[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 13 20:14:04 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
af962a33 by security tracker role at 2026-08-13T19:13:58+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,220 +1,862 @@
-CVE-2022-4993
+CVE-2026-73671 (Saurus CMS Community Edition contains an unauthenticated open redirect ...)
+	TODO: check
+CVE-2026-73670 (A CMS contains a SQL injection vulnerability in admin/db_data.php at l ...)
+	TODO: check
+CVE-2026-73653 (Vitest is a testing framework powered by Vite. Prior to versions 3.2.7 ...)
+	TODO: check
+CVE-2026-73652 (vantage6 is an open-source infrastructure for privacy preserving analy ...)
+	TODO: check
+CVE-2026-73651 (TypeORM is a TypeScript and JavaScript ORM for Node.js that supports P ...)
+	TODO: check
+CVE-2026-73650 (SVGO, short for SVG Optimizer, is a Node.js library and command-line a ...)
+	TODO: check
+CVE-2026-73649 (Velocity.js is a JavaScript implementation of the Apache Velocity temp ...)
+	TODO: check
+CVE-2026-73648 (rails-html-sanitizer is responsible for sanitizing HTML fragments in R ...)
+	TODO: check
+CVE-2026-73647 (Quasar Framework is a framework for building high-performance Vue.js u ...)
+	TODO: check
+CVE-2026-73645 (OpenZeppelin Confidential Contracts is an experimental library for dev ...)
+	TODO: check
+CVE-2026-73644 (OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the S ...)
+	TODO: check
+CVE-2026-73643 (js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 until 5.2.2 ...)
+	TODO: check
+CVE-2026-73629 (Serendipity before 2.6.0 contains a server-side request forgery vulner ...)
+	TODO: check
+CVE-2026-73628 (Serendipity versions >= 2.3.5 and <= 2.6.0 contain a reflected cross-s ...)
+	TODO: check
+CVE-2026-73627 (JupyterLab (pip package 'jupyterlab') versions >=4.1.0,<=4.5.9 and >=4 ...)
+	TODO: check
+CVE-2026-73626 (JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/b ...)
+	TODO: check
+CVE-2026-73625 (GitPython versions before 3.1.54 contain a remote code execution vulne ...)
+	TODO: check
+CVE-2026-73624 (GitPython versions before 3.1.54 contain an arbitrary file overwrite v ...)
+	TODO: check
+CVE-2026-73623 (GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_ ...)
+	TODO: check
+CVE-2026-73622 (GitPython before 3.1.55 fails to disable environment variable expansio ...)
+	TODO: check
+CVE-2026-73621 (GitPython before 3.1.56 contains an argument injection vulnerability i ...)
+	TODO: check
+CVE-2026-73620 (GitPython before 3.1.57 fails to guard git option forwarding in IndexF ...)
+	TODO: check
+CVE-2026-73619 (GitPython before 3.1.57 contains an incomplete denylist in the unsafe_ ...)
+	TODO: check
+CVE-2026-73618 (Budibase Server before 3.40.0 contains a NoSQL injection vulnerability ...)
+	TODO: check
+CVE-2026-73617 (Budibase before 3.40.0 contains a NoSQL injection vulnerability in the ...)
+	TODO: check
+CVE-2026-73616 (OpenRemote notification deletion endpoints fail to enforce realm bound ...)
+	TODO: check
+CVE-2026-73615 (Network-AI versions before 5.15.1 contain a security matcher bypass vu ...)
+	TODO: check
+CVE-2026-73614 (Network-AI ClaudeHookBridge before 5.15.1 truncates the target string  ...)
+	TODO: check
+CVE-2026-73613 (filebrowser versions before 2.63.19 contain an out-of-scope file delet ...)
+	TODO: check
+CVE-2026-73612 (File Browser before v2.63.22 fails to validate access rules for descen ...)
+	TODO: check
+CVE-2026-73611 (File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT ...)
+	TODO: check
+CVE-2026-73610 (SiYuan before v3.7.4 contains an information disclosure vulnerability  ...)
+	TODO: check
+CVE-2026-73609 (SiYuan versions before v3.7.4 contain an information disclosure vulner ...)
+	TODO: check
+CVE-2026-73608 (SiYuan's development branch (endpoint introduced by commit 9b8e8956f,  ...)
+	TODO: check
+CVE-2026-73607 (SiYuan versions before v3.7.4 contain an information disclosure vulner ...)
+	TODO: check
+CVE-2026-73606 (SiYuan versions before v3.7.4 contain an information disclosure vulner ...)
+	TODO: check
+CVE-2026-73605 (SiYuan versions before v3.7.4 contain a path traversal vulnerability i ...)
+	TODO: check
+CVE-2026-73604 (Flowise before 3.1.3 contains an incomplete credential redaction vulne ...)
+	TODO: check
+CVE-2026-73603 (Flowise before 3.1.4 fails to validate chatflow visibility in the unau ...)
+	TODO: check
+CVE-2026-73602 (Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm ...)
+	TODO: check
+CVE-2026-73601 (Flowise versions before 3.1.3 contain a remote code execution vulnerab ...)
+	TODO: check
+CVE-2026-73585 (A flaw was found in sblim-cmpi-base. Insecure temporary file creation  ...)
+	TODO: check
+CVE-2026-73584 (A flaw was found in sblim-sfcb. A local, low-privileged attacker can e ...)
+	TODO: check
+CVE-2026-73583 (A flaw was found in sblim-sfcb. A local attacker with access to the sy ...)
+	TODO: check
+CVE-2026-73576 (In Zimbra Collaboration (ZCS) before 10.1.17,weak cryptographic key ge ...)
+	TODO: check
+CVE-2026-73575 (In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request For ...)
+	TODO: check
+CVE-2026-73574 (In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) v ...)
+	TODO: check
+CVE-2026-73573 (In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnera ...)
+	TODO: check
+CVE-2026-73572 (In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scri ...)
+	TODO: check
+CVE-2026-73571 (An authorization bypass vulnerability exists in Zimbra Collaboration ( ...)
+	TODO: check
+CVE-2026-73570 (A remote code execution vulnerability exists in Zimbra Collaboration ( ...)
+	TODO: check
+CVE-2026-73569 (fast-xml-parser allows users to process XML from JS object without C/C ...)
+	TODO: check
+CVE-2026-73568 (py-libp2p is the Python implementation of the libp2p networking stack. ...)
+	TODO: check
+CVE-2026-73567 (sm-crypto provides JavaScript implementations of the Chinese cryptogra ...)
+	TODO: check
+CVE-2026-73566 (node-tar is a tar archive manipulation library for Node.js. Prior to 7 ...)
+	TODO: check
+CVE-2026-73565 (@hono/node-server allows running the Hono application on Node.js. From ...)
+	TODO: check
+CVE-2026-73564 (frp is a fast reverse proxy. From 0.53.0 until 0.70.1, frp's optional  ...)
+	TODO: check
+CVE-2026-73563 (Backstage is an open framework for building developer portals. Prior t ...)
+	TODO: check
+CVE-2026-73562 (Mongoose is a MongoDB object modeling tool designed to work in an asyn ...)
+	TODO: check
+CVE-2026-73561 (Hub is a Node.js WebSocket server and client with added features. Prio ...)
+	TODO: check
+CVE-2026-73559 (vLLM is an inference and serving engine for large language models. Fro ...)
+	TODO: check
+CVE-2026-73558 (vLLM is an inference and serving engine for large language models. Pri ...)
