[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 14 06:54:50 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
10c1b606 by Salvatore Bonaccorso at 2026-08-14T07:54:11+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -168,21 +168,21 @@ CVE-2026-73619 (GitPython before 3.1.57 contains an incomplete denylist in the u
 	- python-git <unfixed>
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-539m-9xh6-q6rr
 CVE-2026-73618 (Budibase Server before 3.40.0 contains a NoSQL injection vulnerability ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-73617 (Budibase before 3.40.0 contains a NoSQL injection vulnerability in the ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-73616 (OpenRemote notification deletion endpoints fail to enforce realm bound ...)
-	TODO: check
+	NOT-FOR-US: OpenRemote
 CVE-2026-73615 (Network-AI versions before 5.15.1 contain a security matcher bypass vu ...)
-	TODO: check
+	NOT-FOR-US: Network-AI
 CVE-2026-73614 (Network-AI ClaudeHookBridge before 5.15.1 truncates the target string  ...)
-	TODO: check
+	NOT-FOR-US: Network-AI
 CVE-2026-73613 (filebrowser versions before 2.63.19 contain an out-of-scope file delet ...)
-	TODO: check
+	NOT-FOR-US: filebrowser
 CVE-2026-73612 (File Browser before v2.63.22 fails to validate access rules for descen ...)
-	TODO: check
+	NOT-FOR-US: filebrowser
 CVE-2026-73611 (File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT ...)
-	TODO: check
+	NOT-FOR-US: filebrowser
 CVE-2026-73610 (SiYuan before v3.7.4 contains an information disclosure vulnerability  ...)
 	NOT-FOR-US: SiYuan
 CVE-2026-73609 (SiYuan versions before v3.7.4 contain an information disclosure vulner ...)
@@ -204,11 +204,11 @@ CVE-2026-73602 (Flowise before 3.1.3 contains a sandbox escape vulnerability in
 CVE-2026-73601 (Flowise versions before 3.1.3 contain a remote code execution vulnerab ...)
 	NOT-FOR-US: Flowise
 CVE-2026-73585 (A flaw was found in sblim-cmpi-base. Insecure temporary file creation  ...)
-	TODO: check
+	NOT-FOR-US: sblim-cmpi-base
 CVE-2026-73584 (A flaw was found in sblim-sfcb. A local, low-privileged attacker can e ...)
-	TODO: check
+	NOT-FOR-US: sblim-sfcb
 CVE-2026-73583 (A flaw was found in sblim-sfcb. A local attacker with access to the sy ...)
-	TODO: check
+	NOT-FOR-US: sblim-sfcb
 CVE-2026-73576 (In Zimbra Collaboration (ZCS) before 10.1.17,weak cryptographic key ge ...)
 	NOT-FOR-US: Zimbra
 CVE-2026-73575 (In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request For ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/10c1b6060d5b36c5d85e2405bf38be9264993ceb

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/10c1b6060d5b36c5d85e2405bf38be9264993ceb
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/e603714e/attachment.htm>


More information about the debian-security-tracker-commits mailing list