[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 14 06:54:50 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
10c1b606 by Salvatore Bonaccorso at 2026-08-14T07:54:11+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -168,21 +168,21 @@ CVE-2026-73619 (GitPython before 3.1.57 contains an incomplete denylist in the u
- python-git <unfixed>
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-539m-9xh6-q6rr
CVE-2026-73618 (Budibase Server before 3.40.0 contains a NoSQL injection vulnerability ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-73617 (Budibase before 3.40.0 contains a NoSQL injection vulnerability in the ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-73616 (OpenRemote notification deletion endpoints fail to enforce realm bound ...)
- TODO: check
+ NOT-FOR-US: OpenRemote
CVE-2026-73615 (Network-AI versions before 5.15.1 contain a security matcher bypass vu ...)
- TODO: check
+ NOT-FOR-US: Network-AI
CVE-2026-73614 (Network-AI ClaudeHookBridge before 5.15.1 truncates the target string ...)
- TODO: check
+ NOT-FOR-US: Network-AI
CVE-2026-73613 (filebrowser versions before 2.63.19 contain an out-of-scope file delet ...)
- TODO: check
+ NOT-FOR-US: filebrowser
CVE-2026-73612 (File Browser before v2.63.22 fails to validate access rules for descen ...)
- TODO: check
+ NOT-FOR-US: filebrowser
CVE-2026-73611 (File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT ...)
- TODO: check
+ NOT-FOR-US: filebrowser
CVE-2026-73610 (SiYuan before v3.7.4 contains an information disclosure vulnerability ...)
NOT-FOR-US: SiYuan
CVE-2026-73609 (SiYuan versions before v3.7.4 contain an information disclosure vulner ...)
@@ -204,11 +204,11 @@ CVE-2026-73602 (Flowise before 3.1.3 contains a sandbox escape vulnerability in
CVE-2026-73601 (Flowise versions before 3.1.3 contain a remote code execution vulnerab ...)
NOT-FOR-US: Flowise
CVE-2026-73585 (A flaw was found in sblim-cmpi-base. Insecure temporary file creation ...)
- TODO: check
+ NOT-FOR-US: sblim-cmpi-base
CVE-2026-73584 (A flaw was found in sblim-sfcb. A local, low-privileged attacker can e ...)
- TODO: check
+ NOT-FOR-US: sblim-sfcb
CVE-2026-73583 (A flaw was found in sblim-sfcb. A local attacker with access to the sy ...)
- TODO: check
+ NOT-FOR-US: sblim-sfcb
CVE-2026-73576 (In Zimbra Collaboration (ZCS) before 10.1.17,weak cryptographic key ge ...)
NOT-FOR-US: Zimbra
CVE-2026-73575 (In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request For ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/10c1b6060d5b36c5d85e2405bf38be9264993ceb
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/10c1b6060d5b36c5d85e2405bf38be9264993ceb
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/e603714e/attachment.htm>
More information about the debian-security-tracker-commits
mailing list