+	TODO: check
+CVE-2026-73557 (vLLM is an inference and serving engine for large language models. Fro ...)
+	TODO: check
+CVE-2026-73556 (vLLM is an inference and serving engine for large language models. Pri ...)
+	TODO: check
+CVE-2026-73555 (vLLM is an inference and serving engine for large language models. Pri ...)
+	TODO: check
+CVE-2026-73533 (Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerabil ...)
+	TODO: check
+CVE-2026-73532 (Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerabili ...)
+	TODO: check
+CVE-2026-73515 (PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability ...)
+	TODO: check
+CVE-2026-73514 (The address_standardizer extension for PostGIS through 3.7.0, fixed in ...)
+	TODO: check
+CVE-2026-73509 (OpenList a file list program that supports multiple storage. Prior to  ...)
+	TODO: check
+CVE-2026-73508 (Netty is an asynchronous, event-driven network application framework.  ...)
+	TODO: check
+CVE-2026-73507 (Netty is an asynchronous, event-driven network application framework.  ...)
+	TODO: check
+CVE-2026-73506 (Oh My Posh is the most customisable and low-latency cross platform/she ...)
+	TODO: check
+CVE-2026-73505 (Oh My Posh is the most customisable and low-latency cross platform/she ...)
+	TODO: check
+CVE-2026-73488 (Flowise versions before 3.1.3 contain an insecure direct object refere ...)
+	TODO: check
+CVE-2026-73487 (Flowise before 3.1.3 contains a regex-based Python code validator bypa ...)
+	TODO: check
+CVE-2026-73486 (Flowise before 3.1.3 contains a code injection vulnerability in the CS ...)
+	TODO: check
+CVE-2026-73485 (Flowise before 3.1.3 contains a code injection vulnerability in the Ai ...)
+	TODO: check
+CVE-2026-73484 (Flowise before 3.1.3 contains a sandbox escape vulnerability in python ...)
+	TODO: check
+CVE-2026-73483 (Flowise (packages flowise and flowise-components) in versions <= 3.1.2 ...)
+	TODO: check
+CVE-2026-73482 (phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF)  ...)
+	TODO: check
+CVE-2026-73481 (phpList before 3.7.0-RC5 fail to enforce CSRF token validation on the  ...)
+	TODO: check
+CVE-2026-73403 (Unauthenticated Broken Access Control in User Registration <= 5.2.6 ve ...)
+	TODO: check
+CVE-2026-73401 (Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 ve ...)
+	TODO: check
+CVE-2026-73357 (Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions.)
+	TODO: check
+CVE-2026-73353 (Unauthenticated Broken Access Control in Revolut Gateway for WooCommer ...)
+	TODO: check
+CVE-2026-73349 (Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.)
+	TODO: check
+CVE-2026-73346 (Administrator SQL Injection in MailChimp For WooCommerce < 6.2 version ...)
+	TODO: check
+CVE-2026-73344 (Author Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions ...)
+	TODO: check
+CVE-2026-73340 (Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5 ...)
+	TODO: check
+CVE-2026-73266 (A flaw was found in the clusterclaims-controller component of Multiclu ...)
+	TODO: check
+CVE-2026-73188 (Unauthenticated Sensitive Data Exposure in KiviCare <= 4.5.1 versions.)
+	TODO: check
+CVE-2026-73038 (NodeBB before 4.15.0 contains a stored cross-site scripting vulnerabil ...)
+	TODO: check
+CVE-2026-73037 (Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site s ...)
+	TODO: check
+CVE-2026-72777 (Next AI Draw.io through 0.4.16 contains a server-side request forgery  ...)
+	TODO: check
+CVE-2026-72741 (Rainbond through 6.9.7 contains a broken access control vulnerability  ...)
+	TODO: check
+CVE-2026-6387 (A potential authentication bypass vulnerability was reported in Lenovo ...)
+	TODO: check
+CVE-2026-67991 (crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 cont ...)
+	TODO: check
+CVE-2026-67990 (basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f di ...)
+	TODO: check
+CVE-2026-67986 (amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c271 ...)
+	TODO: check
+CVE-2026-67614 (CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability ...)
+	TODO: check
+CVE-2026-67613 (CyberPanel before 3.0.0 contains a path traversal vulnerability that a ...)
+	TODO: check
+CVE-2026-66704 (Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Compa ...)
+	TODO: check
+CVE-2026-66700 (Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for C ...)
+	TODO: check
+CVE-2026-66698 (Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versi ...)
+	TODO: check
+CVE-2026-66697 (Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : M\x ...)
+	TODO: check
+CVE-2026-66693 (Subscriber Broken Access Control in Motors <= 1.4.113 versions.)
+	TODO: check
+CVE-2026-66691 (Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.)
+	TODO: check
+CVE-2026-66689 (Unauthenticated Broken Access Control in Anti Spam and list cleaner &# ...)
+	TODO: check
+CVE-2026-66687 (Customer Cross Site Scripting (XSS) in WpBookingly <= 1.3.2 versions.)
+	TODO: check
+CVE-2026-66661 (Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions.)
+	TODO: check
+CVE-2026-66660 (Unauthenticated Broken Access Control in Contact Form 7 \u2013 PayPal  ...)
+	TODO: check
+CVE-2026-66658 (Subscriber SQL Injection in Reviewer <= 3.14.2 versions.)
+	TODO: check
+CVE-2026-66657 (Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versio ...)
+	TODO: check
+CVE-2026-66656 (Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions.)
+	TODO: check
+CVE-2026-66655 (Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping Fo ...)
+	TODO: check
+CVE-2026-66654 (Subscriber Server Side Request Forgery (SSRF) in Vehica Core <= 1.0.10 ...)
+	TODO: check
+CVE-2026-66653 (Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions.)
+	TODO: check
+CVE-2026-66478 (Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.)
+	TODO: check
+CVE-2026-66472 (Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions.)
+	TODO: check
+CVE-2026-66471 (Subscriber Cross Site Scripting (XSS) in Accordion <= 3.0.6 versions.)
+	TODO: check
+CVE-2026-66469 (Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3  ...)
+	TODO: check
+CVE-2026-66468 (Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers f ...)
+	TODO: check
+CVE-2026-66467 (Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 vers ...)
+	TODO: check
+CVE-2026-66466 (Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Boos ...)
+	TODO: check
+CVE-2026-66465 (Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.)
+	TODO: check
+CVE-2026-66464 (Unauthenticated Broken Access Control in Internal Link Optimiser <= 5. ...)
+	TODO: check
+CVE-2026-66463 (Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions.)
+	TODO: check
+CVE-2026-66462 (Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= ...)
+	TODO: check
+CVE-2026-66461 (Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCo ...)
+	TODO: check
+CVE-2026-66460 (Subscriber Cross Site Scripting (XSS) in AfterShip Tracking <= 1.18.1  ...)
+	TODO: check
+CVE-2026-66459 (Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions.)
+	TODO: check
+CVE-2026-66458 (Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.)
+	TODO: check
+CVE-2026-66456 (Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestW ...)
+	TODO: check
+CVE-2026-66455 (Subscriber Broken Access Control in ReactPress <= 3.4.0 versions.)
+	TODO: check
+CVE-2026-66454 (Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versi ...)
+	TODO: check
+CVE-2026-66453 (Unauthenticated Broken Authentication in Salon booking system <= 10.30 ...)
+	TODO: check
+CVE-2026-66450 (Unauthenticated Local File Inclusion in  Geo Mashup <= 1.13.18 version ...)
