[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Aug 13 13:34:50 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
a5f7263f by Salvatore Bonaccorso at 2026-08-13T14:34:28+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -67,13 +67,13 @@ CVE-2026-73429 (Russh is a Rust SSH client & server library. Prior to 0.62.4, a
NOTE: https://github.com/Eugeny/russh/security/advisories/GHSA-g9hv-x236-4qp3
NOTE: Fixed by: https://github.com/Eugeny/russh/commit/a7fc1eb5717264e31c3c5f7dd849b73989a08f3d (v0.62.4)
CVE-2026-73427 (Trix is a what-you-see-is-what-you-get rich text editor for everyday w ...)
- TODO: check
+ NOT-FOR-US: Trix
CVE-2026-73425 (Astro is a web framework for content-driven websites. Prior to 8.1.2, ...)
- TODO: check
+ NOT-FOR-US: Astro
CVE-2026-73423 (Astro is a web framework for content-driven websites. From 7.0.0 until ...)
- TODO: check
+ NOT-FOR-US: Astro
CVE-2026-73422 (Astro is a web framework for content-driven websites. From 2.9.0 until ...)
- TODO: check
+ NOT-FOR-US: Astro
CVE-2026-73419 (NextAuth.js provides authentication for Next.js. Prior to at auth/core 0. ...)
NOT-FOR-US: Next.js
CVE-2026-73418 (NextAuth.js provides authentication for Next.js. Prior to @auth/core 0 ...)
@@ -165,15 +165,15 @@ CVE-2026-72787 (Craft CMS versions before 5.10.8 contain a stored cross-site scr
CVE-2026-72786 (Craft CMS versions before 5.10.8 contain an authentication bypass vuln ...)
NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-72508 (A flaw was found in the multicloud-operators-subscription component of ...)
- TODO: check
+ NOT-FOR-US: Red Hat Advanced Cluster Management (RHACM)
CVE-2026-72506 (VoiceTra provided by National Institute of Information and Communicati ...)
- TODO: check
+ NOT-FOR-US: VoiceTra
CVE-2026-71846 (A flaw was found in insights-client. The component's ServiceAccount is ...)
TODO: check
CVE-2026-71473 (A flaw was found in the `search-v2-operator` component. A user with sp ...)
TODO: check
CVE-2026-71471 (A flaw was found in acm-search-v2-rhel9. An attacker with administrati ...)
- TODO: check
+ NOT-FOR-US: acm-search-v2-rhel9
CVE-2026-71469 (A flaw was found in search-v2-api. An unauthenticated attacker can exp ...)
TODO: check
CVE-2026-6821 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
@@ -584,7 +584,7 @@ CVE-2026-71408 (A allocation of resources without limits or throttling vulnerabi
CVE-2026-71407 (A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in ...)
NOT-FOR-US: Fortinet
CVE-2026-70560 (Ultimate POS (Stock Management & Point of Sale) contains a stored cros ...)
- TODO: check
+ NOT-FOR-US: Ultimate POS (Stock Management & Point of Sale)
CVE-2026-70547 (An authenticated user without repository read permission may access pa ...)
TODO: check
CVE-2026-70468 (A authentication bypass using an alternate path or channel vulnerabili ...)
@@ -1889,11 +1889,11 @@ CVE-2026-69278 (Incorrect authorization in Visual Studio Code allows an unauthor
CVE-2026-69223 (Apache Allura's webhooks are vulnerable toServer-Side Request Forgery ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-69119 (Taubyte Tau v1.1.10 contains a missing authorization vulnerability in ...)
- TODO: check
+ NOT-FOR-US: Taubyte Tau
CVE-2026-69117 (NetBox 4.5.8 contains an ORM injection vulnerability that allows authe ...)
TODO: check
CVE-2026-69115 (OpenIM Server v3.8.3 contains a missing authorization vulnerability th ...)
- TODO: check
+ NOT-FOR-US: OpenIM Server
CVE-2026-69113 (Cap v0.3.1 contains a broken access control vulnerability in the POST ...)
TODO: check
CVE-2026-69109 (A vulnerability has been identified in Siemens License Server (SLS) (A ...)
@@ -3462,7 +3462,7 @@ CVE-2026-69118 (Cachet through 2.4.1 contains a server-side template injection v
CVE-2026-69116 (FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering an ...)
NOT-FOR-US: FlyEnv
CVE-2026-69114 (Spacebar Server before commit 8d126f4 contains a cross-channel message ...)
- TODO: check
+ NOT-FOR-US: Spacebar Server
CVE-2026-69112 (Hugging Face Accelerate through 1.14.0 contains a path traversal vulne ...)
NOT-FOR-US: Hugging Face Accelerate
CVE-2026-66779 (Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver App ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a5f7263fdb892fbe6e70b8e4f7a2b3e89110f5e8
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a5f7263fdb892fbe6e70b8e4f7a2b3e89110f5e8
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260813/29001f11/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list