[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Fri Aug 14 08:22:51 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
580561cc by Moritz Muehlenhoff at 2026-08-14T09:22:41+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -766,15 +766,15 @@ CVE-2026-72741 (Rainbond through 6.9.7 contains a broken access control vulnerab
CVE-2026-6387 (A potential authentication bypass vulnerability was reported in Lenovo ...)
NOT-FOR-US: Lenovo
CVE-2026-67991 (crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 cont ...)
- TODO: check
+ NOT-FOR-US: ruby_llm
CVE-2026-67990 (basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f di ...)
TODO: check
CVE-2026-67986 (amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c271 ...)
TODO: check
CVE-2026-67614 (CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability ...)
- TODO: check
+ NOT-FOR-US: CyberPanel
CVE-2026-67613 (CyberPanel before 3.0.0 contains a path traversal vulnerability that a ...)
- TODO: check
+ NOT-FOR-US: CyberPanel
CVE-2026-66704 (Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Compa ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-66700 (Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for C ...)
@@ -1638,13 +1638,13 @@ CVE-2026-72508 (A flaw was found in the multicloud-operators-subscription compon
CVE-2026-72506 (VoiceTra provided by National Institute of Information and Communicati ...)
NOT-FOR-US: VoiceTra
CVE-2026-71846 (A flaw was found in insights-client. The component's ServiceAccount is ...)
- TODO: check
+ NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
CVE-2026-71473 (A flaw was found in the `search-v2-operator` component. A user with sp ...)
- TODO: check
+ NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
CVE-2026-71471 (A flaw was found in acm-search-v2-rhel9. An attacker with administrati ...)
NOT-FOR-US: acm-search-v2-rhel9
CVE-2026-71469 (A flaw was found in search-v2-api. An unauthenticated attacker can exp ...)
- TODO: check
+ NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
CVE-2026-6821 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-67579 (Deserialization of Untrusted Data vulnerability in ash-project ash all ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/580561ccd08be40bfbfab6e84b39329f38f9587c
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/580561ccd08be40bfbfab6e84b39329f38f9587c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/b7ff03dc/attachment.htm>
More information about the debian-security-tracker-commits
mailing list