[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 13 08:14:26 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
cb5f6ae4 by security tracker role at 2026-08-13T07:14:20+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,5 +1,5 @@
 CVE-2026-7366 (IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gate ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-73519 (WolfStack before 25.9.2 contains a hard-coded cluster-authentication s ...)
 	TODO: check
 CVE-2026-73501 (kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144 ...)
@@ -37,9 +37,9 @@ CVE-2026-73423 (Astro is a web framework for content-driven websites. From 7.0.0
 CVE-2026-73422 (Astro is a web framework for content-driven websites. From 2.9.0 until ...)
 	TODO: check
 CVE-2026-73419 (NextAuth.js provides authentication for Next.js. Prior to at auth/core 0. ...)
-	TODO: check
+	NOT-FOR-US: Next.js
 CVE-2026-73418 (NextAuth.js provides authentication for Next.js. Prior to @auth/core 0 ...)
-	TODO: check
+	NOT-FOR-US: Next.js
 CVE-2026-73415 (jupyterlab is an extensible environment for interactive and reproducib ...)
 	TODO: check
 CVE-2026-73414 (Shescape is a simple shell escape library for JavaScript. Prior to 2.1 ...)
@@ -123,9 +123,9 @@ CVE-2026-72789 (SiYuan before v3.7.4 fails to properly validate publish access f
 CVE-2026-72788 (SiYuan versions before v3.7.4 contain an information disclosure vulner ...)
 	TODO: check
 CVE-2026-72787 (Craft CMS versions before 5.10.8 contain a stored cross-site scripting ...)
-	TODO: check
+	NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-72786 (Craft CMS versions before 5.10.8 contain an authentication bypass vuln ...)
-	TODO: check
+	NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-72508 (A flaw was found in the multicloud-operators-subscription component of ...)
 	TODO: check
 CVE-2026-72506 (VoiceTra provided by National Institute of Information and Communicati ...)
@@ -139,13 +139,13 @@ CVE-2026-71471 (A flaw was found in acm-search-v2-rhel9. An attacker with admini
 CVE-2026-71469 (A flaw was found in search-v2-api. An unauthenticated attacker can exp ...)
 	TODO: check
 CVE-2026-6821 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-67579 (Deserialization of Untrusted Data vulnerability in ash-project ash all ...)
 	TODO: check
 CVE-2026-66898 (A path traversal vulnerability in LXD allows an attacker to manipulate ...)
 	TODO: check
 CVE-2026-65370 (ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding w ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-64826 (rConfig before 8.2.13 contains a path traversal vulnerability that all ...)
 	TODO: check
 CVE-2026-63300 (An improper validation vulnerability in the instancePostMigration func ...)
@@ -169,15 +169,15 @@ CVE-2026-62421
 CVE-2026-62420 (An authorization bypass vulnerability in LXD allows an authenticated a ...)
 	TODO: check
 CVE-2026-59917 (Dell Display and Peripheral Manager (DDPM Windows), versions prior to  ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-59916 (Dell Display and Peripheral Manager (DDPM Windows), versions prior to  ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-59914 (Dell Display and Peripheral Manager (DDPM Windows), versions prior to  ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-50544 (NortheBridge/luminalshine is a Sunshine-compatible game stream host fo ...)
 	TODO: check
 CVE-2026-4879 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-49819 (UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vuln ...)
 	TODO: check
 CVE-2026-49481 (UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS co ...)
@@ -193,13 +193,13 @@ CVE-2026-47718 (FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard)
 CVE-2026-47717 (FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ...)
 	TODO: check
 CVE-2026-46731 (Dell Display and Peripheral Manager (DDPM Windows), versions prior to  ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-46688 (The Meeting Room Booking System (MRBS) is a PHP-based application for  ...)
 	TODO: check
 CVE-2026-46382 (The Meeting Room Booking System (MRBS) is a PHP-based application for  ...)
 	TODO: check
 CVE-2026-3835 (The Prevent Direct Access \u2013 Protect WordPress Files plugin for Wo ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-19657 (ScadaLTS 2.7.8.1reflects user-supplied input into an HTML response wit ...)
 	TODO: check
 CVE-2026-19656 (ScadaLTS 2.7.8.1exposes a server-side method that lacks authorization  ...)
@@ -207,15 +207,15 @@ CVE-2026-19656 (ScadaLTS 2.7.8.1exposes a server-side method that lacks authoriz
 CVE-2026-19654 (A unauthenticated remote peer may lead rsyslogd to crash due to a flaw ...)
 	TODO: check
 CVE-2026-19643 (An out-of-bounds read issue in the Base64 decoder in Amazon aws-sdk-cp ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-19642 (An out-of-bounds write issue in the Base64 decoder in Amazon aws-sdk-c ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-19503 (MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not valida ...)
 	TODO: check
 CVE-2026-19502 (MongoDB SQL Schema Builder CLI records its startup configuration to st ...)
 	TODO: check
 CVE-2026-19228 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-19182 (An incorrect authorization check in the v2 Alarm REST API in OpenNMS M ...)
 	TODO: check
 CVE-2026-19135 (A JEXL expression sandbox bypass exists in multiple versions of OpenNM ...)
@@ -223,7 +223,7 @@ CVE-2026-19135 (A JEXL expression sandbox bypass exists in multiple versions of
 CVE-2026-19130 (A flaw was found in the provider-credential-controller component of mu ...)
