[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 14 08:15:09 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4ba19497 by security tracker role at 2026-08-14T07:15:02+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -51,9 +51,9 @@ CVE-2026-73479 (dua-cli fails to filter terminal escape sequences when printing
 CVE-2026-73428 (Trix is a what-you-see-is-what-you-get rich text editor for everyday w ...)
 	TODO: check
 CVE-2026-73421 (NextAuth.js provides authentication for Next.js. From next-auth 5.0.0- ...)
-	TODO: check
+	NOT-FOR-US: Next.js
 CVE-2026-73420 (NextAuth.js provides authentication for Next.js. Prior to @auth/core 0 ...)
-	TODO: check
+	NOT-FOR-US: Next.js
 CVE-2026-73417 (jupyterlab is an extensible environment for interactive and reproducib ...)
 	TODO: check
 CVE-2026-73416 (jupyterlab is an extensible environment for interactive and reproducib ...)
@@ -93,23 +93,23 @@ CVE-2026-72839 (filebrowser through 2.63.16 fails to properly restrict scope and
 CVE-2026-72776 (AgenticSeek (commit fc242c7) contains an unauthenticated remote code e ...)
 	TODO: check
 CVE-2026-72687 (A flaw in Elasticsearch allows a low-privileged authenticated user to  ...)
-	TODO: check
+	NOT-FOR-US: Elasticsearch
 CVE-2026-72686 (A flaw in Elasticsearch allows a low-privileged authenticated user to  ...)
-	TODO: check
+	NOT-FOR-US: Elasticsearch
 CVE-2026-72685 (A flaw in Elasticsearch allows a low-privileged authenticated user who ...)
-	TODO: check
+	NOT-FOR-US: Elasticsearch
 CVE-2026-72684 (A flaw in Elasticsearch allows an authenticated user holding only read ...)
-	TODO: check
+	NOT-FOR-US: Elasticsearch
 CVE-2026-72683 (A flaw in Elasticsearch allows an authenticated user with the privileg ...)
-	TODO: check
+	NOT-FOR-US: Elasticsearch
 CVE-2026-72681 (Kibana Agent Builder does not correctly verify that the requesting use ...)
 	TODO: check
 CVE-2026-72680 (Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier  ...)
 	TODO: check
 CVE-2026-72679 (Elasticsearch does not apply its configurable input length restriction ...)
-	TODO: check
+	NOT-FOR-US: Elasticsearch
 CVE-2026-72678 (Elasticsearch does not validate a size value taken from a user-supplie ...)
-	TODO: check
+	NOT-FOR-US: Elasticsearch
 CVE-2026-72677 (Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorize ...)
 	TODO: check
 CVE-2026-72676 (Improper Control of Generation of Code ('Code Injection') (CWE-94) in  ...)
@@ -149,7 +149,7 @@ CVE-2026-72658 (Cross-Site Request Forgery (CWE-352) in Kibana can lead to privi
 CVE-2026-72657 (Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Se ...)
 	TODO: check
 CVE-2026-72656 (Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL que ...)
-	TODO: check
+	NOT-FOR-US: Elasticsearch
 CVE-2026-72655 (Improperly Controlled Modification of Dynamically-Determined Object At ...)
 	TODO: check
 CVE-2026-72653 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
@@ -161,21 +161,21 @@ CVE-2026-72650 (Authorization Bypass Through User-Controlled Key (CWE-639) in Ki
 CVE-2026-72648 (Cleartext Storage of Sensitive Information in an Environment Variable  ...)
 	TODO: check
 CVE-2026-72647 (Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial o ...)
-	TODO: check
+	NOT-FOR-US: Elasticsearch
 CVE-2026-72645 (Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch ...)
-	TODO: check
+	NOT-FOR-US: Elasticsearch
 CVE-2026-72643 (Kibana Agent Builder determines whether a caller owns a private agent  ...)
 	TODO: check
 CVE-2026-72642 (The native inference process that Elasticsearch uses to evaluate uploa ...)
-	TODO: check
+	NOT-FOR-US: Elasticsearch
 CVE-2026-72640 (The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret  ...)
 	TODO: check
 CVE-2026-72639 (Elasticsearch does not enforce an upper bound on a user-supplied count ...)
-	TODO: check
+	NOT-FOR-US: Elasticsearch
 CVE-2026-72638 (Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial o ...)
-	TODO: check
+	NOT-FOR-US: Elasticsearch
 CVE-2026-72636 (Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matchin ...)
-	TODO: check
+	NOT-FOR-US: Elasticsearch
 CVE-2026-72632 (Observable Discrepancy (CWE-203) in Kibana Fleet can lead to informati ...)
 	TODO: check
 CVE-2026-72631 (Improper Privilege Management (CWE-269) in Kibana Fleet can lead to pr ...)
