[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Aug 12 07:31:03 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
2a484189 by Moritz Muehlenhoff at 2026-08-12T08:30:48+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,5 @@
+CVE-2026-19496
+	NOT-FOR-US: Red Hat sources-api-go
 CVE-2026-73283
 	- openssh <unfixed>
 	NOTE: https://www.openwall.com/lists/oss-security/2026/08/12/1
@@ -2294,11 +2296,11 @@ CVE-2026-14549 (The Ray Enterprise Translation WordPress plugin through 1.7.3 do
 CVE-2026-14548 (The Ray Enterprise Translation WordPress plugin through 1.7.3 does not ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-14450 (A flaw was found in the MaaS API. This vulnerability allows any pod wi ...)
-	TODO: check
+	NOT-FOR-US: Red Hat OpenShift AI
 CVE-2026-13717 (A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Imp ...)
 	NOT-FOR-US: Red Hat OpenShift AI
 CVE-2026-13716 (Path traversal in server import and admin file upload in Crafty Contro ...)
-	TODO: check
+	NOT-FOR-US: Crafty Controller
 CVE-2026-12052 (The USB device-side CDC NCM class control-to-host handler usbd_cdc_ncm ...)
 	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-12051 (The USB DFU class implementation in Zephyr's new (experimental) device ...)
@@ -2380,7 +2382,7 @@ CVE-2026-72863 (Dokploy is a free, self-hostable Platform as a Service (PaaS). P
 CVE-2026-72862 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
 	NOT-FOR-US: Dokploy
 CVE-2026-72761 (The webhook URL validator in `website/notifications/webhooks.py` uses  ...)
-	TODO: check
+	NOT-FOR-US: vulnerability-lookup
 CVE-2026-72760 (Affected versions of MISP cti-transmute disclose users' email addresse ...)
 	NOT-FOR-US: MISP
 CVE-2026-72759 (In affected versions of MISP cti-transmute, the conversion-history det ...)
@@ -2608,9 +2610,9 @@ CVE-2026-64940 (Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory
 CVE-2026-63623 (A flaw was found in libvirt. During storage volume clone or convert op ...)
 	TODO: check
 CVE-2026-63106 (ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection  ...)
-	TODO: check
+	NOT-FOR-US: ReadyEcommerceCrafty Controller
 CVE-2026-63105 (ReadyEcommerce before 4.5.2 contains a stored cross-site scripting (XS ...)
-	TODO: check
+	NOT-FOR-US: ReadyEcommerceCrafty Controller
 CVE-2026-59233 (Missing Authorization in the permission management component in Roskus ...)
 	TODO: check
 CVE-2026-59112 (Improper verification of cryptographic signature and Improper Check fo ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2a4841893fffb9d862e41119f463a17ba1d4ce38

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2a4841893fffb9d862e41119f463a17ba1d4ce38
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260812/3694dc34/attachment.htm>


More information about the debian-security-tracker-commits mailing list