[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Aug 8 08:14:51 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f9e0e366 by security tracker role at 2026-08-08T07:14:45+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,11 +1,11 @@
 CVE-2026-9031 (An input validation vulnerability exists in the HTTP-WRITEOEM handler  ...)
-	TODO: check
+	NOT-FOR-US: TPLink
 CVE-2026-9030 (A denial-of-service vulnerability exists in httpd service on Archer A6 ...)
-	TODO: check
+	NOT-FOR-US: TPLink
 CVE-2026-8798 (In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the nati ...)
 	TODO: check
 CVE-2026-71381 (Adobe Genuine Software Integrity Service was affected by an Incorrect  ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-70624
 	REJECTED
 CVE-2026-70623
@@ -13,7 +13,7 @@ CVE-2026-70623
 CVE-2026-69207 (Hono is a Web application framework that provides support for any Java ...)
 	TODO: check
 CVE-2026-66151 (SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnera ...)
-	TODO: check
+	NOT-FOR-US: SonicWall
 CVE-2026-66061 (Home Assistant is open source home automation software focused on loca ...)
 	TODO: check
 CVE-2026-66060 (Home Assistant is open source home automation software focused on loca ...)
@@ -53,7 +53,7 @@ CVE-2026-48122 (Ruby LSP is an implementation of the language server protocol fo
 CVE-2026-48120 (Kakoune is a code editor. Prior to version 2026.05.21, the bundled, en ...)
 	TODO: check
 CVE-2026-48047 (XWiki Platform WebJars API is a package for XWiki, a generic wiki plat ...)
-	TODO: check
+	NOT-FOR-US: XWiki
 CVE-2026-48039 (Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI ass ...)
 	TODO: check
 CVE-2026-48026 (lakeFS is an open-source tool that transforms object storage into a Gi ...)
@@ -109,53 +109,53 @@ CVE-2026-19014 (Consul Community Edition and Consul Enterprise 1.17.0 through 2.
 CVE-2026-19012 (Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 ar ...)
 	TODO: check
 CVE-2026-18988 (The Easy Accordion plugin for WordPress is vulnerable to Stored Cross- ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16955 (The AI Engine  WordPress plugin before 3.6.6 does not confine a caller ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16953 (The AI Engine  WordPress plugin before 3.6.4 does not verify ownership ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16948 (The Solace Extra WordPress plugin before 1.6.1 does not perform capabi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16608 (The Download Monitor WordPress plugin before 5.2.6 does not perform au ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16595 (The WP Directory Kit WordPress plugin before 1.5.5 does not perform au ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16594 (The WP Directory Kit WordPress plugin before 1.5.5 does not perform au ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16590 (The WP Directory Kit WordPress plugin before 1.5.5 does not perform au ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16589 (The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize a ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16578 (The Admin Safety Guard \u2014 Login Security, Limit Logins, 2FA & Brut ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16574 (The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution  Wo ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16562 (The WP Statistics  WordPress plugin before 14.16.10 does not perform a ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16559 (The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG fi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16558 (The YMC Filter WordPress plugin before 3.12.8 does not sanitize and es ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16535 (The Link Library WordPress plugin before 7.9.4 does not sanitise and e ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16282 (The Appointment Hour Booking  WordPress plugin before 1.5.88 does not  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16269 (The Newsletters WordPress plugin before 4.16 does not strictly compare ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16267 (The Newsletters WordPress plugin before 4.16 does not restrict the cla ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15972 (Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 ar ...)
 	TODO: check
 CVE-2026-15970 (Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 ar ...)
 	TODO: check
 CVE-2026-14526 (The AI Copilot \u2013 Content Generator plugin for WordPress is vulner ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13505 (In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X  ...)
 	TODO: check
 CVE-2026-11743 (The SF32LB MPI QSPI NOR flash driver (drivers/flash/flash_sf32lb_mpi_q ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-11742 (The kernel queue helper z_queue_node_peek() in kernel/queue.c derefere ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-11425 (Domoticz versions prior to 2026.3 contains a stored cross-site scripti ...)
 	TODO: check
 CVE-2025-4438



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f9e0e366b86eb4eb3fcccc684d48cb620c0d5e65

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f9e0e366b86eb4eb3fcccc684d48cb620c0d5e65
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260808/8928b232/attachment.htm>


More information about the debian-security-tracker-commits mailing list