[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Aug 12 12:05:33 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a3a4ae27 by Moritz Muehlenhoff at 2026-08-12T13:05:14+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2050,7 +2050,7 @@ CVE-2026-17535 (Velociraptor's NTFS parsing library mishandles several out of bo
 CVE-2026-17061 (A Deserialization of Untrusted Data vulnerability affecting SIMULIA Ex ...)
 	NOT-FOR-US: Dassault Systemes
 CVE-2026-15567 (A flaw was found in Wildfly. A remote unauthenticated attacker can tri ...)
-	TODO: check
+	- wildfly <itp> (bug #752018)
 CVE-2026-15565 (A flaw was found in Undertow. A remote attacker can cause Out of Memor ...)
 	TODO: check
 CVE-2026-15563 (A flaw was found in EAP's IIOP. The listener's NameService would accep ...)
@@ -2482,13 +2482,13 @@ CVE-2026-6426 (A type mismatch vulnerability was found in QEMU's vhost inflight
 CVE-2026-6181 (The Device Configuration Framework is vulnerable to an authentication  ...)
 	NOT-FOR-US: Axis Communication
 CVE-2026-69118 (Cachet through 2.4.1 contains a server-side template injection vulnera ...)
-	TODO: check
+	NOT-FOR-US: Cachet
 CVE-2026-69116 (FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering an ...)
 	NOT-FOR-US: FlyEnv
 CVE-2026-69114 (Spacebar Server before commit 8d126f4 contains a cross-channel message ...)
 	TODO: check
 CVE-2026-69112 (Hugging Face Accelerate through 1.14.0 contains a path traversal vulne ...)
-	TODO: check
+	NOT-FOR-US: Hugging Face Accelerate
 CVE-2026-66779 (Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver App ...)
 	NOT-FOR-US: SAP
 CVE-2026-66778 (SAP Approuter does not sufficiently sanitize certain request headers b ...)
@@ -2550,9 +2550,9 @@ CVE-2026-58230 (SAP Approuter does not sufficiently validate certain token conte
 CVE-2026-4757 (A VAPIX API parameter had improper input validation which could allow  ...)
 	NOT-FOR-US: Axis Communication
 CVE-2026-48161 (react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 a ...)
-	TODO: check
+	NOT-FOR-US: react18-use
 CVE-2026-48160 (react-tracked provides state usage tracking with Proxies. Between 2026 ...)
-	TODO: check
+	NOT-FOR-US: react-tracked
 CVE-2026-44765 (Due to a Missing Authorization Check vulnerability in SAP Manufacturin ...)
 	NOT-FOR-US: SAP
 CVE-2026-44764 (Due to a Missing Authorization Check vulnerability in SAP Manufacturin ...)
@@ -2564,15 +2564,15 @@ CVE-2026-44762 (SAP Data Services Management Console allows an overly permissive
 CVE-2026-44758 (SAP Manufacturing Integration and Intelligence (MII) allows an attacke ...)
 	NOT-FOR-US: SAP
 CVE-2026-44401 (Typemill CMS version 2.x contains a persistent cross-site scripting vu ...)
-	TODO: check
+	NOT-FOR-US: Typemill CMS
 CVE-2026-40130 (SAP SAPSPrint Service has memory corruption vulnerabilities in the han ...)
 	NOT-FOR-US: SAP
 CVE-2026-34265 (SAP NetWeaver Application Server ABAP allows an unauthenticated attack ...)
 	NOT-FOR-US: SAP
 CVE-2026-24330 (A flaw was found in wildfly-core. A remote attacker, authenticated as  ...)
-	TODO: check
+	- wildfly <itp> (bug #752018)
 CVE-2026-24329 (A flaw was found in wildfly-core. A remote user authenticated as an ad ...)
-	TODO: check
+	- wildfly <itp> (bug #752018)
 CVE-2026-19518 (Improper Validation of Specified Quantity in Input vulnerability in Sa ...)
 	TODO: check
 CVE-2026-19517 (Improper Validation of Specified Quantity in Input and Allocation of R ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a3a4ae274d2ddf3315336c2d5d4fede8c521de60

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a3a4ae274d2ddf3315336c2d5d4fede8c521de60
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260812/93a842fa/attachment.htm>


More information about the debian-security-tracker-commits mailing list