[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 11 21:04:05 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ef68c294 by Salvatore Bonaccorso at 2026-08-11T22:03:32+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -54,25 +54,25 @@ CVE-2026-73212 (Coturn is a free open source implementation of TURN and STUN Ser
 CVE-2026-73211 (PeerTube is an ActivityPub-federated video streaming platform. Prior t ...)
 	- peertube <itp> (bug #950821)
 CVE-2026-73210 (A Server-Side Request Forgery (SSRF) vulnerability existed in Lookyloo ...)
-	TODO: check
+	NOT-FOR-US: Lookyloo PlaywrightCapture
 CVE-2026-73162 (Affected versions of MISP cti-transmute expose several state-changing  ...)
-	TODO: check
+	NOT-FOR-US: MISP
 CVE-2026-73161 (Affected versions of cti-transmute improperly handle conversion-table  ...)
-	TODO: check
+	NOT-FOR-US: MISP
 CVE-2026-73160 (Affected versions of cti-transmute contain an SSRF vulnerability in th ...)
-	TODO: check
+	NOT-FOR-US: MISP
 CVE-2026-73159 (Affected versions of cti-transmute allow a tag's icon value to be stor ...)
-	TODO: check
+	NOT-FOR-US: MISP
 CVE-2026-73158 (Affected versions of cti-transmute insufficiently validate saved graph ...)
-	TODO: check
+	NOT-FOR-US: MISP
 CVE-2026-73157 (Affected versions of cti-transmute render data obtained from a remote  ...)
-	TODO: check
+	NOT-FOR-US: MISP
 CVE-2026-73156 (Affected versions of cti-transmute fail to HTML-escape attacker-contro ...)
-	TODO: check
+	NOT-FOR-US: MISP
 CVE-2026-73155 (Affected versions of cti-transmute allow authenticated users to add or ...)
-	TODO: check
+	NOT-FOR-US: MISP
 CVE-2026-73140 (Affected versions of cti-transmute fail to apply comment-level access- ...)
-	TODO: check
+	NOT-FOR-US: MISP
 CVE-2026-73090 (PeerTube is an ActivityPub-federated video streaming platform. Prior t ...)
 	- peertube <itp> (bug #950821)
 CVE-2026-73089 (Browserslist is a configuration tool for sharing target browsers and N ...)
@@ -84,7 +84,7 @@ CVE-2026-73088 (Browserslist is a configuration tool for sharing target browsers
 	NOTE: https://github.com/browserslist/browserslist/security/advisories/GHSA-73wf-gq98-2v4g
 	NOTE: Fixed by: https://github.com/browserslist/browserslist/commit/f9914ad9effc865ccc27d816255625890b31ca51 (4.28.7)
 CVE-2026-73087 (Dozzle is a realtime log viewer for docker containers. From 10.5.2 unt ...)
-	TODO: check
+	NOT-FOR-US: Dozzle
 CVE-2026-73086 (nanoid is a secure, URL-friendly, unique string ID generator for JavaS ...)
 	- node-postcss 8.5.14+~cs9.3.34-1
 	- node-mocha 9.1.4+ds1+~cs28.2.8-1
@@ -95,19 +95,19 @@ CVE-2026-73086 (nanoid is a secure, URL-friendly, unique string ID generator for
 	NOTE: Fixed by: https://github.com/ai/nanoid/commit/821dfed7b5db7f88e92f56c60eef32c8135077c3 (3.3.12)
 	NOTE: Fixed by: https://github.com/ai/nanoid/commit/b0036ed60dc9facd7f1191a50dfb3076500202ac (3.3.12)
 CVE-2026-73085 (Audiobookshelf is a self-hosted audiobook and podcast server. Prior to ...)
-	TODO: check
+	NOT-FOR-US: Audiobookshelf
 CVE-2026-73084 (Activepieces is an open source AI workflow automation platform. Prior  ...)
-	TODO: check
+	NOT-FOR-US: Activepieces
 CVE-2026-73083 (Activepieces is an open source AI workflow automation platform. Prior  ...)
-	TODO: check
+	NOT-FOR-US: Activepieces
 CVE-2026-73082 (Activepieces is an open source AI workflow automation platform. Prior  ...)
-	TODO: check
+	NOT-FOR-US: Activepieces
 CVE-2026-73081 (Activepieces is an open source AI workflow automation platform. Prior  ...)
-	TODO: check
+	NOT-FOR-US: Activepieces
 CVE-2026-73080 (SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer ...)
 	TODO: check
 CVE-2026-73079 (Sub2API is an AI API gateway platform designed to distribute and manag ...)
-	TODO: check
+	NOT-FOR-US: Sub2API
 CVE-2026-73078 (Vim is an open source, command line text editor. Prior to 9.2.0840, ru ...)
 	TODO: check
 CVE-2026-73077 (Vim is an open source, command line text editor. Prior to 9.2.0839, th ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ef68c29444e161ddd9f1cb27b70abca0a7e5484a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ef68c29444e161ddd9f1cb27b70abca0a7e5484a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260811/bcb5c262/attachment.htm>


More information about the debian-security-tracker-commits mailing list