[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Aug 14 08:22:51 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
580561cc by Moritz Muehlenhoff at 2026-08-14T09:22:41+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -766,15 +766,15 @@ CVE-2026-72741 (Rainbond through 6.9.7 contains a broken access control vulnerab
 CVE-2026-6387 (A potential authentication bypass vulnerability was reported in Lenovo ...)
 	NOT-FOR-US: Lenovo
 CVE-2026-67991 (crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 cont ...)
-	TODO: check
+	NOT-FOR-US: ruby_llm
 CVE-2026-67990 (basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f di ...)
 	TODO: check
 CVE-2026-67986 (amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c271 ...)
 	TODO: check
 CVE-2026-67614 (CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability ...)
-	TODO: check
+	NOT-FOR-US: CyberPanel
 CVE-2026-67613 (CyberPanel before 3.0.0 contains a path traversal vulnerability that a ...)
-	TODO: check
+	NOT-FOR-US: CyberPanel
 CVE-2026-66704 (Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Compa ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66700 (Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for C ...)
@@ -1638,13 +1638,13 @@ CVE-2026-72508 (A flaw was found in the multicloud-operators-subscription compon
 CVE-2026-72506 (VoiceTra provided by National Institute of Information and Communicati ...)
 	NOT-FOR-US: VoiceTra
 CVE-2026-71846 (A flaw was found in insights-client. The component's ServiceAccount is ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
 CVE-2026-71473 (A flaw was found in the `search-v2-operator` component. A user with sp ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
 CVE-2026-71471 (A flaw was found in acm-search-v2-rhel9. An attacker with administrati ...)
 	NOT-FOR-US: acm-search-v2-rhel9
 CVE-2026-71469 (A flaw was found in search-v2-api. An unauthenticated attacker can exp ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
 CVE-2026-6821 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-67579 (Deserialization of Untrusted Data vulnerability in ash-project ash all ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/580561ccd08be40bfbfab6e84b39329f38f9587c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/580561ccd08be40bfbfab6e84b39329f38f9587c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/b7ff03dc/attachment.htm>


More information about the debian-security-tracker-commits mailing list