+	TODO: check
+CVE-2026-66449 (Unauthenticated Cross Site Scripting (XSS) in  Geo Mashup <= 1.13.18 v ...)
+	TODO: check
+CVE-2026-66446 (Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1 ...)
+	TODO: check
+CVE-2026-66444 (Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4. ...)
+	TODO: check
+CVE-2026-66443 (Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versi ...)
+	TODO: check
+CVE-2026-66441 (Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versio ...)
+	TODO: check
+CVE-2026-66436 (Unauthenticated SQL Injection in Active Products Tables for WooCommerc ...)
+	TODO: check
+CVE-2026-66432 (Subscriber Sensitive Data Exposure in WPJAM Basic <= 7.0.2.1 versions.)
+	TODO: check
+CVE-2026-66431 (Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gat ...)
+	TODO: check
+CVE-2026-66430 (Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro < ...)
+	TODO: check
+CVE-2026-66429 (Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Tim ...)
+	TODO: check
+CVE-2026-66426 (Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 version ...)
+	TODO: check
+CVE-2026-66424 (Unauthenticated Privilege Escalation in SMS Alert Order Notifications  ...)
+	TODO: check
+CVE-2026-66256 (** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vuln ...)
+	TODO: check
+CVE-2026-65936 (A malformed Bluetooth connection request message can cause the RS9116W ...)
+	TODO: check
+CVE-2026-65935 (Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS911 ...)
+	TODO: check
+CVE-2026-65934 (An unencrypted 'pause encryption request' message causes a denial of s ...)
+	TODO: check
+CVE-2026-65933 (A malformed Bluetooth connection request message can cause the BT122 t ...)
+	TODO: check
+CVE-2026-65932 (The BT122 module stops advertising after receiving a plaintext 'pause  ...)
+	TODO: check
+CVE-2026-65582 (Subscriber Arbitrary File Download in AI Hub <= 1.3.10 versions.)
+	TODO: check
+CVE-2026-65580 (Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 versions ...)
+	TODO: check
+CVE-2026-63426 (During an internal security assessment, a potential vulnerability was  ...)
+	TODO: check
+CVE-2026-63425 (During an internal security assessment, a potential improper permissio ...)
+	TODO: check
+CVE-2026-63424 (During an internal security assessment, an improperly protected key wa ...)
+	TODO: check
+CVE-2026-63423 (During an internal security assessment, a potential vulnerability was  ...)
+	TODO: check
+CVE-2026-61984 (Unauthenticated Broken Access Control in WPMobile.App <= 11.77 version ...)
+	TODO: check
+CVE-2026-61980 (Unauthenticated Arbitrary File Download in OMGF Pro <= 5.2.7 versions.)
+	TODO: check
+CVE-2026-61979 (Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4. ...)
+	TODO: check
+CVE-2026-61978 (Unauthenticated Broken Access Control in Secure Card Gateway for ePay  ...)
+	TODO: check
+CVE-2026-61974 (Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.3.4 v ...)
+	TODO: check
+CVE-2026-61969 (Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.)
+	TODO: check
+CVE-2026-61967 (Unauthenticated Privilege Escalation in miniorange otp verification <= ...)
+	TODO: check
+CVE-2026-61966 (Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.)
+	TODO: check
+CVE-2026-61965 (Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versio ...)
+	TODO: check
+CVE-2026-61962 (Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 v ...)
+	TODO: check
+CVE-2026-61960 (Unauthenticated Cross Site Scripting (XSS) in WP Full Stripe Free <= 8 ...)
+	TODO: check
+CVE-2026-59765 (SSRF via Migration Asset Downloads Bypasses hostmatcher \u2014 Reads I ...)
+	TODO: check
+CVE-2026-59763 (Unbounded Arch package file metadata can cause resource amplification  ...)
+	TODO: check
+CVE-2026-59507 (CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive  ...)
+	TODO: check
+CVE-2026-59506 (CWE-306: Missing Authentication for Critical Function)
+	TODO: check
+CVE-2026-59505 (CWE-284: Improper Access Control)
+	TODO: check
+CVE-2026-59504 (CWE-602: Client-Side Enforcement of Server-Side Security)
+	TODO: check
+CVE-2026-59503 (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CW ...)
+	TODO: check
+CVE-2026-59502 (CWE-203: Observable Discrepancy)
+	TODO: check
+CVE-2026-59501 (CWE-284: Improper Access Control)
+	TODO: check
+CVE-2026-59500 (CWE-287: Improper Authentication)
+	TODO: check
+CVE-2026-59499 (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor)
+	TODO: check
+CVE-2026-59109 (SQL injection in the Zalktis accounting application via trading-partne ...)
+	TODO: check
+CVE-2026-58511 (Webhook Authorization Header Returned in Plaintext via API)
+	TODO: check
+CVE-2026-58510 (GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo p ...)
+	TODO: check
+CVE-2026-58508 (Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + mi ...)
+	TODO: check
+CVE-2026-58507 (Private Repository Existence Disclosure via go-get Meta Endpoint)
+	TODO: check
+CVE-2026-58445 (Cross-repository label-ID enumeration oracle via unscoped DeleteIssueL ...)
+	TODO: check
+CVE-2026-58444 (Personal access token scope enforcement bypass on the repository home  ...)
+	TODO: check
+CVE-2026-58443 (Public-only repository tokens can update private PR head branches)
+	TODO: check
+CVE-2026-58442 (Repository migration SSRF via multi-answer DNS allow-list bypass)
+	TODO: check
+CVE-2026-58441 (SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL)
+	TODO: check
+CVE-2026-58440 (Webhooks created by a collaborator keep firing after their repo access ...)
+	TODO: check
+CVE-2026-58439 (Branch Protection Bypass via PR Retargeting Preserves Stale `official` ...)
+	TODO: check
+CVE-2026-58438 (Cross-repository IDOR in issue-dependency removal lets an attacker tam ...)
+	TODO: check
+CVE-2026-58437 (Repository Visibility Manipulation via Git Push Options)
+	TODO: check
+CVE-2026-58436 (ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauth ...)
+	TODO: check
+CVE-2026-58435 (Gitea LFS Deploy-Key Privilege Escalation)
+	TODO: check
+CVE-2026-58434 (Private Repository Metadata Remains Accessible After Access Revocation)
+	TODO: check
+CVE-2026-58433 (Team-repository linking endpoint bypasses the RepoAdminChangeTeamAcces ...)
+	TODO: check
+CVE-2026-58432 (Missing Authorization and Authorization Bypass Through User-Controlled ...)
+	TODO: check
+CVE-2026-58431 (Public-only API token restriction is not enforced on team API routes)
+	TODO: check
+CVE-2026-58429 (Public-Only Personal access tokens scope bypass in Organization and Pe ...)
+	TODO: check
+CVE-2026-58428 (Release attachment extension allowlist bypass via web release edit for ...)
+	TODO: check
+CVE-2026-58427 (Private org member list leaked via /members API endpoint \u2014 incomp ...)
+	TODO: check
+CVE-2026-58425 (OAuth token introspection returns metadata of tokens issued to other c ...)
+	TODO: check
+CVE-2026-58420 (Local File Inclusion via file:// URI in Migration Restore)
+	TODO: check
+CVE-2026-58417 (REST API exposes organization membership of private organizations to p ...)
+	TODO: check
+CVE-2026-58416 (Fork-PR Actions task can read a third private repository via the colla ...)
+	TODO: check
+CVE-2026-58314 (Two SSRF findings in Gitea 1.26.2)
+	TODO: check
+CVE-2026-57897 (Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs)
+	TODO: check
+CVE-2026-57894 (Repository Migration Follows Git HTTP Redirects After URL Allow/Block  ...)
