[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Aug 13 08:14:26 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
cb5f6ae4 by security tracker role at 2026-08-13T07:14:20+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,5 +1,5 @@
CVE-2026-7366 (IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gate ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-73519 (WolfStack before 25.9.2 contains a hard-coded cluster-authentication s ...)
TODO: check
CVE-2026-73501 (kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144 ...)
@@ -37,9 +37,9 @@ CVE-2026-73423 (Astro is a web framework for content-driven websites. From 7.0.0
CVE-2026-73422 (Astro is a web framework for content-driven websites. From 2.9.0 until ...)
TODO: check
CVE-2026-73419 (NextAuth.js provides authentication for Next.js. Prior to at auth/core 0. ...)
- TODO: check
+ NOT-FOR-US: Next.js
CVE-2026-73418 (NextAuth.js provides authentication for Next.js. Prior to @auth/core 0 ...)
- TODO: check
+ NOT-FOR-US: Next.js
CVE-2026-73415 (jupyterlab is an extensible environment for interactive and reproducib ...)
TODO: check
CVE-2026-73414 (Shescape is a simple shell escape library for JavaScript. Prior to 2.1 ...)
@@ -123,9 +123,9 @@ CVE-2026-72789 (SiYuan before v3.7.4 fails to properly validate publish access f
CVE-2026-72788 (SiYuan versions before v3.7.4 contain an information disclosure vulner ...)
TODO: check
CVE-2026-72787 (Craft CMS versions before 5.10.8 contain a stored cross-site scripting ...)
- TODO: check
+ NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-72786 (Craft CMS versions before 5.10.8 contain an authentication bypass vuln ...)
- TODO: check
+ NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-72508 (A flaw was found in the multicloud-operators-subscription component of ...)
TODO: check
CVE-2026-72506 (VoiceTra provided by National Institute of Information and Communicati ...)
@@ -139,13 +139,13 @@ CVE-2026-71471 (A flaw was found in acm-search-v2-rhel9. An attacker with admini
CVE-2026-71469 (A flaw was found in search-v2-api. An unauthenticated attacker can exp ...)
TODO: check
CVE-2026-6821 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
- TODO: check
+ NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-67579 (Deserialization of Untrusted Data vulnerability in ash-project ash all ...)
TODO: check
CVE-2026-66898 (A path traversal vulnerability in LXD allows an attacker to manipulate ...)
TODO: check
CVE-2026-65370 (ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding w ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-64826 (rConfig before 8.2.13 contains a path traversal vulnerability that all ...)
TODO: check
CVE-2026-63300 (An improper validation vulnerability in the instancePostMigration func ...)
@@ -169,15 +169,15 @@ CVE-2026-62421
CVE-2026-62420 (An authorization bypass vulnerability in LXD allows an authenticated a ...)
TODO: check
CVE-2026-59917 (Dell Display and Peripheral Manager (DDPM Windows), versions prior to ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-59916 (Dell Display and Peripheral Manager (DDPM Windows), versions prior to ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-59914 (Dell Display and Peripheral Manager (DDPM Windows), versions prior to ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-50544 (NortheBridge/luminalshine is a Sunshine-compatible game stream host fo ...)
TODO: check
CVE-2026-4879 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
- TODO: check
+ NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-49819 (UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vuln ...)
TODO: check
CVE-2026-49481 (UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS co ...)
@@ -193,13 +193,13 @@ CVE-2026-47718 (FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard)
CVE-2026-47717 (FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ...)
TODO: check
CVE-2026-46731 (Dell Display and Peripheral Manager (DDPM Windows), versions prior to ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-46688 (The Meeting Room Booking System (MRBS) is a PHP-based application for ...)
TODO: check
CVE-2026-46382 (The Meeting Room Booking System (MRBS) is a PHP-based application for ...)
TODO: check
CVE-2026-3835 (The Prevent Direct Access \u2013 Protect WordPress Files plugin for Wo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19657 (ScadaLTS 2.7.8.1reflects user-supplied input into an HTML response wit ...)
TODO: check
CVE-2026-19656 (ScadaLTS 2.7.8.1exposes a server-side method that lacks authorization ...)
@@ -207,15 +207,15 @@ CVE-2026-19656 (ScadaLTS 2.7.8.1exposes a server-side method that lacks authoriz
CVE-2026-19654 (A unauthenticated remote peer may lead rsyslogd to crash due to a flaw ...)
TODO: check
CVE-2026-19643 (An out-of-bounds read issue in the Base64 decoder in Amazon aws-sdk-cp ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-19642 (An out-of-bounds write issue in the Base64 decoder in Amazon aws-sdk-c ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-19503 (MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not valida ...)
TODO: check
CVE-2026-19502 (MongoDB SQL Schema Builder CLI records its startup configuration to st ...)
TODO: check
CVE-2026-19228 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
- TODO: check
+ NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-19182 (An incorrect authorization check in the v2 Alarm REST API in OpenNMS M ...)
TODO: check
CVE-2026-19135 (A JEXL expression sandbox bypass exists in multiple versions of OpenNM ...)
@@ -223,7 +223,7 @@ CVE-2026-19135 (A JEXL expression sandbox bypass exists in multiple versions of
CVE-2026-19130 (A flaw was found in the provider-credential-controller component of mu ...)
