[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Aug 11 21:04:05 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
ef68c294 by Salvatore Bonaccorso at 2026-08-11T22:03:32+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -54,25 +54,25 @@ CVE-2026-73212 (Coturn is a free open source implementation of TURN and STUN Ser
CVE-2026-73211 (PeerTube is an ActivityPub-federated video streaming platform. Prior t ...)
- peertube <itp> (bug #950821)
CVE-2026-73210 (A Server-Side Request Forgery (SSRF) vulnerability existed in Lookyloo ...)
- TODO: check
+ NOT-FOR-US: Lookyloo PlaywrightCapture
CVE-2026-73162 (Affected versions of MISP cti-transmute expose several state-changing ...)
- TODO: check
+ NOT-FOR-US: MISP
CVE-2026-73161 (Affected versions of cti-transmute improperly handle conversion-table ...)
- TODO: check
+ NOT-FOR-US: MISP
CVE-2026-73160 (Affected versions of cti-transmute contain an SSRF vulnerability in th ...)
- TODO: check
+ NOT-FOR-US: MISP
CVE-2026-73159 (Affected versions of cti-transmute allow a tag's icon value to be stor ...)
- TODO: check
+ NOT-FOR-US: MISP
CVE-2026-73158 (Affected versions of cti-transmute insufficiently validate saved graph ...)
- TODO: check
+ NOT-FOR-US: MISP
CVE-2026-73157 (Affected versions of cti-transmute render data obtained from a remote ...)
- TODO: check
+ NOT-FOR-US: MISP
CVE-2026-73156 (Affected versions of cti-transmute fail to HTML-escape attacker-contro ...)
- TODO: check
+ NOT-FOR-US: MISP
CVE-2026-73155 (Affected versions of cti-transmute allow authenticated users to add or ...)
- TODO: check
+ NOT-FOR-US: MISP
CVE-2026-73140 (Affected versions of cti-transmute fail to apply comment-level access- ...)
- TODO: check
+ NOT-FOR-US: MISP
CVE-2026-73090 (PeerTube is an ActivityPub-federated video streaming platform. Prior t ...)
- peertube <itp> (bug #950821)
CVE-2026-73089 (Browserslist is a configuration tool for sharing target browsers and N ...)
@@ -84,7 +84,7 @@ CVE-2026-73088 (Browserslist is a configuration tool for sharing target browsers
NOTE: https://github.com/browserslist/browserslist/security/advisories/GHSA-73wf-gq98-2v4g
NOTE: Fixed by: https://github.com/browserslist/browserslist/commit/f9914ad9effc865ccc27d816255625890b31ca51 (4.28.7)
CVE-2026-73087 (Dozzle is a realtime log viewer for docker containers. From 10.5.2 unt ...)
- TODO: check
+ NOT-FOR-US: Dozzle
CVE-2026-73086 (nanoid is a secure, URL-friendly, unique string ID generator for JavaS ...)
- node-postcss 8.5.14+~cs9.3.34-1
- node-mocha 9.1.4+ds1+~cs28.2.8-1
@@ -95,19 +95,19 @@ CVE-2026-73086 (nanoid is a secure, URL-friendly, unique string ID generator for
NOTE: Fixed by: https://github.com/ai/nanoid/commit/821dfed7b5db7f88e92f56c60eef32c8135077c3 (3.3.12)
NOTE: Fixed by: https://github.com/ai/nanoid/commit/b0036ed60dc9facd7f1191a50dfb3076500202ac (3.3.12)
CVE-2026-73085 (Audiobookshelf is a self-hosted audiobook and podcast server. Prior to ...)
- TODO: check
+ NOT-FOR-US: Audiobookshelf
CVE-2026-73084 (Activepieces is an open source AI workflow automation platform. Prior ...)
- TODO: check
+ NOT-FOR-US: Activepieces
CVE-2026-73083 (Activepieces is an open source AI workflow automation platform. Prior ...)
- TODO: check
+ NOT-FOR-US: Activepieces
CVE-2026-73082 (Activepieces is an open source AI workflow automation platform. Prior ...)
- TODO: check
+ NOT-FOR-US: Activepieces
CVE-2026-73081 (Activepieces is an open source AI workflow automation platform. Prior ...)
- TODO: check
+ NOT-FOR-US: Activepieces
CVE-2026-73080 (SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer ...)
TODO: check
CVE-2026-73079 (Sub2API is an AI API gateway platform designed to distribute and manag ...)
- TODO: check
+ NOT-FOR-US: Sub2API
CVE-2026-73078 (Vim is an open source, command line text editor. Prior to 9.2.0840, ru ...)
TODO: check
CVE-2026-73077 (Vim is an open source, command line text editor. Prior to 9.2.0839, th ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ef68c29444e161ddd9f1cb27b70abca0a7e5484a
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ef68c29444e161ddd9f1cb27b70abca0a7e5484a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260811/bcb5c262/attachment.htm>
More information about the debian-security-tracker-commits
mailing list