+	TODO: check
+CVE-2026-57886 (Cross-repository issue/comment attachment re-linking can expose privat ...)
+	TODO: check
+CVE-2026-56755 (Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concaten ...)
+	TODO: check
+CVE-2026-56750 (Gitea Remember-Me Token Theft Not Invalidating Attacker Session)
+	TODO: check
+CVE-2026-56657 (Gitea SSH Key Parser Denial of Service)
+	TODO: check
+CVE-2026-56654 (Privilege Escalation via Access Token Scope Escalation in API)
+	TODO: check
+CVE-2026-56443 (Token public-only scope bypassed on Limited-visibility owners (Reposit ...)
+	TODO: check
+CVE-2026-55987 (OAuth2 sign-in reactivates an administrator-deactivated account on aut ...)
+	TODO: check
+CVE-2026-55986 (Email Management API Bypasses ManageCredentials Feature Restrictions)
+	TODO: check
+CVE-2026-55984 (Null Pointer Dereference in AddTime API Causes Authenticated Denial of ...)
+	TODO: check
+CVE-2026-55982 (OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API T ...)
+	TODO: check
+CVE-2026-55402 (CVE-2026-55402 is an out of bounds read vulnerability in Secure Access ...)
+	TODO: check
+CVE-2026-55401 (CVE-2026-55401 is a null dereference vulnerability on the load-balanci ...)
+	TODO: check
+CVE-2026-55400 (CVE-2026-55400 is an integer underflow in Secure Access servers prior  ...)
+	TODO: check
+CVE-2026-54481 (Internal API HTTP client hardcodes InsecureSkipVerify:true with no con ...)
+	TODO: check
+CVE-2026-50105 (RSS/Atom feed handlers bypass API-token scope & public-only confinemen ...)
+	TODO: check
+CVE-2026-49857 (auth-fetch-mcp is an MCP server that lets AI assistants fetch content  ...)
+	TODO: check
+CVE-2026-49856 (@jshookmcp/jshook is an MCP server that gives AI agents tools for Java ...)
+	TODO: check
+CVE-2026-49827 (WebErpMesv2 is a Resource Management and Manufacturing execution syste ...)
+	TODO: check
+CVE-2026-49820 (Probo is a self-hostable governance, risk, and compliance (GRC) platfo ...)
+	TODO: check
+CVE-2026-45819 (baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instea ...)
+	TODO: check
+CVE-2026-42931 (Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint)
+	TODO: check
+CVE-2026-3639 (The PPWP \u2013 Password Protect Pages plugin for WordPress is vulnera ...)
+	TODO: check
+CVE-2026-28189 (Unauthenticated Arbitrary File Deletion in Participants Database <= 2. ...)
+	TODO: check
+CVE-2026-28188 (Unauthenticated Broken Access Control in Hydra Booking <= 1.2.2 versio ...)
+	TODO: check
+CVE-2026-28187 (Unauthenticated Cross Site Scripting (XSS) in Knowledge Base for Docum ...)
+	TODO: check
+CVE-2026-28186 (Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 version ...)
+	TODO: check
+CVE-2026-28185 (Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 v ...)
+	TODO: check
+CVE-2026-28184 (Subscriber SQL Injection in Form Maker by 10Web <= 1.15.44 versions.)
+	TODO: check
+CVE-2026-28182 (Subscriber Cross Site Scripting (XSS) in AcyMailing SMTP Newsletter <= ...)
+	TODO: check
+CVE-2026-28181 (Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.1 ...)
+	TODO: check
+CVE-2026-28176 (Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 v ...)
+	TODO: check
+CVE-2026-28175 (Unauthenticated Cross Site Scripting (XSS) in Visitors Traffic Real Ti ...)
+	TODO: check
+CVE-2026-28174 (Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versio ...)
+	TODO: check
+CVE-2026-28173 (Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 ver ...)
+	TODO: check
+CVE-2026-28170 (Unauthenticated Cross Site Scripting (XSS) in Blog Floating Button <=  ...)
+	TODO: check
+CVE-2026-28168 (Subscriber SQL Injection in CubeWP <= 1.1.30 versions.)
+	TODO: check
+CVE-2026-28161 (Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versi ...)
+	TODO: check
+CVE-2026-28159 (Subscriber Broken Access Control in Service Finder Booking <= 6.2 vers ...)
+	TODO: check
+CVE-2026-28158 (Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358 versions ...)
+	TODO: check
+CVE-2026-28157 (Subscriber Path Traversal in Do Lasso <= 358 versions.)
+	TODO: check
+CVE-2026-28156 (Subscriber SQL Injection in Do Lasso <= 358 versions.)
+	TODO: check
+CVE-2026-28155 (Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso < ...)
+	TODO: check
+CVE-2026-28154 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
+	TODO: check
+CVE-2026-28149 (Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 ...)
+	TODO: check
+CVE-2026-28148 (Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 ...)
+	TODO: check
+CVE-2026-28142 (Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions ...)
+	TODO: check
+CVE-2026-28008 (Unauthenticated Broken Authentication in OAuth Single Sign On \u2013 S ...)
+	TODO: check
+CVE-2026-28004 (Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6. ...)
+	TODO: check
+CVE-2026-28003 (Unauthenticated Cross Site Scripting (XSS) in Maspik \u2013 Spam black ...)
+	TODO: check
+CVE-2026-28002 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
+	TODO: check
+CVE-2026-28001 (Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.)
+	TODO: check
+CVE-2026-27999 (Subscriber Broken Access Control in Tourfic <= 2.23.1 versions.)
+	TODO: check
+CVE-2026-27544 (Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 ...)
+	TODO: check
+CVE-2026-27543 (Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions.)
+	TODO: check
+CVE-2026-27539 (Unauthenticated Cross Site Scripting (XSS) in Welcart e-Commerce <= 2. ...)
+	TODO: check
+CVE-2026-27538 (Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.)
+	TODO: check
+CVE-2026-27537 (Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1. ...)
+	TODO: check
+CVE-2026-27536 (Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Form ...)
+	TODO: check
+CVE-2026-27535 (Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions.)
+	TODO: check
+CVE-2026-27380 (Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions.)
+	TODO: check
+CVE-2026-27345 (Unauthenticated Broken Access Control in Taxi Booking Manager for WooC ...)
+	TODO: check
+CVE-2026-24791 (Public-only tokens bypass private-resource restrictions on `/api/v1/us ...)
+	TODO: check
+CVE-2026-24059 (The GET /api/v1/user/actions/runners/registration-token endpoint (and  ...)
+	TODO: check
+CVE-2026-23603 (Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC pictu ...)
+	TODO: check
+CVE-2026-21832 (HCL AION is affected by a vulnerability where indirect prompt injectio ...)
+	TODO: check
+CVE-2026-19744 (Cross-site Scripting in the Markdown renderer in maalfer Pentestify be ...)
+	TODO: check
+CVE-2026-19734 (Missing Authorization and Authorization Bypass Through User-Controlled ...)
+	TODO: check
+CVE-2026-19730 (The 'podman quadlet install --replace' command opens the existing dest ...)
+	TODO: check
+CVE-2026-19716 (Stored Cross-site Scripting (CWE-79) in the user management component  ...)
+	TODO: check
+CVE-2026-19710 (A vulnerability was found in SourceCodester Simple Student Information ...)
+	TODO: check
+CVE-2026-19696 (Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 ...)
+	TODO: check
+CVE-2026-19695 (Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of  ...)