TODO: check
CVE-2026-19088 (The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin b ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19004 (An application using the MongoDB BI Connector ODBC Driver may experien ...)
TODO: check
CVE-2026-19003 (A data source definition containing an over-length file path setting m ...)
@@ -233,7 +233,7 @@ CVE-2026-19002 (A missing bounds check when parsing stored procedure parameter m
CVE-2026-19001 (The MongoDB BI Connector ODBC Driver may write outside the bounds of a ...)
TODO: check
CVE-2026-18945 (The WP Helper Premium WordPress plugin before 4.7.6 does not verify th ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18888 (The MongoDB BI Connector ODBC Driver converts floating point column va ...)
TODO: check
CVE-2026-18750 (vinny/views.py: (ModifyEmailNotifications)IDOR: view fetches VinceComm ...)
@@ -251,123 +251,123 @@ CVE-2026-18726 (A flaw was found in open-iscsi. This vulnerability allows a remo
CVE-2026-18679 (When kuma-dp is started against an HTTPS control plane and the operato ...)
TODO: check
CVE-2026-18433 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
- TODO: check
+ NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-18150 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18148 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18146 (The Fluent Forms \u2013 Customizable Contact Forms, Survey, Quiz, & Co ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18099 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18097 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UN ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18096 (IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Serve ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17642 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17616 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identi ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17485 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17445 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17417 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17111 (IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17083 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17082 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16695 (IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a l ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16494 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
- TODO: check
+ NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-16480 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is affected b ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16033 (A path traversal vulnerability in LXD allows an attacker to achieve ar ...)
TODO: check
CVE-2026-15424
REJECTED
CVE-2026-15217 (GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)
- TODO: check
+ NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-15216 (GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)
- TODO: check
+ NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-15141 (The web interface of the affected device relies on the HTTP referrer h ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2026-14866 (IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable t ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-14213 (The Booking for Appointments and Events Calendar WordPress plugin bef ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14182 (The Customer Email Verification for WooCommerce WordPress plugin befor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13622 (A symlink following vulnerability was found in KubeVirt's virt-handler ...)
TODO: check
CVE-2026-13610 (The KiviCare WordPress plugin before 4.5.2 does not restrict the role ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13476 (IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unau ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-13433 (IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulner ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-13367 (IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-13361 (IBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface leng ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-13328 (The Food Menu WordPress plugin before 6.0.2 does not perform any capa ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13267 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identi ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-13105 (IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable t ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-13094 (IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable t ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-12618 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identi ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-12359 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identi ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-12005 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identi ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-12004 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identi ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-11937 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identi ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-11932 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identi ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-11923 (IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identi ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-10543 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-10534 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-0301 (An information disclosure vulnerability in the URL Filtering feature o ...)
- TODO: check
+ NOT-FOR-US: Palo Alto Networks
CVE-2026-0299 (Local privilege escalation vulnerabilities in the Palo Alto Networks G ...)
- TODO: check
+ NOT-FOR-US: Palo Alto Networks
CVE-2026-0298 (An improper input validation vulnerability exists in the Windows Pre-L ...)
- TODO: check
+ NOT-FOR-US: Palo Alto Networks
CVE-2026-0297 (A buffer overflow vulnerability exists in the Palo Alto Networks Globa ...)
- TODO: check
+ NOT-FOR-US: Palo Alto Networks
CVE-2026-0296 (Improper certificate validation vulnerabilities in Palo Alto Networks ...)
- TODO: check
+ NOT-FOR-US: Palo Alto Networks
CVE-2026-0295 (A race condition in the Palo Alto Networks GlobalProtect\u2122 client ...)
- TODO: check
+ NOT-FOR-US: Palo Alto Networks
CVE-2026-0294 (A privilege escalation (PE) vulnerability in the Palo Alto Networks Pr ...)
- TODO: check
+ NOT-FOR-US: Palo Alto Networks
CVE-2026-0293 (A vulnerability in Palo Alto Networks Prisma\xae Access Agent on Windo ...)
- TODO: check
+ NOT-FOR-US: Palo Alto Networks
CVE-2026-0292 (An authentication bypass vulnerability in the network driver of Palo A ...)
- TODO: check
+ NOT-FOR-US: Palo Alto Networks
CVE-2026-0291 (An improper link resolution before file access vulnerability exists in ...)
- TODO: check
+ NOT-FOR-US: Palo Alto Networks
CVE-2026-0290 (An information disclosure vulnerability in the Account Protection feat ...)
- TODO: check
+ NOT-FOR-US: Palo Alto Networks
CVE-2026-0289 (A security bypass vulnerability in the Account Protection feature of ...)
- TODO: check
+ NOT-FOR-US: Palo Alto Networks
CVE-2025-9486 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
- TODO: check
+ NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2024-27253 (IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an auth ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-53802
- rsync <unfixed>
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb5f6ae411c2c5833db0b88916c82abfe6e111bb
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb5f6ae411c2c5833db0b88916c82abfe6e111bb
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260813/31c53559/attachment.htm>
More information about the debian-security-tracker-commits
mailing list