[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Aug 10 20:14:54 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
422f2efd by security tracker role at 2026-08-10T19:14:48+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -51,31 +51,31 @@ CVE-2026-72734 (Dokploy is a free, self-hostable Platform as a Service (PaaS). F
CVE-2026-72733 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
TODO: check
CVE-2026-72732 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-72731 (Discourse is an open-source discussion platform. From 2026.1.0-latest ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-72730 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-72729 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-72728 (Discourse is an open-source discussion platform. Prior to 2026.1.7, an ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-72727 (Discourse is an open-source discussion platform. Prior to 026.1.6, 202 ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-72726 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-72725 (Discourse is an open-source discussion platform. Prior to 2026.1.6, th ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-72724 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-72723 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-72722 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-72721 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-72720 (Discourse is an open-source discussion platform. Prior to 2026.1.7, 20 ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-72719 (Chatwoot is a customer engagement suite. Prior to 4.9.0, Chatwoot allo ...)
TODO: check
CVE-2026-72718 (goose is general-purpose AI agent that runs on your machine. Prior to ...)
@@ -161,7 +161,7 @@ CVE-2026-71967 (OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a nu
CVE-2026-71964 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file ...)
TODO: check
CVE-2026-71962 (Flowise versions 2.2.4 through 3.1.4 contain a missing authorization v ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-71959 (Bitwarden Server before 2026.7.2 does not verify that the caller is a ...)
TODO: check
CVE-2026-71577 (A flaw was found in multicluster-global-hub. During a ManagedClusterMi ...)
@@ -185,11 +185,11 @@ CVE-2026-6373 (Exposure of sensitive system information to an unauthorized contr
CVE-2026-6368 (Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to v ...)
TODO: check
CVE-2026-66915 (Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4. ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-66738 (SPIP before 4.4.18 contains a code injection vulnerability in SQLite-b ...)
TODO: check
CVE-2026-66642 (Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66486 (GNU cpio is vulnerable to improper encoding or escaping of output in i ...)
TODO: check
CVE-2026-66485 (GNU cpio is vulnerable to an uncontrolled memory allocation in the mak ...)
@@ -215,11 +215,11 @@ CVE-2026-66404 (DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certif
CVE-2026-66403 (DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging ...)
TODO: check
CVE-2026-65948 (UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8 ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-65945 (Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-65942 (TLS hostname verification issue in Apache Ranger Client Code in versio ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-64941 (URL Redirection to Untrusted Site ('Open Redirect') vulnerability in p ...)
TODO: check
CVE-2026-64940 (Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contai ...)
@@ -245,29 +245,29 @@ CVE-2026-59087 (A flaw was found in the GIMP image manipulation program, specifi
CVE-2026-57279 (Cybozu Garoon contains a cross-site scripting vulnerability. If this v ...)
TODO: check
CVE-2026-56620 (HCL BigFix Mobileis vulnerable to information disclosure due to improp ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-56619 (HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Ref ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-55814 (Missing Authentication in Apache Ranger Download APIs on versions <= 2 ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-55799 (Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apa ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-48159 (use-reducer-async is a React useReducer with async actions. Between 20 ...)
TODO: check
CVE-2026-48158 (use-context-selector is a React useContextSelector hook in userland Be ...)
TODO: check
CVE-2026-48048 (XWiki Platform is a generic wiki platform. XWiki discovered that the p ...)
- TODO: check
+ NOT-FOR-US: XWiki
CVE-2026-47754 (Metacat is data repository software that helps researchers preserve, s ...)
TODO: check
CVE-2026-44630 (Improper validation of length fields in the Apache IoTDB RPC service m ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-44416 (Remote Code Execution via Arbitrary Class Instantiation inplugin-schem ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-42537 (Remote Code Execution via JDBC URL Injectionin Apache Ranger <= 2.8.0 ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-40920 (Privilege Escalation via URL Parameteris reported in Apache Ranger ver ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-40512
REJECTED
CVE-2026-35028
@@ -283,7 +283,7 @@ CVE-2026-35005
CVE-2026-34423
REJECTED
CVE-2026-32227 (SQL Injection vulnerability vulnerability in Apache Ranger. This issu ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-29517
REJECTED
CVE-2026-29033
@@ -317,7 +317,7 @@ CVE-2026-28999
CVE-2026-28998
REJECTED
CVE-2026-28672 (Improper Neutralization of Special Elements used in a Command ('Comman ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-28534
REJECTED
CVE-2026-28533
@@ -365,59 +365,59 @@ CVE-2026-22652
CVE-2026-22651
REJECTED
CVE-2026-21084 (Improper access control in SmartThings prior to version 1.8.47.24 allo ...)
- TODO: check
+ NOT-FOR-US: Samsung Mobile
CVE-2026-21083 (Improper input validation in Smart Switch prior to version 3.7.72.6 al ...)
- TODO: check
+ NOT-FOR-US: Samsung Mobile
CVE-2026-21082 (Relative path traversal in Samsung Health prior to version 7.0.0 allow ...)