+	TODO: check
+CVE-2026-19694 (TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of servic ...)
+	TODO: check
+CVE-2026-19487 (Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expre ...)
+	TODO: check
+CVE-2026-19484 (@fastify/busboy is a multipart form-data parser. In versions 3.1.0 thr ...)
+	TODO: check
+CVE-2026-19481 (@fastify/busboy is a multipart form-data parser. In versions 1.0.0 thr ...)
+	TODO: check
+CVE-2026-19293 (SMP security request (from peripheral)does not include the maximum enc ...)
+	TODO: check
+CVE-2026-19292 (Re-pairing with a legitimate device can use a lower security level tha ...)
+	TODO: check
+CVE-2026-19291 (Bluetooth re-pairing with an existing device can use a lower security  ...)
+	TODO: check
+CVE-2026-18622 (Foxit PDF Editor/Reader inconsistently alerts users when signature fie ...)
+	TODO: check
+CVE-2026-18428 (A SQL query validation bypass in the Flint extension query handler in  ...)
+	TODO: check
+CVE-2026-18368 (In Teltonika Networks RUTOS devices, a vulnerability exists in modbusg ...)
+	TODO: check
+CVE-2026-18071 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elev ...)
+	TODO: check
+CVE-2026-17220 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
+	TODO: check
+CVE-2026-17197 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass s ...)
+	TODO: check
+CVE-2026-16459 (Padding oracle attack vulnerability in Oberon microsystem AG\u2019s Ob ...)
+	TODO: check
+CVE-2026-16458 (Padding oracle attack vulnerability in Oberon microsystem AG\u2019s oc ...)
+	TODO: check
+CVE-2026-16455 (In Teltonika Networks RUTOS devices running versions 7.07.1 through 7. ...)
+	TODO: check
+CVE-2026-16101 (Spoofing an already bonded device can force either RS9116W or SiWx917  ...)
+	TODO: check
+CVE-2026-15994 (During an internal security assessment, an improper link following vul ...)
+	TODO: check
+CVE-2026-15413 (The Link Factory WordPress plugin is a backdoor. Distributed as a "hom ...)
+	TODO: check
+CVE-2026-14456 (Issue summary: When an OpenSSL QUIC server (Listener SSL object) proce ...)
+	TODO: check
+CVE-2026-14332 (The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin befor ...)
+	TODO: check
+CVE-2026-14298 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7 ...)
+	TODO: check
+CVE-2026-14256 (ELAN reported a potential out-of-bounds write vulnerability in the ELA ...)
+	TODO: check
+CVE-2026-12908
+	REJECTED
+CVE-2026-12263 (Zohocorp ManageEngine Password Manager Pro versions before 13232 and P ...)
+	TODO: check
+CVE-2026-12236 (The Bluetooth host GATT client function parse_read_std_char_desc() in  ...)
+	TODO: check
+CVE-2026-12036 (An improper link following vulnerability was reported in the VantageCo ...)
+	TODO: check
+CVE-2026-11970 (This vulnerability allows a normal (non-admin) user to disable the For ...)
+	TODO: check
+CVE-2026-11840 (Zohocorp ManageEngine Password Manager Pro versions before 13232 and M ...)
+	TODO: check
+CVE-2025-62318 (HCL AION is affected by a vulnerability where JavaScript responses con ...)
+	TODO: check
+CVE-2025-62315 (HCL AION is affected by a vulnerability where certain input fields do  ...)
+	TODO: check
+CVE-2025-62314 (HCL AION is affected by a vulnerability where certain endpoints lack s ...)
+	TODO: check
+CVE-2025-52640 (HCL AION is affected by a vulnerability where the shared storage used  ...)
+	TODO: check
+CVE-2024-58374 (Hongjing e-HR contains an unauthenticated SQL injection vulnerability  ...)
+	TODO: check
+CVE-2019-25765 (ASP-CMS contains a SQL injection vulnerability in the commentList.asp  ...)
+	TODO: check
+CVE-2022-4993 (HTML::FormHandler versions through 0.40068 for Perl allow attacker sel ...)
 	- libhtml-formhandler-perl <unfixed>
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/42659947/
 	NOTE: https://security.metacpan.org/patches/H/HTML-FormHandler/0.40068/CVE-2022-4993-r2.patch
-CVE-2026-13048
+CVE-2026-13048 (Data::MuForm::Localizer versions through 0.05 for Perl execute Perl fr ...)
 	NOT-FOR-US: Data::MuForm Perl module
-CVE-2026-13051
+CVE-2026-13051 (Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 f ...)
 	NOT-FOR-US: Form::Processor Perl module
-CVE-2026-6464
+CVE-2026-6464 (Untrusted data inclusion in PostgreSQL psql COPY may allow a server ad ...)
 	- postgresql-18 <unfixed>
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-6464/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-6469
+CVE-2026-6469 (Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE co ...)
 	- postgresql-18 <unfixed>
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-6469/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-6470
+CVE-2026-6470 (Missing authorization in PostgreSQL DDL commands allows an object crea ...)
 	- postgresql-18 <unfixed>
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-6470/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-6471
+CVE-2026-6471 (Missing authorization in PostgreSQL logical decoding allows a non-supe ...)
 	- postgresql-18 <unfixed>
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-6471/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14662
+CVE-2026-14662 (Integer wraparound in PostgreSQL tsvector and tsquery data type functi ...)
 	- postgresql-18 <unfixed>
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14662/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14663
+CVE-2026-14663 (Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a use ...)
 	- postgresql-18 <unfixed>
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14663/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14664
+CVE-2026-14664 (Heap buffer overflow in PostgreSQL regexp allows the query author to e ...)
 	- postgresql-18 <unfixed>
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14664/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14666
+CVE-2026-14666 (Incomplete tracking in PostgreSQL of changes to role membership, role  ...)
 	- postgresql-18 <unfixed>
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14666/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14668
+CVE-2026-14668 (Type confusion regarding input of PostgreSQL ctid data type selectivit ...)
 	- postgresql-18 <unfixed>
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14668/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14669
+CVE-2026-14669 (Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the par ...)
 	- postgresql-18 <unfixed>
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14669/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14670
+CVE-2026-14670 (Heap buffer overflow in PostgreSQL plperl return of a tied hash allows ...)
 	- postgresql-18 <unfixed>
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14670/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14671
+CVE-2026-14671 (Type confusion in PostgreSQL module "refint" allows an object creator  ...)
 	- postgresql-18 <unfixed>
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14671/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14672
+CVE-2026-14672 (Observable response discrepancy in PostgreSQL SCRAM authentication all ...)
 	- postgresql-18 <unfixed>
 	- postgresql-17 <removed>
 	- postgresql-15 <not-affected> ((Vulnerable code not present)
 	- postgresql-13 <not-affected> ((Vulnerable code not present)
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14672/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14673
+CVE-2026-14673 (Untrusted search path in PostgreSQL amcheck allows a grantee of amchec ...)
 	- postgresql-18 <unfixed>
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14673/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14676
+CVE-2026-14676 (Heap buffer overflow in PostgreSQL pg_stat_statements allows the query ...)
 	- postgresql-18 <unfixed>
 	- postgresql-17 <not-affected> (Vulnerable code not present)
 	- postgresql-15 <not-affected> (Vulnerable code not present)
 	- postgresql-13 <not-affected> (Vulnerable code not present)
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14676/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14677
+CVE-2026-14677 (Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl all ...)
 	- postgresql-18 <unfixed>
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14677/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14678
+CVE-2026-14678 (Buffer over-read in PostgreSQL pg_trgm index picksplit function reads  ...)
