[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Wed Aug 12 19:21:17 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
110e77f0 by Moritz Muehlenhoff at 2026-08-12T20:20:51+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,19 @@
+CVE-2026-59242
+ - airflow <itp> (bug #819700)
+CVE-2026-59244
+ - airflow <itp> (bug #819700)
+CVE-2026-68968
+ - airflow <itp> (bug #819700)
+CVE-2026-65017
+ - airflow <itp> (bug #819700)
+CVE-2026-68076
+ - airflow <itp> (bug #819700)
+CVE-2026-68971
+ - airflow <itp> (bug #819700)
+CVE-2026-68970
+ - airflow <itp> (bug #819700)
+CVE-2026-68969
+ - airflow <itp> (bug #819700)
CVE-2026-XXXX [OSSN-0106: API ramdisk endpoints require network-level access controls]
- ironic 1:35.0.1-10
NOTE: https://wiki.openstack.org/wiki/OSSN/OSSN-0106
@@ -132,7 +148,7 @@ CVE-2026-73233 (FreeCAD is a free and open-source multiplatform 3D parametric mo
CVE-2026-73232 (ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a ...)
TODO: check
CVE-2026-73231 (Faker generates massive amounts of fake data in the browser and Node.j ...)
- TODO: check
+ NOT-FOR-US: Faker
CVE-2026-73230 (Ente provides end-to-end encrypted cloud services and security tools. ...)
NOT-FOR-US: Ente
CVE-2026-73229 (Django REST framework is a powerful and flexible toolkit for building ...)
@@ -231,7 +247,7 @@ CVE-2026-48763 (TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expo
CVE-2026-48762 (TypeBot is a chatbot builder tool. Prior to version 3.16.0, the OpenAI ...)
NOT-FOR-US: TypeBot
CVE-2026-45618 (LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior t ...)
- TODO: check
+ NOT-FOR-US: LiquidJS
CVE-2026-29036 (cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved na ...)
TODO: check
CVE-2026-29035 (CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow v ...)
@@ -243,7 +259,7 @@ CVE-2026-19588 (Integer Overflow to Buffer Overflow vulnerability in Samsung Ope
CVE-2026-19587 (Uncontrolled Resource Consumption vulnerability in Samsung Open Source ...)
TODO: check
CVE-2026-19579 (Snipe-IT before 8.6.0 contains an authorization bypass (insecure direc ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-19550 (A flaw was found in FreeIPA. The trust-fetch-domains command is gated ...)
TODO: check
CVE-2026-19217 (The Royal Addons for Elementor WordPress plugin before 1.7.1065 does ...)
@@ -263,7 +279,7 @@ CVE-2026-18961 (The Social Login, Passkeys, Magic Link & Email OTP \u2013 Passwo
CVE-2026-18943 (The WPC Admin Columns WordPress plugin before 2.3.4 does not have auth ...)
NOT-FOR-US: WordPress plugin
CVE-2026-18844 (The firmware of thePulsetto Vagus Nerve Stimulatoraccepts several undi ...)
- TODO: check
+ NOT-FOR-US: Pulsetto Vagus Nerve Stimulator
CVE-2026-18789 (The Ezoic WordPress plugin before 2.23.1 does not properly restrict ac ...)
NOT-FOR-US: WordPress plugin
CVE-2026-18710 (A MongoDB driver component could write sensitive configuration informa ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/110e77f056e689171115b6974dbb90206d14ce37
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/110e77f056e689171115b6974dbb90206d14ce37
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260812/023d7f94/attachment.htm>
More information about the debian-security-tracker-commits
mailing list