[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 10 20:14:54 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
422f2efd by security tracker role at 2026-08-10T19:14:48+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -51,31 +51,31 @@ CVE-2026-72734 (Dokploy is a free, self-hostable Platform as a Service (PaaS). F
 CVE-2026-72733 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
 	TODO: check
 CVE-2026-72732 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
-	TODO: check
+	NOT-FOR-US: Discourse
 CVE-2026-72731 (Discourse is an open-source discussion platform. From 2026.1.0-latest  ...)
-	TODO: check
+	NOT-FOR-US: Discourse
 CVE-2026-72730 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
-	TODO: check
+	NOT-FOR-US: Discourse
 CVE-2026-72729 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
-	TODO: check
+	NOT-FOR-US: Discourse
 CVE-2026-72728 (Discourse is an open-source discussion platform. Prior to 2026.1.7, an ...)
-	TODO: check
+	NOT-FOR-US: Discourse
 CVE-2026-72727 (Discourse is an open-source discussion platform. Prior to 026.1.6, 202 ...)
-	TODO: check
+	NOT-FOR-US: Discourse
 CVE-2026-72726 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
-	TODO: check
+	NOT-FOR-US: Discourse
 CVE-2026-72725 (Discourse is an open-source discussion platform. Prior to 2026.1.6, th ...)
-	TODO: check
+	NOT-FOR-US: Discourse
 CVE-2026-72724 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
-	TODO: check
+	NOT-FOR-US: Discourse
 CVE-2026-72723 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
-	TODO: check
+	NOT-FOR-US: Discourse
 CVE-2026-72722 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
-	TODO: check
+	NOT-FOR-US: Discourse
 CVE-2026-72721 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
-	TODO: check
+	NOT-FOR-US: Discourse
 CVE-2026-72720 (Discourse is an open-source discussion platform. Prior to 2026.1.7, 20 ...)
-	TODO: check
+	NOT-FOR-US: Discourse
 CVE-2026-72719 (Chatwoot is a customer engagement suite. Prior to 4.9.0, Chatwoot allo ...)
 	TODO: check
 CVE-2026-72718 (goose is general-purpose AI agent that runs on your machine. Prior to  ...)
@@ -161,7 +161,7 @@ CVE-2026-71967 (OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a nu
 CVE-2026-71964 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file  ...)
 	TODO: check
 CVE-2026-71962 (Flowise versions 2.2.4 through 3.1.4 contain a missing authorization v ...)
-	TODO: check
+	NOT-FOR-US: Flowise
 CVE-2026-71959 (Bitwarden Server before 2026.7.2 does not verify that the caller is a  ...)
 	TODO: check
 CVE-2026-71577 (A flaw was found in multicluster-global-hub. During a ManagedClusterMi ...)
@@ -185,11 +185,11 @@ CVE-2026-6373 (Exposure of sensitive system information to an unauthorized contr
 CVE-2026-6368 (Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to v ...)
 	TODO: check
 CVE-2026-66915 (Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4. ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-66738 (SPIP before 4.4.18 contains a code injection vulnerability in SQLite-b ...)
 	TODO: check
 CVE-2026-66642 (Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66486 (GNU cpio is vulnerable to improper encoding or escaping of output in i ...)
 	TODO: check
 CVE-2026-66485 (GNU cpio is vulnerable to an uncontrolled memory allocation in the mak ...)
@@ -215,11 +215,11 @@ CVE-2026-66404 (DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certif
 CVE-2026-66403 (DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging  ...)
 	TODO: check
 CVE-2026-65948 (UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8 ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-65945 (Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-65942 (TLS hostname verification issue in Apache Ranger Client Code in versio ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-64941 (URL Redirection to Untrusted Site ('Open Redirect') vulnerability in p ...)
 	TODO: check
 CVE-2026-64940 (Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contai ...)