 	- postgresql-18 <unfixed>
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14678/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14679
+CVE-2026-14679 (Stack buffer overflow in PostgreSQL argument name matching allows an o ...)
 	- postgresql-18 <unfixed>
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14679/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14680
+CVE-2026-14680 (Type confusion with PostgreSQL "internal" data type arguments allows a ...)
 	- postgresql-18 <unfixed>
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14680/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14681
+CVE-2026-14681 (Improper enforcement of message integrity in PostgreSQL GSSAPI support ...)
 	- postgresql-18 <unfixed>
 	- postgresql-17 <removed>
 	- postgresql-15 <not-affected> (Vulnerable code not present)
 	- postgresql-13 <not-affected> (Vulnerable code not present)
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-14681/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-15741
+CVE-2026-15741 (SQL injection in PostgreSQL EXTRACT() deparse allows an object owner t ...)
 	- postgresql-18 <unfixed>
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-15741/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-15742
+CVE-2026-15742 (Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct ...)
 	- postgresql-18 <unfixed>
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-15742/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-16238
+CVE-2026-16238 (Type confusion in PostgreSQL pg_restore_attribute_stats() allows an ob ...)
 	- postgresql-18 <unfixed>
 	- postgresql-17 <not-affected> (Vulnerable code not present)
 	- postgresql-15 <not-affected> (Vulnerable code not present)
 	- postgresql-13 <not-affected> (Vulnerable code not present)
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-16238/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-16239
+CVE-2026-16239 (Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user t ...)
 	- postgresql-18 <unfixed>
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-16239/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-16241
+CVE-2026-16241 (Integer underflow in PostgreSQL ECPG allows a database server administ ...)
 	- postgresql-18 <unfixed>
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-16241/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-18024
+CVE-2026-18024 (Buffer over-read in PostgreSQL ascii() SQL function allows a user to d ...)
 	- postgresql-18 <unfixed>
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-18024/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-18408
+CVE-2026-18408 (Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious s ...)
 	- postgresql-18 <unfixed>
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-18408/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-19385
+CVE-2026-19385 (Heap buffer overflow in PostgreSQL pg_dump of long function transform  ...)
 	- postgresql-18 <unfixed>
 	- postgresql-17 <removed>
 	- postgresql-15 <removed>
 	- postgresql-13 <unfixed>
 	NOTE: https://www.postgresql.org/support/security/CVE-2026-19385/
 	NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-68454 [KVM: s390: pci: Fix handling of AIF enable without AISB]
+CVE-2026-68454 (In the Linux kernel, the following vulnerability has been resolved:  K ...)
 	- linux 7.1.5-1
 	[trixie] - linux 6.12.100-1
 	[bookworm] - linux 6.1.180-1
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/3e3aa6da87d30a0064a17b836685cd43c90a3572 (7.2-rc4)
-CVE-2026-68453 [s390/zcrypt: Fix buffer over-read in cca_cipher2protkey]
+CVE-2026-68453 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
 	- linux 7.1.8-1
 	NOTE: https://git.kernel.org/linus/36b230835b8a008266aad22168ca52afacc8a58d (7.2-rc6)
-CVE-2026-68452 [s390/zcrypt: Validate length for CCA AES cipher key requests]
+CVE-2026-68452 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
 	- linux 7.1.8-1
 	NOTE: https://git.kernel.org/linus/06afe425d5283b9764303de47f554da5a808ce8a (7.2-rc6)
-CVE-2026-68451 [s390/zcrypt: Validate length for CCA ECC private key requests]
+CVE-2026-68451 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
 	- linux 7.1.8-1
 	NOTE: https://git.kernel.org/linus/a9ae0f6dd45c3ccc1d69363f7aea8af179122730 (7.2-rc6)
 CVE-2026-7366 (IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gate ...)
@@ -628,103 +1270,103 @@ CVE-2025-9486 (GitLab has remediated an issue in GitLab EE affecting all version
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2024-27253 (IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an auth ...)
 	NOT-FOR-US: IBM
-CVE-2026-53802
+CVE-2026-53802 (rsync before 3.5.0 contains an arbitrary file read vulnerability that  ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53803
+CVE-2026-53803 (rsync before 3.5.0 contains a symlink following vulnerability that all ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53785
+CVE-2026-53785 (rsyncbefore 3.5.0contains a path traversal vulnerability that allows a ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53784
+CVE-2026-53784 (rsync before 3.5.0contains a path traversal vulnerability that allows  ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53793
+CVE-2026-53793 (rsync before 3.5.0contains a path confinement bypass vulnerability tha ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53795
+CVE-2026-53795 (rsync before 3.5.0contains an arbitrary file write vulnerability that  ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53796
+CVE-2026-53796 (rsync before 3.5.0contains a time-of-check to time-of-use (TOCTOU) rac ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53797
+CVE-2026-53797 (rsync before 3.5.0contains a symlink race condition vulnerability in t ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53799
+CVE-2026-53799 (rsync before 3.5.0contains a symlink race condition vulnerability that ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53800
+CVE-2026-53800 (rsync before 3.5.0contains a symlink race condition vulnerability in t ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53801
+CVE-2026-53801 (rsync before 3.5.0contains a symlink race condition vulnerability in t ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53783
+CVE-2026-53783 (rsync before3.5.0 contains a time-of-check to time-of-use (TOCTOU) rac ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53786
+CVE-2026-53786 (rsyncbefore 3.5.0contains a filter rule bypass vulnerability that allo ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53798
+CVE-2026-53798 (rsync tbefore 3.5.0contains a privilege confusion vulnerability in the ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53788
+CVE-2026-53788 (rsync before 3.5.0contains a newline injection vulnerability in the na ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53789
+CVE-2026-53789 (rsync before 3.5.0contains an improper path handling vulnerability tha ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53791
+CVE-2026-53791 (rsync daemon before 3.5.0contains an IP address spoofing vulnerability ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53790
+CVE-2026-53790 (rsync before 3.5.0contains multiple command and argument injection vul ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53792
+CVE-2026-53792 (rsyncbefore 3.5.0contains an out-of-bounds read vulnerability in the s ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53794
+CVE-2026-53794 (rsync before 3.5.0contains a logic error in --max-alloc handling that  ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-70461
+CVE-2026-70461 (rsync 3.2.5 before 3.5.0contains a heap out-of-bounds write vulnerabil ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-70458
+CVE-2026-70458 (rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-70456
+CVE-2026-70456 (rsync 3.0.1 before 3.5.0contains an out-of-bounds write vulnerability  ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-70457
+CVE-2026-70457 (rsync 3.2.3before 3.5.0contains an out-of-bounds write in parse_size_a ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-70459
+CVE-2026-70459 (rsync 3.0.0 before 3.5.0contains a null pointer dereference vulnerabil ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-70464
+CVE-2026-70464 (rsync daemon 2.0.0 before 3.5.0contains a denial of service vulnerabil ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-70455
+CVE-2026-70455 (rsync 3.4.2 before 3.5.0contains a denial of service vulnerability tha ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-70453
+CVE-2026-70453 (rsync before 3.5.0contains an algorithmic complexity vulnerability in  ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-70452
+CVE-2026-70452 (rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerabili ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-70463
+CVE-2026-70463 (rsync 3.1.0 before 3.5.0contains an authorization bypass in auth users ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-70460
+CVE-2026-70460 (rsync 2.3.3 before 3.5.0contains a path traversal vulnerability that a ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-70462
+CVE-2026-70462 (rsync 3.1.0 before 3.5.0contains a signed integer overflow vulnerabili ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-70454
+CVE-2026-70454 (rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 ( ...)
