[Git][security-tracker-team/security-tracker][master] Process more NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Aug 12 08:48:30 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
5022c3a4 by Salvatore Bonaccorso at 2026-08-12T09:48:05+02:00
Process more NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3,7 +3,7 @@ CVE-2026-9318 (tablib prior to 3.10.0 contains a stored cross-site scripting vul
NOTE: https://github.com/jazzband/tablib/pull/668
NOTE: Fixed by: https://github.com/jazzband/tablib/commit/b0ff39fb9b2f457e5332249b4cc2ec11eabf46ee (v3.10.0)
CVE-2026-73250 (Notepad++ is a free and open-source source code editor. Prior to 8.9.7 ...)
- TODO: check
+ NOT-FOR-US: Notepad++
CVE-2026-73249 (calibre is an e-book manager. Prior to 9.12.0, the calibre Content Ser ...)
- calibre 9.12.0+ds+~0.10.6-1
NOTE: https://github.com/kovidgoyal/calibre/security/advisories/GHSA-5x64-w63v-x2g6
@@ -13,15 +13,15 @@ CVE-2026-73248 (calibre is an e-book manager. Prior to 9.12.0, calibre processes
NOTE: https://github.com/kovidgoyal/calibre/security/advisories/GHSA-4f7g-rjfp-hmvx
NOTE: Fixed by: https://github.com/kovidgoyal/calibre/commit/dac9990458374a81a5372a768bba6527d965aac8 (v9.12.0)
CVE-2026-73247 (Kestra is an open-source, event-driven orchestration platform. Prior t ...)
- TODO: check
+ NOT-FOR-US: Kestra
CVE-2026-73246 (Kestra is an open-source, event-driven orchestration platform. Prior t ...)
- TODO: check
+ NOT-FOR-US: Kestra
CVE-2026-73245 (Kestra is an open-source, event-driven orchestration platform. Prior t ...)
- TODO: check
+ NOT-FOR-US: Kestra
CVE-2026-73244 (kkFileView is a universal file online preview project based on Spring ...)
- TODO: check
+ NOT-FOR-US: kkFileView
CVE-2026-73243 (kkFileView is a universal file online preview project based on Spring ...)
- TODO: check
+ NOT-FOR-US: kkFileView
CVE-2026-73242 (FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...)
TODO: check
CVE-2026-73241 (FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...)
@@ -41,15 +41,15 @@ CVE-2026-73230 (Ente provides end-to-end encrypted cloud services and security t
CVE-2026-73229 (Django REST framework is a powerful and flexible toolkit for building ...)
TODO: check
CVE-2026-73122 (A flaw was found in the multicloud-operators-channel component of Red ...)
- TODO: check
+ NOT-FOR-US: Red Hat Advanced Cluster Management (RHACM)
CVE-2026-73036 (Bash-it 3.2.0 contains a terminal escape sequence injection vulnerabil ...)
- TODO: check
+ NOT-FOR-US: Bash-it
CVE-2026-73034 (DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability ...)
- TODO: check
+ NOT-FOR-US: DB-GPT
CVE-2026-73032 (PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerabil ...)
- TODO: check
+ NOT-FOR-US: PapersGPT
CVE-2026-73031 (telegram-search contains a stored cross-site scripting vulnerability t ...)
- TODO: check
+ NOT-FOR-US: telegram-search
CVE-2026-72526 (A flaw was found in the multicloud-integrations component. The Applica ...)
TODO: check
CVE-2026-71845 (A flaw was found in insights-client. The setDefault() function logs th ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5022c3a4324b5c034567c79ba9d8e9dbcc75aaf9
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5022c3a4324b5c034567c79ba9d8e9dbcc75aaf9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260812/1e7f2c18/attachment.htm>
More information about the debian-security-tracker-commits
mailing list