[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Wed Aug 12 07:31:03 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
2a484189 by Moritz Muehlenhoff at 2026-08-12T08:30:48+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,5 @@
+CVE-2026-19496
+ NOT-FOR-US: Red Hat sources-api-go
CVE-2026-73283
- openssh <unfixed>
NOTE: https://www.openwall.com/lists/oss-security/2026/08/12/1
@@ -2294,11 +2296,11 @@ CVE-2026-14549 (The Ray Enterprise Translation WordPress plugin through 1.7.3 do
CVE-2026-14548 (The Ray Enterprise Translation WordPress plugin through 1.7.3 does not ...)
NOT-FOR-US: WordPress plugin
CVE-2026-14450 (A flaw was found in the MaaS API. This vulnerability allows any pod wi ...)
- TODO: check
+ NOT-FOR-US: Red Hat OpenShift AI
CVE-2026-13717 (A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Imp ...)
NOT-FOR-US: Red Hat OpenShift AI
CVE-2026-13716 (Path traversal in server import and admin file upload in Crafty Contro ...)
- TODO: check
+ NOT-FOR-US: Crafty Controller
CVE-2026-12052 (The USB device-side CDC NCM class control-to-host handler usbd_cdc_ncm ...)
NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-12051 (The USB DFU class implementation in Zephyr's new (experimental) device ...)
@@ -2380,7 +2382,7 @@ CVE-2026-72863 (Dokploy is a free, self-hostable Platform as a Service (PaaS). P
CVE-2026-72862 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
NOT-FOR-US: Dokploy
CVE-2026-72761 (The webhook URL validator in `website/notifications/webhooks.py` uses ...)
- TODO: check
+ NOT-FOR-US: vulnerability-lookup
CVE-2026-72760 (Affected versions of MISP cti-transmute disclose users' email addresse ...)
NOT-FOR-US: MISP
CVE-2026-72759 (In affected versions of MISP cti-transmute, the conversion-history det ...)
@@ -2608,9 +2610,9 @@ CVE-2026-64940 (Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory
CVE-2026-63623 (A flaw was found in libvirt. During storage volume clone or convert op ...)
TODO: check
CVE-2026-63106 (ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection ...)
- TODO: check
+ NOT-FOR-US: ReadyEcommerceCrafty Controller
CVE-2026-63105 (ReadyEcommerce before 4.5.2 contains a stored cross-site scripting (XS ...)
- TODO: check
+ NOT-FOR-US: ReadyEcommerceCrafty Controller
CVE-2026-59233 (Missing Authorization in the permission management component in Roskus ...)
TODO: check
CVE-2026-59112 (Improper verification of cryptographic signature and Improper Check fo ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2a4841893fffb9d862e41119f463a17ba1d4ce38
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2a4841893fffb9d862e41119f463a17ba1d4ce38
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260812/3694dc34/attachment.htm>
More information about the debian-security-tracker-commits
mailing list