 	- rsync <unfixed>
 	NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
 CVE-2026-17431 (PDF::WebKit versions through 1.2 for Perl allow OS command injection v ...)
@@ -1642,18 +2284,23 @@ CVE-2026-68430 (In the Linux kernel, the following vulnerability has been resolv
 	[trixie] - linux 6.12.101-1
 	NOTE: https://git.kernel.org/linus/84a1a8a952ab4b8c23c5dd1f2eea4049cb4914f5 (7.2-rc2)
 CVE-2026-19556 (Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed  ...)
+	{DSA-6436-1 DLA-4739-1}
 	- chromium 151.0.7922.137-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19557 (Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922 ...)
+	{DSA-6436-1 DLA-4739-1}
 	- chromium 151.0.7922.137-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19558 (Use after free in Extensions in Google Chrome prior to 151.0.7922.137  ...)
+	{DSA-6436-1 DLA-4739-1}
 	- chromium 151.0.7922.137-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19559 (Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowe ...)
+	{DSA-6436-1 DLA-4739-1}
 	- chromium 151.0.7922.137-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19560 (Use after free in Blink in Google Chrome prior to 151.0.7922.137 allow ...)
+	{DSA-6436-1 DLA-4739-1}
 	- chromium 151.0.7922.137-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-9214 (Insufficient input validation vulnerability in the NETGEAR R7000 model ...)
@@ -2831,7 +3478,7 @@ CVE-2026-59119 (Incorrect default permissions in Microsoft PowerShell allows an
 	NOT-FOR-US: Microsoft
 CVE-2026-59113 (Missing authorization in Visual Studio Code allows an unauthorized att ...)
 	NOT-FOR-US: Microsoft
-CVE-2026-59086 (A vulnerability has been identified in Simcenter Nastran (All versions ...)
+CVE-2026-59086 (A vulnerability has been identified in Simcenter Femap (All versions < ...)
 	NOT-FOR-US: Siemens
 CVE-2026-58651 (Heap-based buffer overflow in Microsoft Office Word allows an unauthor ...)
 	NOT-FOR-US: Microsoft
@@ -4399,7 +5046,8 @@ CVE-2026-21058 (Improper input validation in Samsung Contacts prior to SMR Aug-2
 	NOT-FOR-US: Samsung Mobile
 CVE-2026-19433 (Authorization Bypass Through User-Controlled Key in the contact manage ...)
 	TODO: check
-CVE-2026-19429 (Jenkins FilePath.untarFrom() does not validate symlink targets in extr ...)
+CVE-2026-19429
+	REJECTED
 	NOTE: bogus assignment outside of Jenkins CNA scope, being sorted out with MITRE
 CVE-2026-19404 (A flaw was found in 389 Directory Server. The CleanAllRUV and Abort Cl ...)
 	- 389-ds-base <unfixed>
@@ -6218,11 +6866,11 @@ CVE-2026-17519
 	REJECTED
 CVE-2026-17023 (The Salon Booking System  WordPress plugin through 10.30.33 does not p ...)
 	NOT-FOR-US: WordPress plugin
-CVE-2026-17022 (The Salon Booking System  WordPress plugin through 10.30.33 does not p ...)
+CVE-2026-17022 (The Salon Booking System  WordPress plugin before 10.30.34 does not pr ...)
 	NOT-FOR-US: WordPress plugin
-CVE-2026-17021 (The Salon Booking System  WordPress plugin through 10.30.33 does not p ...)
+CVE-2026-17021 (The Salon Booking System WordPress plugin before 10.30.34 does not pro ...)
 	NOT-FOR-US: WordPress plugin
-CVE-2026-17020 (The Salon Booking System  WordPress plugin through 10.30.33 does not v ...)
+CVE-2026-17020 (The Salon Booking System  WordPress plugin through 10.31.0 does not ve ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-17019 (The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploa ...)
 	NOT-FOR-US: WordPress plugin
@@ -7962,10 +8610,12 @@ CVE-2026-43622 (llama.cpp builds b1886 through b7445 contain a double free vulne
 CVE-2026-3430 (The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not saniti ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-34502 (Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Ut ...)
+	{DSA-6437-1}
 	- apr-util 1.6.4-1 (bug #1143837)
 	NOTE: https://lists.apache.org/thread/spk5643m4vq0mb8h5b9hz9gkp57ombl8
 	NOTE: Fixed by: https://github.com/apache/apr-util/commit/f1c98dd0847c43375daf3789c936685adbc6d872 (1.6.4-rc1-candidate)
 CVE-2026-34501 (Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Ut ...)
+	{DSA-6437-1}
 	- apr-util 1.6.4-1 (bug #1143837)
 	NOTE: https://lists.apache.org/thread/o8h6c7cq86fplxlnry6c3rn9x0ovq8mv
 	NOTE: Fixed by: https://github.com/apache/apr-util/commit/e8f36bd5f1cc1c82bed1ae52d5699a4c610251c2 (1.6.4-rc1-candidate)
@@ -7980,6 +8630,7 @@ CVE-2026-32548 (Unauthenticated Broken Access Control in SureCart <= 4.6.2 versi
 CVE-2026-32469 (Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32327 (A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion ...)
+	{DSA-6437-1}
 	- apr-util 1.6.4-1 (bug #1143837)
 	NOTE: https://lists.apache.org/thread/hq27vj8yfno9tkwv0fpj6jksfzgxvth1
 	NOTE: Fixed by: https://github.com/apache/apr-util/commit/414e12e427c89f135d8ee66ab1203feffd3e2bd8 (1.6.4-rc1-candidate)
@@ -8103,6 +8754,7 @@ CVE-2026-0637 (When an Event Publisher output adapter is configured with irrelev
 CVE-2025-9266 (The Accelerate theme for WordPress is vulnerable to unauthorized modif ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2025-49506 (APR-util versions 1.6.3 (and earlier) function apr_password_validate() ...)
+	{DSA-6437-1}
 	- apr-util 1.6.4-1 (bug #1143837)
 	NOTE: https://lists.apache.org/thread/2v8o3bj9pb7lfcr57bdnjg9xfkj04mg5
 	NOTE: Fixed by: https://github.com/apache/apr-util/commit/f77a20761cb15686f8d4de5b5eafc534ae24b19e (1.6.4-rc1-candidate)
@@ -16554,12 +17206,12 @@ CVE-2026-64531 (In the Linux kernel, the following vulnerability has been resolv
 	NOTE: https://git.kernel.org/linus/3f1f755366687d051174739fb99f7d560202f60b (7.2-rc4)
 	NOTE: https://heyitsas.im/posts/ovswrap
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/28/8
-CVE-2026-49478
+CVE-2026-49478 (Fulcio is a certificate authority for issuing code signing certificate ...)
 	- golang-github-sigstore-fulcio 1.8.7-1
 	[trixie] - golang-github-sigstore-fulcio <no-dsa> (Minor issue)
 	NOTE: https://github.com/sigstore/fulcio/pull/2354
 	NOTE: Fixed by: https://github.com/sigstore/fulcio/commit/378c654f48c3bafdced04ead7010aab2cb4c6ca1 (v1.8.6)
-CVE-2026-48702
+CVE-2026-48702 (Rekor is a software supply chain transparency log. Starting in version ...)
