[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 11 09:31:27 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
79733ee4 by Salvatore Bonaccorso at 2026-08-11T10:31:08+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -14,11 +14,11 @@ CVE-2026-73030 (unearth through 0.18.2, fixed in commit 6c78164, contains a path
 	NOTE: https://github.com/frostming/unearth/pull/181
 	NOTE: Fixed by: https://github.com/frostming/unearth/commit/6c78164e7bfa28b8b3d6f247b87e560692e3c8ba
 CVE-2026-72919 (Rocket.Chat is an open-source, secure, fully customizable communicatio ...)
-	TODO: check
+	NOT-FOR-US: Rocket.Chat
 CVE-2026-72918 (Rocket.Chat is an open-source, secure, fully customizable communicatio ...)
-	TODO: check
+	NOT-FOR-US: Rocket.Chat
 CVE-2026-72917 (AnythingLLM is an application that turns pieces of content into contex ...)
-	TODO: check
+	NOT-FOR-US: AnythingLLM
 CVE-2026-72916 (Mastodon is a free, open-source social network server based on Activit ...)
 	- mastodon <itp> (bug #859741)
 CVE-2026-72915 (Mastodon is a free, open-source social network server based on Activit ...)
@@ -30,57 +30,57 @@ CVE-2026-72913 (Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, t
 	NOTE: https://github.com/kovidgoyal/kitty/security/advisories/GHSA-ccp2-q4v6-rw94
 	NOTE: Fixed by: https://github.com/kovidgoyal/kitty/commit/9dca948e9bec3c926ab3370f2cd10f9b9b10821f (0.48.2)
 CVE-2026-72912 (CyberChef is a web app for encryption, encoding, compression, and data ...)
-	TODO: check
+	NOT-FOR-US: CyberChef
 CVE-2026-72911 (ERPNext is a free and open source Enterprise Resource Planning tool. P ...)
-	TODO: check
+	NOT-FOR-US: Frappe ERPNext
 CVE-2026-72910 (ERPNext is a free and open source Enterprise Resource Planning tool. P ...)
-	TODO: check
+	NOT-FOR-US: Frappe ERPNext
 CVE-2026-72909 (ERPNext is a free and open source Enterprise Resource Planning tool. P ...)
-	TODO: check
+	NOT-FOR-US: Frappe ERPNext
 CVE-2026-72908 (ERPNext is a free and open source Enterprise Resource Planning tool. P ...)
-	TODO: check
+	NOT-FOR-US: Frappe ERPNext
 CVE-2026-72907 (ERPNext is a free and open source Enterprise Resource Planning tool. P ...)
-	TODO: check
+	NOT-FOR-US: Frappe ERPNext
 CVE-2026-72906 (ERPNext is a free and open source Enterprise Resource Planning tool. P ...)
-	TODO: check
+	NOT-FOR-US: Frappe ERPNext
 CVE-2026-72905
 	REJECTED
 CVE-2026-72904 (Firecrawl turns entire websites into LLM-ready markdown or structured  ...)
-	TODO: check
+	NOT-FOR-US: Firecrawl
 CVE-2026-72903 (Tabby (formerly Terminus) is a highly configurable terminal emulator.  ...)
-	TODO: check
+	NOT-FOR-US: Tabby (formerly Terminus, but not the same as src:terminus)
 CVE-2026-72902 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
-	TODO: check
+	NOT-FOR-US: Dokploy
 CVE-2026-72901 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
-	TODO: check
+	NOT-FOR-US: Dokploy
 CVE-2026-72886 (Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0. ...)
-	TODO: check
+	NOT-FOR-US: Dokploy
 CVE-2026-72885 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
-	TODO: check
+	NOT-FOR-US: Dokploy
 CVE-2026-72884 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
-	TODO: check
+	NOT-FOR-US: Dokploy
 CVE-2026-72883 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
-	TODO: check
+	NOT-FOR-US: Dokploy
 CVE-2026-72882 (Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28 ...)
-	TODO: check
+	NOT-FOR-US: Dokploy
 CVE-2026-72881 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
-	TODO: check
+	NOT-FOR-US: Dokploy
 CVE-2026-72880 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
-	TODO: check
+	NOT-FOR-US: Dokploy
 CVE-2026-72879 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
-	TODO: check
+	NOT-FOR-US: Dokploy
 CVE-2026-72878 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
-	TODO: check
+	NOT-FOR-US: Dokploy
 CVE-2026-72877 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
-	TODO: check
+	NOT-FOR-US: Dokploy
 CVE-2026-72876 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
-	TODO: check
+	NOT-FOR-US: Dokploy
 CVE-2026-72875 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
-	TODO: check
+	NOT-FOR-US: Dokploy
 CVE-2026-72874 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
-	TODO: check
+	NOT-FOR-US: Dokploy
 CVE-2026-72873 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
-	TODO: check
+	NOT-FOR-US: Dokploy
 CVE-2026-72743 (SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cros ...)
 	TODO: check
 CVE-2026-71966 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated c ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/79733ee48972d6e261cf4db8698af24c0e2a312f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/79733ee48972d6e261cf4db8698af24c0e2a312f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260811/2a50bf75/attachment.htm>


More information about the debian-security-tracker-commits mailing list