@@ -245,29 +245,29 @@ CVE-2026-59087 (A flaw was found in the GIMP image manipulation program, specifi
 CVE-2026-57279 (Cybozu Garoon contains a cross-site scripting vulnerability. If this v ...)
 	TODO: check
 CVE-2026-56620 (HCL BigFix Mobileis vulnerable to information disclosure due to improp ...)
-	TODO: check
+	NOT-FOR-US: HCL
 CVE-2026-56619 (HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Ref ...)
-	TODO: check
+	NOT-FOR-US: HCL
 CVE-2026-55814 (Missing Authentication in Apache Ranger Download APIs on versions <= 2 ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-55799 (Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apa ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-48159 (use-reducer-async is a React useReducer with async actions. Between 20 ...)
 	TODO: check
 CVE-2026-48158 (use-context-selector is a React useContextSelector hook in userland Be ...)
 	TODO: check
 CVE-2026-48048 (XWiki Platform is a generic wiki platform. XWiki discovered that the p ...)
-	TODO: check
+	NOT-FOR-US: XWiki
 CVE-2026-47754 (Metacat is data repository software that helps researchers preserve, s ...)
 	TODO: check
 CVE-2026-44630 (Improper validation of length fields in the Apache IoTDB RPC service m ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-44416 (Remote Code Execution via Arbitrary Class Instantiation inplugin-schem ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-42537 (Remote Code Execution via JDBC URL Injectionin Apache Ranger <= 2.8.0  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-40920 (Privilege Escalation via URL Parameteris reported in Apache Ranger ver ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-40512
 	REJECTED
 CVE-2026-35028
@@ -283,7 +283,7 @@ CVE-2026-35005
 CVE-2026-34423
 	REJECTED
 CVE-2026-32227 (SQL Injection vulnerability vulnerability in Apache Ranger.  This issu ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-29517
 	REJECTED
 CVE-2026-29033
@@ -317,7 +317,7 @@ CVE-2026-28999
 CVE-2026-28998
 	REJECTED
 CVE-2026-28672 (Improper Neutralization of Special Elements used in a Command ('Comman ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-28534
 	REJECTED
 CVE-2026-28533
@@ -365,59 +365,59 @@ CVE-2026-22652
 CVE-2026-22651
 	REJECTED
 CVE-2026-21084 (Improper access control in SmartThings prior to version 1.8.47.24 allo ...)
-	TODO: check
+	NOT-FOR-US: Samsung Mobile
 CVE-2026-21083 (Improper input validation in Smart Switch prior to version 3.7.72.6 al ...)
-	TODO: check
+	NOT-FOR-US: Samsung Mobile
 CVE-2026-21082 (Relative path traversal in Samsung Health prior to version 7.0.0 allow ...)
-	TODO: check
+	NOT-FOR-US: Samsung Mobile
 CVE-2026-21081 (Improper export of android application components in SamsungPassAutofi ...)
-	TODO: check
+	NOT-FOR-US: Samsung Mobile
 CVE-2026-21080 (Cleartext storage of sensitive information in Smart Switch prior to ve ...)
-	TODO: check
+	NOT-FOR-US: Samsung Mobile
 CVE-2026-21079 (Missing encryption of sensitive data in Smart Switch prior to version  ...)
-	TODO: check
+	NOT-FOR-US: Samsung Mobile
 CVE-2026-21078 (Insufficient verification of data authenticity in Smart Switch trouble ...)
-	TODO: check
+	NOT-FOR-US: Samsung Mobile
 CVE-2026-21077 (Incorrect authorization in Samsung Health prior to version 7.0.0 allow ...)
-	TODO: check
+	NOT-FOR-US: Samsung Mobile
 CVE-2026-21076 (Incorrect authorization in Samsung Health prior to version 7.0.0 allow ...)
-	TODO: check
+	NOT-FOR-US: Samsung Mobile
 CVE-2026-21075 (Improper authorization in handler for custom URL scheme in My Galaxy p ...)
