[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Aug 12 19:21:17 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
110e77f0 by Moritz Muehlenhoff at 2026-08-12T20:20:51+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,19 @@
+CVE-2026-59242
+	- airflow <itp> (bug #819700)
+CVE-2026-59244
+	- airflow <itp> (bug #819700)
+CVE-2026-68968
+	- airflow <itp> (bug #819700)
+CVE-2026-65017
+	- airflow <itp> (bug #819700)
+CVE-2026-68076
+	- airflow <itp> (bug #819700)
+CVE-2026-68971
+	- airflow <itp> (bug #819700)
+CVE-2026-68970
+	- airflow <itp> (bug #819700)
+CVE-2026-68969
+	- airflow <itp> (bug #819700)
 CVE-2026-XXXX [OSSN-0106: API ramdisk endpoints require network-level access controls]
 	- ironic 1:35.0.1-10
 	NOTE: https://wiki.openstack.org/wiki/OSSN/OSSN-0106
@@ -132,7 +148,7 @@ CVE-2026-73233 (FreeCAD is a free and open-source multiplatform 3D parametric mo
 CVE-2026-73232 (ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a ...)
 	TODO: check
 CVE-2026-73231 (Faker generates massive amounts of fake data in the browser and Node.j ...)
-	TODO: check
+	NOT-FOR-US: Faker
 CVE-2026-73230 (Ente provides end-to-end encrypted cloud services and security tools.  ...)
 	NOT-FOR-US: Ente
 CVE-2026-73229 (Django REST framework is a powerful and flexible toolkit for building  ...)
@@ -231,7 +247,7 @@ CVE-2026-48763 (TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expo
 CVE-2026-48762 (TypeBot is a chatbot builder tool. Prior to version 3.16.0, the OpenAI ...)
 	NOT-FOR-US: TypeBot
 CVE-2026-45618 (LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior t ...)
-	TODO: check
+	NOT-FOR-US: LiquidJS
 CVE-2026-29036 (cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved na ...)
 	TODO: check
 CVE-2026-29035 (CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow v ...)
@@ -243,7 +259,7 @@ CVE-2026-19588 (Integer Overflow to Buffer Overflow vulnerability in Samsung Ope
 CVE-2026-19587 (Uncontrolled Resource Consumption vulnerability in Samsung Open Source ...)
 	TODO: check
 CVE-2026-19579 (Snipe-IT before 8.6.0 contains an authorization bypass (insecure direc ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-19550 (A flaw was found in FreeIPA. The trust-fetch-domains command is gated  ...)
 	TODO: check
 CVE-2026-19217 (The Royal Addons for Elementor  WordPress plugin before 1.7.1065 does  ...)
@@ -263,7 +279,7 @@ CVE-2026-18961 (The Social Login, Passkeys, Magic Link & Email OTP \u2013 Passwo
 CVE-2026-18943 (The WPC Admin Columns WordPress plugin before 2.3.4 does not have auth ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-18844 (The firmware of thePulsetto Vagus Nerve Stimulatoraccepts several undi ...)
-	TODO: check
+	NOT-FOR-US: Pulsetto Vagus Nerve Stimulator
 CVE-2026-18789 (The Ezoic WordPress plugin before 2.23.1 does not properly restrict ac ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-18710 (A MongoDB driver component could write sensitive configuration informa ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/110e77f056e689171115b6974dbb90206d14ce37

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/110e77f056e689171115b6974dbb90206d14ce37
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260812/023d7f94/attachment.htm>


More information about the debian-security-tracker-commits mailing list