@@ -199,19 +199,19 @@ CVE-2026-45725 (compliance-trestle is a tooling platform for managing compliance
 CVE-2026-3883
 	REJECTED
 CVE-2026-19811 (A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-19792 (A security flaw has been discovered in Tenda G0 up to 20260625. Impact ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-19791 (A weakness has been identified in Tenda G0 up to 20260625. The affecte ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-19790 (A vulnerability was identified in Tenda G0 up to 20260625. This issue  ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-19789 (A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-19788 (A vulnerability was found in Tenda AC1206 15.03.06.23_multi_TD01. This ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-19787 (A vulnerability was determined in SourceCodester Air Cargo Management  ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-19786 (A vulnerability was found in francoisjacquet RosarioSIS up to 12.8. Th ...)
 	TODO: check
 CVE-2026-19785 (A vulnerability has been found in francoisjacquet RosarioSIS up to 12. ...)
@@ -223,7 +223,7 @@ CVE-2026-19771 (A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0
 CVE-2026-19770 (A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affect ...)
 	TODO: check
 CVE-2026-19767 (A weakness has been identified in itsourcecode Hospital Management Sys ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-19765 (A security flaw has been discovered in eyaushev swagger-testcase-mcp 5 ...)
 	TODO: check
 CVE-2026-19764 (A vulnerability was identified in Raisecom Communication Command and D ...)
@@ -247,13 +247,13 @@ CVE-2026-19752 (A vulnerability was found in EnzoVezzaro mcp-dominican-layer up
 CVE-2026-19751 (A flaw has been found in EnzoVezzaro mcp-dominican-layer up to 39dd373 ...)
 	TODO: check
 CVE-2026-19750 (A flaw has been found in Tenda CH, CP and TX3 V21.x/V22.x/V25.x/V26.x/ ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-19749 (A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, C ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-19748 (A security vulnerability has been detected in Tenda CH7, CH7G, CH10, C ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-19747 (A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-19746 (A vulnerability has been found in Calix GigaSpire 26.1.0. The affected ...)
 	TODO: check
 CVE-2026-19745 (A flaw has been found in Calix GigaSpire 26.1.0. Impacted is an unknow ...)
@@ -261,171 +261,171 @@ CVE-2026-19745 (A flaw has been found in Calix GigaSpire 26.1.0. Impacted is an
 CVE-2026-19617 (A flaw was found in libdm. A remote attacker could craft a malicious L ...)
 	TODO: check
 CVE-2026-19483 (IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-19297 (IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18846 (IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a buffer overflow from im ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18741 (Worksuite SaaS versions prior to 6.0.14 contains a stored cross-site s ...)
 	TODO: check
 CVE-2026-18715 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18671 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18532
 	REJECTED
 CVE-2026-18511 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacke ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18509 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacke ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18249 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18193 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass s ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18164 (An undocumented hard-coded credential, shared by all device units, is  ...)
 	TODO: check
 CVE-2026-18109 (The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross- ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18101 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elev ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18086 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute a ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18077 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18068 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain s ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18039 (The Essential Addons for Elementor  WordPress plugin before 6.7.2 does ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18020 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17649 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain s ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17502 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17482 (IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17481 (IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17476 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17473 (IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17468 (IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17438 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain se ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17272 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17229 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17226 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17223 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17216 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17212 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17206 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17199 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17101 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17099 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain s ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17088 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17078 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17077 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17076 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17075 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain s ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17074 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17071 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17069 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17045 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17043 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17029 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute a ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17004 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16987 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elev ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16982 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16975 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16967 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16961 (IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16929 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16908 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16898 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacke ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16896 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacke ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16887 (IBM i 7.6 could allow a remote attacker to cause a denial of service d ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16878 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16871 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16868 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16867 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access s ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16861 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16859 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain s ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16853 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain s ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16815 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16810 (The Bit Form \u2013 Contact Form, Payment Forms, Multi Step Forms, Cal ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16739 (The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 do ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16722 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16713 (IBM Documentation Offline 1.0.0 through 1.4.1 IBM Documentation could  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16692 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16674 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-15205 (The Paymob for WooCommerce WordPress plugin before 4.1.9 does not prop ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14875 (IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable t ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-14525 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 I ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-14290 (The Embed Google Photos album WordPress plugin through 2.2.1 does not  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13460 (IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-13365 (IBM Planning Analytics 2.0, and 2.1 Local is vulnerable to cross-site  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-12949 (The Wishlist Member plugin for WordPress is vulnerable to Account Take ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12743 (The affiliate-toolkit \u2013 Multi-Network Affiliate & Amazon Product  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-10571 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 i ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2025-10308 (The Astro Booking Engine plugin for WordPress is vulnerable to Cross-S ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-73261 [Built-in TCP/IP malformed TCP option handling]
 	- mongoose 7.23+ds-1
 CVE-2026-73260 [Built-in TLS X.509 DER parsing bounds check]



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4ba194970a2d36ded2dc5381f56ade12cb8ef76b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4ba194970a2d36ded2dc5381f56ade12cb8ef76b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/ea996ac8/attachment.htm>


More information about the debian-security-tracker-commits mailing list