 	- rekor 1.5.2-1
 	[trixie] - rekor <no-dsa> (Minor issue)
 	NOTE: https://github.com/sigstore/rekor/pull/2831
@@ -48582,7 +49234,8 @@ CVE-2019-25763 (WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an
 	NOT-FOR-US: WordPress plugin
 CVE-2026-9843 (The Database for Contact Form 7, WPforms, Elementor forms plugin for W ...)
 	NOT-FOR-US: WordPress plugin
-CVE-2026-9375 (urllib3 version 2.6.3 is vulnerable to a decompression bomb bypass in  ...)
+CVE-2026-9375
+	REJECTED
 	- python-urllib3 2.7.0-1 (bug #1140427)
 	[trixie] - python-urllib3 <ignored> (Intrusive to backport; requires update for src:brotli for effective fix)
 	[bookworm] - python-urllib3 <ignored> (Intrusive to backport; requires update for src:brotli for effective fix)
@@ -95483,7 +96136,7 @@ CVE-2026-5437 (An out-of-bounds read vulnerability exists in `DicomStreamReader`
 	NOTE: https://orthanc.uclouvain.be/hg/orthanc/rev/5ce108190752
 CVE-2026-5329 (Rapid7 Velociraptor versions prior to 0.76.2contain an improper input  ...)
 	NOT-FOR-US: Rapid7 Velociraptor
-CVE-2026-4901 (Hydrosystem Control System saves sensitive information into a log file ...)
+CVE-2026-4901 (AlanWeb SCADA saves sensitive information into a log file. Critically, ...)
 	NOT-FOR-US: Hydrosystem Control System
 CVE-2026-4660 (HashiCorp\u2019s go-getter library up to v1.8.5 may allow arbitrary fi ...)
 	- golang-github-hashicorp-go-getter <removed>
@@ -95652,9 +96305,9 @@ CVE-2026-34538 (Apache Airflow versions 3.0.0 through 3.1.8 DagRun wait endpoint
 	- airflow <itp> (bug #819700)
 	NOTE: https://github.com/apache/airflow/pull/64415
 	NOTE: https://www.openwall.com/lists/oss-security/2026/04/09/9
-CVE-2026-34185 (Hydrosystem Control System is vulnerable to SQL Injection across most  ...)
+CVE-2026-34185 (AlanWeb SCADA is vulnerable to SQL Injection across most scripts and i ...)
 	NOT-FOR-US: Hydrosystem Control System
-CVE-2026-34184 (Hydrosystem Control System does not enforce authorization for some dir ...)
+CVE-2026-34184 (AlanWeb SCADA does not enforce authorization for some directories. Thi ...)
 	NOT-FOR-US: Hydrosystem Control System
 CVE-2026-34179 (In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate fu ...)
 	{DSA-6213-1 DSA-6212-1}
@@ -240705,7 +241358,8 @@ CVE-2024-8062 (A vulnerability in the typeahead endpoint of h2oai/h2o-3 version
 	NOT-FOR-US: h2oai/h2o-3
 CVE-2024-8061 (In version 3.23.0 of aimhubio/aim, certain methods that request data f ...)
 	NOT-FOR-US: aimhubio/aim
-CVE-2024-8060 (OpenWebUI version 0.3.0 contains a vulnerability in the audio API endp ...)
+CVE-2024-8060
+	REJECTED
 	NOT-FOR-US: OpenWebUI
 CVE-2024-8057 (In version 0.4.1 of danswer-ai/danswer, a vulnerability exists where a ...)
 	NOT-FOR-US: danswer-ai/danswer
@@ -240735,7 +241389,8 @@ CVE-2024-8017 (An XSS vulnerability exists in open-webui/open-webui versions <=
 	NOT-FOR-US: open-webui/open-webui
 CVE-2024-7999
 	REJECTED
-CVE-2024-7990 (A stored cross-site scripting (XSS) vulnerability exists in open-webui ...)
+CVE-2024-7990
+	REJECTED
 	NOT-FOR-US: open-webui/open-webui
 CVE-2024-7983 (In version 0.3.8 of open-webui, an endpoint for converting markdown to ...)
 	NOT-FOR-US: open-webui/open-webui
@@ -240785,11 +241440,14 @@ CVE-2024-7476 (A broken access control vulnerability exists in lunary-ai/lunary
 	NOT-FOR-US: lunary-ai/lunary
 CVE-2024-7058 (A vulnerability in the sanitize_path function in parisneo/lollms-webui ...)
 	NOT-FOR-US: parisneo/lollms-webui
-CVE-2024-7053 (A vulnerability in open-webui/open-webui version 0.3.8 allows an attac ...)
+CVE-2024-7053
+	REJECTED
 	NOT-FOR-US: open-webui/open-webui
-CVE-2024-7046 (An improper access control vulnerability in open-webui/open-webui v0.3 ...)
+CVE-2024-7046
+	REJECTED
 	NOT-FOR-US: open-webui/open-webui
-CVE-2024-7045 (In version v0.3.8 of open-webui/open-webui, improper access control vu ...)
+CVE-2024-7045
+	REJECTED
 	NOT-FOR-US: open-webui/open-webui
 CVE-2024-7044 (A Stored Cross-Site Scripting (XSS) vulnerability exists in the chat f ...)
 	NOT-FOR-US: open-webui/open-webui
@@ -240799,7 +241457,8 @@ CVE-2024-7040
 	REJECTED
 CVE-2024-7039
 	REJECTED
-CVE-2024-7036 (A vulnerability in open-webui/open-webui v0.3.8 allows an unauthentica ...)
+CVE-2024-7036
+	REJECTED
 	NOT-FOR-US: open-webui/open-webui
 CVE-2024-7035 (In version v0.3.8 of open-webui/open-webui, sensitive actions such as  ...)
 	NOT-FOR-US: open-webui/open-webui
@@ -240937,9 +241596,11 @@ CVE-2024-12704 (A vulnerability in the LangChainLLM class of the run-llama/llama
 	NOT-FOR-US: run-llama/llama_index
 CVE-2024-12580 (A vulnerability in danny-avila/librechat prior to version 0.7.6 allows ...)
 	NOT-FOR-US: danny-avila/librechat
-CVE-2024-12537 (In version 0.3.32 of open-webui/open-webui, the absence of authenticat ...)
+CVE-2024-12537
+	REJECTED
 	NOT-FOR-US: open-webui/open-webui
-CVE-2024-12534 (In version v0.3.32 of open-webui/open-webui, the application allows us ...)
+CVE-2024-12534
+	REJECTED
 	NOT-FOR-US: open-webui/open-webui
 CVE-2024-12450 (In infiniflow/ragflow versions 0.12.0, the `web_crawl` function in `do ...)
 	NOT-FOR-US: infiniflow/ragflow
@@ -291351,7 +292012,8 @@ CVE-2024-7041 (An Insecure Direct Object Reference (IDOR) vulnerability exists i
 	NOT-FOR-US: open-webui
 CVE-2024-7038
 	REJECTED
-CVE-2024-7037 (In version v0.3.8 of open-webui/open-webui, the endpoint /api/pipeline ...)
+CVE-2024-7037
+	REJECTED
 	NOT-FOR-US: open-webui
 CVE-2024-5968 (The Photo Gallery by 10Web  WordPress plugin before 1.8.28 does not pr ...)
 	NOT-FOR-US: WordPress plugin



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/af962a3316f1f9f2e94d64cae5e6e87cf5e1e893

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/af962a3316f1f9f2e94d64cae5e6e87cf5e1e893
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260813/af1c61e8/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list