[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 11 04:48:02 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
29da1b4b by Salvatore Bonaccorso at 2026-08-11T05:47:51+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -114,7 +114,7 @@ CVE-2026-72587 (A cache poisoning vulnerability in CoreBunch/Instatic through 0.
 CVE-2026-72586 (A missing authentication vulnerability in frangoteam/FUXA through 1.3. ...)
 	NOT-FOR-US: frangoteam/FUXA
 CVE-2026-72585 (An authorization bypass vulnerability in Grafana through 13.2.0 allows ...)
-	TODO: check
+	NOT-FOR-US: Grafana
 CVE-2026-72584 (A time-of-check/time-of-use (TOCTOU) race condition in fastschema thro ...)
 	NOT-FOR-US: fastschema
 CVE-2026-72583 (A stored cross-site scripting (XSS) vulnerability in fastschema throug ...)
@@ -199,9 +199,9 @@ CVE-2026-71391 (GNU Emacs for Android contains an off-by-one error in the gvar t
 CVE-2026-70622 (tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnera ...)
 	TODO: check
 CVE-2026-6374 (Use of Hard-coded Credentials vulnerability in Zyxel Networks WAH7601  ...)
-	TODO: check
+	NOT-FOR-US: Zyxel
 CVE-2026-6373 (Exposure of sensitive system information to an unauthorized control sp ...)
-	TODO: check
+	NOT-FOR-US: Zyxel
 CVE-2026-6368 (Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to v ...)
 	TODO: check
 CVE-2026-66915 (Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4. ...)
@@ -248,9 +248,9 @@ CVE-2026-65945 (Logs contain replayable JWT tokens in Apache Ranger versions <=
 CVE-2026-65942 (TLS hostname verification issue in Apache Ranger Client Code in versio ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-64941 (URL Redirection to Untrusted Site ('Open Redirect') vulnerability in p ...)
-	TODO: check
+	NOT-FOR-US: phoenixframework
 CVE-2026-64940 (Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contai ...)
-	TODO: check
+	NOT-FOR-US: Nishishi Factory
 CVE-2026-63623 (A flaw was found in libvirt. During storage volume clone or convert op ...)
 	TODO: check
 CVE-2026-63106 (ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection  ...)
@@ -3068,7 +3068,7 @@ CVE-2026-71488 (league/commonmark is a PHP library for parsing and rendering Com
 CVE-2026-71478 (league/commonmark is a PHP library for parsing and rendering CommonMar ...)
 	TODO: check
 CVE-2026-71476 (Nx is a monorepo solution for TypeScript and polyglot codebases. From  ...)
-	TODO: check
+	NOT-FOR-US: Nx
 CVE-2026-71447 (AIL Project contains a stored cross-site scripting vulnerability in th ...)
 	NOT-FOR-US: AIL framework
 CVE-2026-71446 (AIL Framework contains a stored cross-site scripting vulnerability in  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/29da1b4bf8630adb038c8508e82b1d24a9237825

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/29da1b4bf8630adb038c8508e82b1d24a9237825
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260811/a6bd7cab/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list