 	TODO: check
 CVE-2026-19088 (The ShopEngine Elementor WooCommerce Builder Addon  WordPress plugin b ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-19004 (An application using the MongoDB BI Connector ODBC Driver may experien ...)
 	TODO: check
 CVE-2026-19003 (A data source definition containing an over-length file path setting m ...)
@@ -233,7 +233,7 @@ CVE-2026-19002 (A missing bounds check when parsing stored procedure parameter m
 CVE-2026-19001 (The MongoDB BI Connector ODBC Driver may write outside the bounds of a ...)
 	TODO: check
 CVE-2026-18945 (The WP Helper Premium WordPress plugin before 4.7.6 does not verify th ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18888 (The MongoDB BI Connector ODBC Driver converts floating point column va ...)
 	TODO: check
 CVE-2026-18750 (vinny/views.py: (ModifyEmailNotifications)IDOR: view fetches VinceComm ...)
@@ -251,123 +251,123 @@ CVE-2026-18726 (A flaw was found in open-iscsi. This vulnerability allows a remo
 CVE-2026-18679 (When kuma-dp is started against an HTTPS control plane and the operato ...)
 	TODO: check
 CVE-2026-18433 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-18150 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18148 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18146 (The Fluent Forms \u2013 Customizable Contact Forms, Survey, Quiz, & Co ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18099 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18097 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UN ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18096 (IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Serve ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17642 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17616 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identi ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17485 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17445 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17417 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17111 (IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote a ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17083 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17082 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16695 (IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a l ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16494 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-16480 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is affected b ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16033 (A path traversal vulnerability in LXD allows an attacker to achieve ar ...)
 	TODO: check
 CVE-2026-15424
 	REJECTED
 CVE-2026-15217 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-15216 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-15141 (The web interface of the affected device relies on the HTTP referrer h ...)
-	TODO: check
+	NOT-FOR-US: TPLink
 CVE-2026-14866 (IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable t ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-14213 (The Booking for Appointments and Events Calendar  WordPress plugin bef ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14182 (The Customer Email Verification for WooCommerce WordPress plugin befor ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13622 (A symlink following vulnerability was found in KubeVirt's virt-handler ...)
 	TODO: check
 CVE-2026-13610 (The KiviCare  WordPress plugin before 4.5.2 does not restrict the role ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13476 (IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unau ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-13433 (IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulner ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-13367 (IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-13361 (IBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface leng ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-13328 (The Food Menu  WordPress plugin before 6.0.2 does not perform any capa ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13267 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identi ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-13105 (IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable t ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-13094 (IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable t ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-12618 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identi ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-12359 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identi ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-12005 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identi ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-12004 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identi ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-11937 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identi ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-11932 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identi ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-11923 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identi ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-10543 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-10534 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-0301 (An information disclosure vulnerability in the URL Filtering feature o ...)
-	TODO: check
+	NOT-FOR-US: Palo Alto Networks
 CVE-2026-0299 (Local privilege escalation vulnerabilities in the Palo Alto Networks G ...)
-	TODO: check
+	NOT-FOR-US: Palo Alto Networks
 CVE-2026-0298 (An improper input validation vulnerability exists in the Windows Pre-L ...)
-	TODO: check
+	NOT-FOR-US: Palo Alto Networks
 CVE-2026-0297 (A buffer overflow vulnerability exists in the Palo Alto Networks Globa ...)
-	TODO: check
+	NOT-FOR-US: Palo Alto Networks
 CVE-2026-0296 (Improper certificate validation vulnerabilities in Palo Alto Networks  ...)
-	TODO: check
+	NOT-FOR-US: Palo Alto Networks
 CVE-2026-0295 (A race condition in the Palo Alto Networks GlobalProtect\u2122 client  ...)
-	TODO: check
+	NOT-FOR-US: Palo Alto Networks
 CVE-2026-0294 (A privilege escalation (PE) vulnerability in the Palo Alto Networks Pr ...)
-	TODO: check
+	NOT-FOR-US: Palo Alto Networks
 CVE-2026-0293 (A vulnerability in Palo Alto Networks Prisma\xae Access Agent on Windo ...)
-	TODO: check
+	NOT-FOR-US: Palo Alto Networks
 CVE-2026-0292 (An authentication bypass vulnerability in the network driver of Palo A ...)
-	TODO: check
+	NOT-FOR-US: Palo Alto Networks
 CVE-2026-0291 (An improper link resolution before file access vulnerability exists in ...)
-	TODO: check
+	NOT-FOR-US: Palo Alto Networks
 CVE-2026-0290 (An information disclosure vulnerability in the Account Protection feat ...)
-	TODO: check
+	NOT-FOR-US: Palo Alto Networks
 CVE-2026-0289 (A  security bypass vulnerability in the Account Protection feature of  ...)
-	TODO: check
+	NOT-FOR-US: Palo Alto Networks
 CVE-2025-9486 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2024-27253 (IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an auth ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-53802
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb5f6ae411c2c5833db0b88916c82abfe6e111bb

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb5f6ae411c2c5833db0b88916c82abfe6e111bb
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260813/31c53559/attachment.htm>


More information about the debian-security-tracker-commits mailing list