-	TODO: check
+	NOT-FOR-US: Samsung Mobile
 CVE-2026-21074 (Incorrect default permissions in Bixby prior to version 4.0.86.0 allow ...)
-	TODO: check
+	NOT-FOR-US: Samsung Mobile
 CVE-2026-21073 (Improper input validation in Galaxy Themes prior to SMR Aug-2026 Relea ...)
-	TODO: check
+	NOT-FOR-US: Samsung Mobile
 CVE-2026-21072 (Improper input validation in VC1 codec in libsavsvc.so prior to SMR Au ...)
-	TODO: check
+	NOT-FOR-US: Samsung Mobile
 CVE-2026-21071 (Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR  ...)
-	TODO: check
+	NOT-FOR-US: Samsung Mobile
 CVE-2026-21070 (Improper input validation in Samsung Message prior to SMR Aug-2026 Rel ...)
-	TODO: check
+	NOT-FOR-US: Samsung Mobile
 CVE-2026-21069 (Incorrect conversion between numeric types in VC1 codec in libsavsvc.s ...)
-	TODO: check
+	NOT-FOR-US: Samsung Mobile
 CVE-2026-21068 (Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Rel ...)
-	TODO: check
+	NOT-FOR-US: Samsung Mobile
 CVE-2026-21067 (Improper input validation in libsmsd.so prior to SMR Aug-2026 Release  ...)
-	TODO: check
+	NOT-FOR-US: Samsung Mobile
 CVE-2026-21066 (Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug ...)
-	TODO: check
+	NOT-FOR-US: Samsung Mobile
 CVE-2026-21065 (Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 R ...)
-	TODO: check
+	NOT-FOR-US: Samsung Mobile
 CVE-2026-21064 (Improper access control in Weaver prior to SMR Aug-2026 Release 1 allo ...)
-	TODO: check
+	NOT-FOR-US: Samsung Mobile
 CVE-2026-21063 (Improper export of android application components in AppLock prior to  ...)
-	TODO: check
+	NOT-FOR-US: Samsung Mobile
 CVE-2026-21062 (Authorization bypass in SemClipboardService prior to SMR Aug-2026 Rele ...)
-	TODO: check
+	NOT-FOR-US: Samsung Mobile
 CVE-2026-21061 (Improper input validation in Samsung Dialer prior to SMR Aug-2026 Rele ...)
-	TODO: check
+	NOT-FOR-US: Samsung Mobile
 CVE-2026-21060 (Improper input validation in Samsung Contacts prior to SMR Aug-2026 Re ...)
-	TODO: check
+	NOT-FOR-US: Samsung Mobile
 CVE-2026-21059 (Improper export of android application components in Samsung Contacts  ...)
-	TODO: check
+	NOT-FOR-US: Samsung Mobile
 CVE-2026-21058 (Improper input validation in Samsung Contacts prior to SMR Aug-2026 Re ...)
-	TODO: check
+	NOT-FOR-US: Samsung Mobile
 CVE-2026-19433 (Authorization Bypass Through User-Controlled Key in the contact manage ...)
 	TODO: check
 CVE-2026-19429 (Jenkins FilePath.untarFrom() in all versions, including those with the ...)
@@ -449,7 +449,7 @@ CVE-2026-12984 (Insufficiently Protected Credentials vulnerability in Zyxel Netw
 CVE-2026-12624 (Vault\u2019s ACL policy engine did not consistently enforce a wildcard ...)
 	TODO: check
 CVE-2026-12339 (A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows ...)
-	TODO: check
+	NOT-FOR-US: TPLink
 CVE-2026-10754 (Pega Platform versions 8.5.0 through 25.1.2 are affected by an imprope ...)
 	TODO: check
 CVE-2026-68870 (The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azur ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/422f2efd6483320728456feda473fb8b75bee7fe

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/422f2efd6483320728456feda473fb8b75bee7fe
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260810/6ad08e07/attachment.htm>


More information about the debian-security-tracker-commits mailing list