Sonatype
 CVE-2026-17595 (Nexus Repository 3 did not fully sandbox JEXL expressions used in Cont ...)
-	TODO: check
+	NOT-FOR-US: Sonatype
 CVE-2026-17594 (Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an inc ...)
-	TODO: check
+	NOT-FOR-US: Sonatype
 CVE-2026-17593 (An account holding the nexus:settings:update permission in Nexus Repos ...)
-	TODO: check
+	NOT-FOR-US: Sonatype
 CVE-2026-17435 (File::Rotate::Simple versions before 0.4.0 for Perl create the target  ...)
 	TODO: check
 CVE-2026-16637 (OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HT ...)
@@ -205,13 +205,13 @@ CVE-2026-15816 (A flaw was found in dracut. The die() error-handling function wr
 CVE-2026-15570 (An improper restriction of URL schemes and destinations in the SmartCe ...)
 	TODO: check
 CVE-2026-15239 (The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15211 (The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does n ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15148 (The WP Events Manager WordPress plugin before 2.2.5 does not verify th ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14644 (Nexus Repository 3 contained a privilege escalation vulnerability in t ...)
-	TODO: check
+	NOT-FOR-US: Sonatype
 CVE-2026-12071 (The Webbox of TeamDavid byTobit Laboratories AGconstructs redirect URL ...)
 	TODO: check
 CVE-2026-12070 (Tobit Laboratories AG TeamDavid's Webbox  is vulnerable to an arbitrar ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/47eaa6f801c7fb2c2455269fb2c8de25f4a84b3f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/47eaa6f801c7fb2c2455269fb2c8de25f4a84b3f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260807/86ff2f5d/attachment.htm>


More information about the debian-security-tracker-commits mailing list