[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Aug 11 21:31:09 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
3ad24b8c by Salvatore Bonaccorso at 2026-08-11T22:30:53+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -146,9 +146,9 @@ CVE-2026-73070 (Vim is an open source, command line text editor. Prior to 9.2.08
NOTE: https://github.com/vim/vim/security/advisories/GHSA-49m8-wwxj-mr69
NOTE: Fixed by: https://github.com/vim/vim/commit/5598618b2daf8e36b3bf0251caaefcf0bf8e85e4 (v9.2.0842)
CVE-2026-73069 (Twenty is an open-source CRM (customer relationship management) platfo ...)
- TODO: check
+ NOT-FOR-US: Twenty CRM
CVE-2026-73068 (ToolJet is the open-source foundation am AI-native platform for buildi ...)
- TODO: check
+ NOT-FOR-US: ToolJet
CVE-2026-73067 (Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .tra ...)
- tesseract <unfixed>
NOTE: https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-x3vq-7rr7-5x3h
@@ -165,7 +165,7 @@ CVE-2026-72971 (Improper link resolution before file access ('link following') i
CVE-2026-72925 (SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @s ...)
TODO: check
CVE-2026-72922 (AutoGPT is a workflow automation platform for creating, deploying, and ...)
- TODO: check
+ NOT-FOR-US: AutoGPT
CVE-2026-72921 (SeaweedFS is a distributed storage system. Prior to 4.24, the weed/ser ...)
- seaweedfs <itp> (bug #956957)
CVE-2026-72920 (SeaweedFS is a distributed storage system. Prior to 4.24, the filer re ...)
@@ -219,9 +219,9 @@ CVE-2026-72750 (n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection
CVE-2026-72749 (n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution ...)
NOT-FOR-US: n8n
CVE-2026-72748 (AVideo contains an unauthenticated arbitrary file write vulnerability ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-72747 (AVideo fails to sanitize the phone field during user registration, all ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-72746 (FreeRDP before 3.30.0 contains a server-side authentication bypass in ...)
- freerdp3 3.30.0+dfsg-1
- freerdp2 <not-affected> (Vulnerable code ot present)
@@ -232,11 +232,11 @@ CVE-2026-72745 (FreeRDP before 3.30.0 contains an out-of-bounds vulnerability in
- freerdp2 <removed>
NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vv64-95pc-vj9v
CVE-2026-72744 (Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3.21.10, conta ...)
- TODO: check
+ NOT-FOR-US: Nuxt
CVE-2026-72742 (DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image a ...)
- TODO: check
+ NOT-FOR-US: DSPy
CVE-2026-72713 (XAgent contains a path traversal vulnerability in the workspace file e ...)
- TODO: check
+ NOT-FOR-US: XAgent
CVE-2026-72712 (Nmap versions up to and including 7.99 contains a denial of service vu ...)
TODO: check
CVE-2026-72694 (A flaw was found in MRTG. When the MRTG daemon is started as a root us ...)
@@ -1913,7 +1913,7 @@ CVE-2026-72874 (Dokploy is a free, self-hostable Platform as a Service (PaaS). P
CVE-2026-72873 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
NOT-FOR-US: Dokploy
CVE-2026-72743 (SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cros ...)
- TODO: check
+ NOT-FOR-US: SQLBot
CVE-2026-71966 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated c ...)
TODO: check
CVE-2026-71965 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated r ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3ad24b8c2a7ca9add7ec474d9e567cf5a6b1480a
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3ad24b8c2a7ca9add7ec474d9e567cf5a6b1480a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260811/3b0a7cad/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list