[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 12 07:21:23 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
737dc864 by Salvatore Bonaccorso at 2026-08-12T08:21:02+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -278,7 +278,7 @@ CVE-2026-73066 (Tesseract is an open source OCR engine. Prior to 5.5.3, a crafte
 CVE-2026-72971 (Improper link resolution before file access ('link following') in Wind ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-72925 (SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @s ...)
-	TODO: check
+	NOT-FOR-US: SWC
 CVE-2026-72922 (AutoGPT is a workflow automation platform for creating, deploying, and ...)
 	NOT-FOR-US: AutoGPT
 CVE-2026-72921 (SeaweedFS is a distributed storage system. Prior to 4.24, the weed/ser ...)
@@ -370,13 +370,13 @@ CVE-2026-72608 (A stored SQL injection vulnerability in Koha through 24.11.17, 2
 CVE-2026-72607 (A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.1 ...)
 	- koha <itp> (bug #702134)
 CVE-2026-72606 (A server-side request forgery vulnerability in Pinry through 2.1.13 al ...)
-	TODO: check
+	NOT-FOR-US: Pinry
 CVE-2026-72605 (A missing authentication vulnerability in Swing Music 3.0.0 allows una ...)
-	TODO: check
+	NOT-FOR-US: Swing Music
 CVE-2026-72604 (A path traversal vulnerability in Intelliants Subrion CMS through 4.2. ...)
 	NOT-FOR-US: Subrion CMS
 CVE-2026-72603 (An OS command injection vulnerability in wg-easy 15.3.0 allows users w ...)
-	TODO: check
+	NOT-FOR-US: wg-easy
 CVE-2026-72602 (A path traversal vulnerability in AsyncFuncAI deepwiki-open through co ...)
 	NOT-FOR-US: AsyncFuncAI deepwiki-open
 CVE-2026-72601 (A broken access control vulnerability in CSZ CMS 1.3.2 allows unauthen ...)
@@ -398,9 +398,9 @@ CVE-2026-72563 (A broken access control vulnerability in BadChoice Handesk as of
 CVE-2026-72562 (An SQL injection vulnerability in Pimcore admin-ui-classic-bundle thro ...)
 	NOT-FOR-US: Pimcore admin-ui-classic-bundle
 CVE-2026-72561 (A broken access control vulnerability in Peppermint Lab Peppermint thr ...)
-	TODO: check
+	NOT-FOR-US: Peppermint Lab Peppermint
 CVE-2026-72560 (A server-side request forgery vulnerability in HumanSignal Label Studi ...)
-	TODO: check
+	NOT-FOR-US: HumanSignal Label Studio
 CVE-2026-72559 (A stored cross-site scripting vulnerability in HortusFox 5.9 allows au ...)
 	NOT-FOR-US: HortusFox
 CVE-2026-72558 (An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows a ...)
@@ -410,9 +410,9 @@ CVE-2026-72557 (An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 a
 CVE-2026-72556 (A remote code execution vulnerability in ZoneMinder 1.39.17 allows any ...)
 	TODO: check
 CVE-2026-72555 (A broken access control vulnerability in Peppermint Lab Peppermint thr ...)
-	TODO: check
+	NOT-FOR-US: Peppermint Lab Peppermint
 CVE-2026-72554 (A broken access control vulnerability in Ladybird Web Solution Faveo H ...)
-	TODO: check
+	NOT-FOR-US: Ladybird Web Solution Faveo Helpdesk
 CVE-2026-72553 (A stored cross-site scripting vulnerability in ElkArte Forum 2.0 Beta  ...)
 	NOT-FOR-US: ElkArte Forum
 CVE-2026-72552 (A server-side request forgery vulnerability in Dub as of 2026-07-10 al ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/737dc86456f803bd6a22d5ef7d1dd99f537490c4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/737dc86456f803bd6a22d5ef7d1dd99f537490c4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260812/d8194f93/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list