[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Aug 14 09:12:31 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5cd99052 by Moritz Muehlenhoff at 2026-08-14T10:12:11+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -873,7 +873,7 @@ CVE-2026-66426 (Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 v
 CVE-2026-66424 (Unauthenticated Privilege Escalation in SMS Alert Order Notifications  ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66256 (** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vuln ...)
-	TODO: check
+	NOT-FOR-US: Apache Shindig
 CVE-2026-65936 (A malformed Bluetooth connection request message can cause the RS9116W ...)
 	NOT-FOR-US: Silicon Labs
 CVE-2026-65935 (Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS911 ...)
@@ -923,25 +923,25 @@ CVE-2026-59765 (SSRF via Migration Asset Downloads Bypasses hostmatcher \u2014 R
 CVE-2026-59763 (Unbounded Arch package file metadata can cause resource amplification  ...)
 	NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
 CVE-2026-59507 (CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive  ...)
-	TODO: check
+	NOT-FOR-US: Priority ERP
 CVE-2026-59506 (CWE-306: Missing Authentication for Critical Function)
-	TODO: check
+	NOT-FOR-US: Priority ERP
 CVE-2026-59505 (CWE-284: Improper Access Control)
-	TODO: check
+	NOT-FOR-US: Priority ERP
 CVE-2026-59504 (CWE-602: Client-Side Enforcement of Server-Side Security)
-	TODO: check
+	NOT-FOR-US: Priority ERP
 CVE-2026-59503 (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CW ...)
-	TODO: check
+	NOT-FOR-US: Priority ERP
 CVE-2026-59502 (CWE-203: Observable Discrepancy)
-	TODO: check
+	NOT-FOR-US: Priority ERP
 CVE-2026-59501 (CWE-284: Improper Access Control)
-	TODO: check
+	NOT-FOR-US: Priority ERP
 CVE-2026-59500 (CWE-287: Improper Authentication)
-	TODO: check
+	NOT-FOR-US: Priority ERP
 CVE-2026-59499 (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor)
-	TODO: check
+	NOT-FOR-US: Priority ERP
 CVE-2026-59109 (SQL injection in the Zalktis accounting application via trading-partne ...)
-	TODO: check
+	NOT-FOR-US: Zalktis
 CVE-2026-58511 (Webhook Authorization Header Returned in Plaintext via API)
 	NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
 CVE-2026-58510 (GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo p ...)
@@ -1031,15 +1031,15 @@ CVE-2026-54481 (Internal API HTTP client hardcodes InsecureSkipVerify:true with
 CVE-2026-50105 (RSS/Atom feed handlers bypass API-token scope & public-only confinemen ...)
 	NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
 CVE-2026-49857 (auth-fetch-mcp is an MCP server that lets AI assistants fetch content  ...)
-	TODO: check
+	NOT-FOR-US: auth-fetch-mcp
 CVE-2026-49856 (@jshookmcp/jshook is an MCP server that gives AI agents tools for Java ...)
-	TODO: check
+	NOT-FOR-US: jshookmcp/jshook
 CVE-2026-49827 (WebErpMesv2 is a Resource Management and Manufacturing execution syste ...)
-	TODO: check
+	NOT-FOR-US: WebErpMesv2
 CVE-2026-49820 (Probo is a self-hostable governance, risk, and compliance (GRC) platfo ...)
-	TODO: check
+	NOT-FOR-US: Probo
 CVE-2026-45819 (baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instea ...)
-	TODO: check
+	NOT-FOR-US: baseline-browser-mapping
 CVE-2026-42931 (Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint)
 	NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
 CVE-2026-3639 (The PPWP \u2013 Password Protect Pages plugin for WordPress is vulnera ...)
@@ -1085,7 +1085,7 @@ CVE-2026-28156 (Subscriber SQL Injection in Do Lasso <= 358 versions.)
 CVE-2026-28155 (Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso < ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28154 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28149 (Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28148 (Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5cd990520013f45621311637cbb153fcfc2803f1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5cd990520013f45621311637cbb153fcfc2803f1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/33571e16/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list