- TODO: check
+ NOT-FOR-US: Samsung Mobile
CVE-2026-21081 (Improper export of android application components in SamsungPassAutofi ...)
- TODO: check
+ NOT-FOR-US: Samsung Mobile
CVE-2026-21080 (Cleartext storage of sensitive information in Smart Switch prior to ve ...)
- TODO: check
+ NOT-FOR-US: Samsung Mobile
CVE-2026-21079 (Missing encryption of sensitive data in Smart Switch prior to version ...)
- TODO: check
+ NOT-FOR-US: Samsung Mobile
CVE-2026-21078 (Insufficient verification of data authenticity in Smart Switch trouble ...)
- TODO: check
+ NOT-FOR-US: Samsung Mobile
CVE-2026-21077 (Incorrect authorization in Samsung Health prior to version 7.0.0 allow ...)
- TODO: check
+ NOT-FOR-US: Samsung Mobile
CVE-2026-21076 (Incorrect authorization in Samsung Health prior to version 7.0.0 allow ...)
- TODO: check
+ NOT-FOR-US: Samsung Mobile
CVE-2026-21075 (Improper authorization in handler for custom URL scheme in My Galaxy p ...)
- TODO: check
+ NOT-FOR-US: Samsung Mobile
CVE-2026-21074 (Incorrect default permissions in Bixby prior to version 4.0.86.0 allow ...)
- TODO: check
+ NOT-FOR-US: Samsung Mobile
CVE-2026-21073 (Improper input validation in Galaxy Themes prior to SMR Aug-2026 Relea ...)
- TODO: check
+ NOT-FOR-US: Samsung Mobile
CVE-2026-21072 (Improper input validation in VC1 codec in libsavsvc.so prior to SMR Au ...)
- TODO: check
+ NOT-FOR-US: Samsung Mobile
CVE-2026-21071 (Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR ...)
- TODO: check
+ NOT-FOR-US: Samsung Mobile
CVE-2026-21070 (Improper input validation in Samsung Message prior to SMR Aug-2026 Rel ...)
- TODO: check
+ NOT-FOR-US: Samsung Mobile
CVE-2026-21069 (Incorrect conversion between numeric types in VC1 codec in libsavsvc.s ...)
- TODO: check
+ NOT-FOR-US: Samsung Mobile
CVE-2026-21068 (Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Rel ...)
- TODO: check
+ NOT-FOR-US: Samsung Mobile
CVE-2026-21067 (Improper input validation in libsmsd.so prior to SMR Aug-2026 Release ...)
- TODO: check
+ NOT-FOR-US: Samsung Mobile
CVE-2026-21066 (Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug ...)
- TODO: check
+ NOT-FOR-US: Samsung Mobile
CVE-2026-21065 (Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 R ...)
- TODO: check
+ NOT-FOR-US: Samsung Mobile
CVE-2026-21064 (Improper access control in Weaver prior to SMR Aug-2026 Release 1 allo ...)
- TODO: check
+ NOT-FOR-US: Samsung Mobile
CVE-2026-21063 (Improper export of android application components in AppLock prior to ...)
- TODO: check
+ NOT-FOR-US: Samsung Mobile
CVE-2026-21062 (Authorization bypass in SemClipboardService prior to SMR Aug-2026 Rele ...)
- TODO: check
+ NOT-FOR-US: Samsung Mobile
CVE-2026-21061 (Improper input validation in Samsung Dialer prior to SMR Aug-2026 Rele ...)
- TODO: check
+ NOT-FOR-US: Samsung Mobile
CVE-2026-21060 (Improper input validation in Samsung Contacts prior to SMR Aug-2026 Re ...)
- TODO: check
+ NOT-FOR-US: Samsung Mobile
CVE-2026-21059 (Improper export of android application components in Samsung Contacts ...)
- TODO: check
+ NOT-FOR-US: Samsung Mobile
CVE-2026-21058 (Improper input validation in Samsung Contacts prior to SMR Aug-2026 Re ...)
- TODO: check
+ NOT-FOR-US: Samsung Mobile
CVE-2026-19433 (Authorization Bypass Through User-Controlled Key in the contact manage ...)
TODO: check
CVE-2026-19429 (Jenkins FilePath.untarFrom() in all versions, including those with the ...)
@@ -449,7 +449,7 @@ CVE-2026-12984 (Insufficiently Protected Credentials vulnerability in Zyxel Netw
CVE-2026-12624 (Vault\u2019s ACL policy engine did not consistently enforce a wildcard ...)
TODO: check
CVE-2026-12339 (A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2026-10754 (Pega Platform versions 8.5.0 through 25.1.2 are affected by an imprope ...)
TODO: check
CVE-2026-68870 (The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azur ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/422f2efd6483320728456feda473fb8b75bee7fe
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/422f2efd6483320728456feda473fb8b75bee7fe
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260810/6ad08e07/attachment.htm>
More information about the debian-security-tracker-commits
mailing list