[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Aug 10 21:19:05 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
aafa7654 by Salvatore Bonaccorso at 2026-08-10T22:18:43+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -116,21 +116,21 @@ CVE-2026-72586 (A missing authentication vulnerability in frangoteam/FUXA throug
CVE-2026-72585 (An authorization bypass vulnerability in Grafana through 13.2.0 allows ...)
TODO: check
CVE-2026-72584 (A time-of-check/time-of-use (TOCTOU) race condition in fastschema thro ...)
- TODO: check
+ NOT-FOR-US: fastschema
CVE-2026-72583 (A stored cross-site scripting (XSS) vulnerability in fastschema throug ...)
- TODO: check
+ NOT-FOR-US: fastschema
CVE-2026-72582 (A NULL pointer dereference vulnerability in fastschema through v0.15.1 ...)
- TODO: check
+ NOT-FOR-US: fastschema
CVE-2026-72581 (A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-pat ...)
NOT-FOR-US: duhow/xiaoai-patch
CVE-2026-72580 (An OS command injection vulnerability in duhow/xiaoai-patch through co ...)
NOT-FOR-US: duhow/xiaoai-patch
CVE-2026-72579 (An OS command injection vulnerability in NASA HyperCP (main branch) al ...)
- TODO: check
+ NOT-FOR-US: NASA HyperCP
CVE-2026-72578 (A cross-site request forgery (CSRF) vulnerability in FreePBX Framework ...)
- TODO: check
+ NOT-FOR-US: FreePBX Framework
CVE-2026-72577 (Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an una ...)
- TODO: check
+ NOT-FOR-US: NASA fprime-gds
CVE-2026-72576 (A stored cross-site scripting (XSS) vulnerability in Bludit 4.0.0-beta ...)
NOT-FOR-US: Bludit
CVE-2026-72575 (An improper authorization vulnerability in daptin through v0.12.34 all ...)
@@ -144,19 +144,19 @@ CVE-2026-72572 (A path traversal vulnerability in o1lab/xmysql (all versions) al
CVE-2026-72571 (A path traversal vulnerability in mustafaakin/cast-localvideo (all ver ...)
NOT-FOR-US: mustafaakin/cast-localvideo
CVE-2026-72570 (A stored cross-site scripting (XSS) vulnerability in cube-root/directo ...)
- TODO: check
+ NOT-FOR-US: cube-root/directory-serve
CVE-2026-72569 (A path traversal vulnerability in cube-root/directory-serve through 1. ...)
- TODO: check
+ NOT-FOR-US: cube-root/directory-serve
CVE-2026-72568 (An out-of-bounds read vulnerability in Redis through 8.8.1 allows an a ...)
TODO: check
CVE-2026-72567 (An improper path validation vulnerability in AsyncFuncAI/deepwiki-open ...)
- TODO: check
+ NOT-FOR-US: AsyncFuncAI/deepwiki-open
CVE-2026-72566 (A server-side request forgery (SSRF) vulnerability in automatisch thro ...)
TODO: check
CVE-2026-72565 (A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows ...)
- TODO: check
+ NOT-FOR-US: Tencent APIJSON
CVE-2026-72564 (An improper authorization vulnerability in fosrl/pangolin through v1.2 ...)
- TODO: check
+ NOT-FOR-US: fosrl/pangolin
CVE-2026-71969 (OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer u ...)
- optee-os <unfixed>
NOTE: https://github.com/OP-TEE/optee_os/pull/7898
@@ -171,15 +171,15 @@ CVE-2026-71967 (OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a nu
NOTE: https://github.com/OP-TEE/optee_os/pull/7899
NOTE: Fixed by: https://github.com/OP-TEE/optee_os/commit/0aadfc23407f50e770eb5ddd871fc208f5626833
CVE-2026-71964 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file ...)
- TODO: check
+ NOT-FOR-US: CyberPanel
CVE-2026-71962 (Flowise versions 2.2.4 through 3.1.4 contain a missing authorization v ...)
NOT-FOR-US: Flowise
CVE-2026-71959 (Bitwarden Server before 2026.7.2 does not verify that the caller is a ...)
TODO: check
CVE-2026-71577 (A flaw was found in multicluster-global-hub. During a ManagedClusterMi ...)
- TODO: check
+ NOT-FOR-US: multicluster-global-hub
CVE-2026-71576 (A flaw was found in multicluster-global-hub. The manager component imp ...)
- TODO: check
+ NOT-FOR-US: multicluster-global-hub
CVE-2026-71394 (GNU Emacs for Android improperly validates the table header input in s ...)
- emacs <unfixed>
NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-71391
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/aafa7654e1b951b0f400e86cc715cd2f96b30df0
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/aafa7654e1b951b0f400e86cc715cd2f96b30df0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260810/81e29a53/attachment.htm>
More information about the debian-security-tracker-commits
mailing list