[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Wed Aug 12 15:07:46 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
f8dcdff3 by Moritz Muehlenhoff at 2026-08-12T16:04:01+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -109,7 +109,7 @@ CVE-2026-73232 (ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf al
CVE-2026-73231 (Faker generates massive amounts of fake data in the browser and Node.j ...)
TODO: check
CVE-2026-73230 (Ente provides end-to-end encrypted cloud services and security tools. ...)
- TODO: check
+ NOT-FOR-US: Ente
CVE-2026-73229 (Django REST framework is a powerful and flexible toolkit for building ...)
- djangorestframework <unfixed>
NOTE: https://github.com/encode/django-rest-framework/security/advisories/GHSA-g47c-3xmw-q6m2
@@ -128,39 +128,39 @@ CVE-2026-73031 (telegram-search contains a stored cross-site scripting vulnerabi
CVE-2026-72526 (A flaw was found in the multicloud-integrations component. The Applica ...)
TODO: check
CVE-2026-71845 (A flaw was found in insights-client. The setDefault() function logs th ...)
- TODO: check
+ NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
CVE-2026-71475 (A flaw was found in insights-client. A compromised managed cluster, re ...)
- TODO: check
+ NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
CVE-2026-71474 (A flaw was found in insights-client. When the application receives a n ...)
- TODO: check
+ NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
CVE-2026-71468 (A flaw was found in acm-search-v2-api-rhel9. When the `getFederationCo ...)
- TODO: check
+ NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
CVE-2026-71467 (A flaw was found in search-v2-api. The authentication middleware in th ...)
- TODO: check
+ NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
CVE-2026-71290 (Improper TLS hostname verification vulnerability in Apache HttpCompone ...)
TODO: check
CVE-2026-70398 (A flaw was found in multicloud-integrations, a component of Red Hat Ad ...)
- TODO: check
+ NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
CVE-2026-70339 (Access of resource using incompatible type ('type confusion') in Micro ...)
NOT-FOR-US: Microsoft
CVE-2026-6484 (In an UEFI, Lack of verified boot to certain FV may cause arbitrary co ...)
NOT-FOR-US: Insyde
CVE-2026-68067 (The login endpoint on the Mira cloud API accepts any format-valid stri ...)
- TODO: check
+ NOT-FOR-US: Mira
CVE-2026-67568 (The distributed Mira Android APK v4.5.15.4 allows an attacker read/wri ...)
- TODO: check
+ NOT-FOR-US: Mira
CVE-2026-67558 (The Mira Android companion app v4.5.15.4 identifies the paired Mira ho ...)
- TODO: check
+ NOT-FOR-US: Mira
CVE-2026-66878 (A flaw was found in multicloud-operators-subscription. A privileged us ...)
- TODO: check
+ NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
CVE-2026-66875 (In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, ...)
- TODO: check
+ NOT-FOR-US: Mira
CVE-2026-66832 (When the Mira Android app opens in-app WebView content (e.g., shop red ...)
- TODO: check
+ NOT-FOR-US: Mira
CVE-2026-66659 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-66340 (The Mira cloud authentication endpoints do not enforce per-account rat ...)
- TODO: check
+ NOT-FOR-US: Mira
CVE-2026-66154 (An insufficient certificate validation in a privileged communication w ...)
NOT-FOR-US: SonicWall
CVE-2026-66150 (Improper Control of Generation of Code ('Code Injection') Vulnerabilit ...)
@@ -176,15 +176,15 @@ CVE-2026-66146 (Multiple Cross-Site Scripting (XSS) vulnerabilities were identif
CVE-2026-66145 (An unauthenticated remote code execution vulnerability was identified ...)
NOT-FOR-US: SonicWall
CVE-2026-66098 (The Mira hormone monitor device firmware accepts a 0x01 write from any ...)
- TODO: check
+ NOT-FOR-US: Mira
CVE-2026-65655 (When OAuth authentication is enabled and browser-facing TLS terminates ...)
TODO: check
CVE-2026-64954 (Velociraptor allows scheduling new collections via VQL queries in note ...)
TODO: check
CVE-2026-64934 (The Mira cloud API accepts the firmware version reported by the compan ...)
- TODO: check
+ NOT-FOR-US: Mira
CVE-2026-64927 (A flaw was found in the multicloud-operators-channel component. This v ...)
- TODO: check
+ NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
CVE-2026-63177 (Malcolm is a network traffic analysis tool suite. Prior to version 26. ...)
TODO: check
CVE-2026-63134 (Malcolm is a network traffic analysis tool suite. Prior to version 26. ...)
@@ -1685,17 +1685,17 @@ CVE-2026-53414 (Missing bounds check in the annotator function of Zoom Clients a
CVE-2026-53413 (Missing bounds check in the annotator function of Zoom Clients allows ...)
NOT-FOR-US: Zoom
CVE-2026-51584 (An issue in usememos v0.27.1 allows a remote attacker to achieve accou ...)
- TODO: check
+ NOT-FOR-US: usememos
CVE-2026-51583 (An issue in usememos through v0.30.0 allows a remote authenticated att ...)
- TODO: check
+ NOT-FOR-US: usememos
CVE-2026-50516 (Missing authentication for critical function in Microsoft Azure Kubern ...)
NOT-FOR-US: Microsoft
CVE-2026-50472 (Heap-based buffer overflow in Windows LUAFV allows an authorized attac ...)
NOT-FOR-US: Microsoft
CVE-2026-50237 (A Server-Side Request Forgery and supply chain flaw was found in the O ...)
- TODO: check
+ NOT-FOR-US: Red Hat OpenShift Container Platform
CVE-2026-50236 (An authenticated SSRF flaw was found in the OpenShift Console Dev Cons ...)
- TODO: check
+ NOT-FOR-US: Red Hat OpenShift Container Platform
CVE-2026-50064 (A vulnerability has been identified in Solid Edge SE2025 (All versions ...)
NOT-FOR-US: Siemens
CVE-2026-50063 (A vulnerability has been identified in Solid Edge SE2025 (All versions ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f8dcdff38594506e955a76d24d4caf60f4bdd992
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f8dcdff38594506e955a76d24d4caf60f4bdd992
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260812/eefb82e6/attachment.htm>
More information about the debian-security-tracker-commits
mailing list