[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Fri Aug 14 09:12:31 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
5cd99052 by Moritz Muehlenhoff at 2026-08-14T10:12:11+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -873,7 +873,7 @@ CVE-2026-66426 (Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 v
CVE-2026-66424 (Unauthenticated Privilege Escalation in SMS Alert Order Notifications ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-66256 (** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vuln ...)
- TODO: check
+ NOT-FOR-US: Apache Shindig
CVE-2026-65936 (A malformed Bluetooth connection request message can cause the RS9116W ...)
NOT-FOR-US: Silicon Labs
CVE-2026-65935 (Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS911 ...)
@@ -923,25 +923,25 @@ CVE-2026-59765 (SSRF via Migration Asset Downloads Bypasses hostmatcher \u2014 R
CVE-2026-59763 (Unbounded Arch package file metadata can cause resource amplification ...)
NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-59507 (CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive ...)
- TODO: check
+ NOT-FOR-US: Priority ERP
CVE-2026-59506 (CWE-306: Missing Authentication for Critical Function)
- TODO: check
+ NOT-FOR-US: Priority ERP
CVE-2026-59505 (CWE-284: Improper Access Control)
- TODO: check
+ NOT-FOR-US: Priority ERP
CVE-2026-59504 (CWE-602: Client-Side Enforcement of Server-Side Security)
- TODO: check
+ NOT-FOR-US: Priority ERP
CVE-2026-59503 (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CW ...)
- TODO: check
+ NOT-FOR-US: Priority ERP
CVE-2026-59502 (CWE-203: Observable Discrepancy)
- TODO: check
+ NOT-FOR-US: Priority ERP
CVE-2026-59501 (CWE-284: Improper Access Control)
- TODO: check
+ NOT-FOR-US: Priority ERP
CVE-2026-59500 (CWE-287: Improper Authentication)
- TODO: check
+ NOT-FOR-US: Priority ERP
CVE-2026-59499 (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor)
- TODO: check
+ NOT-FOR-US: Priority ERP
CVE-2026-59109 (SQL injection in the Zalktis accounting application via trading-partne ...)
- TODO: check
+ NOT-FOR-US: Zalktis
CVE-2026-58511 (Webhook Authorization Header Returned in Plaintext via API)
NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-58510 (GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo p ...)
@@ -1031,15 +1031,15 @@ CVE-2026-54481 (Internal API HTTP client hardcodes InsecureSkipVerify:true with
CVE-2026-50105 (RSS/Atom feed handlers bypass API-token scope & public-only confinemen ...)
NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-49857 (auth-fetch-mcp is an MCP server that lets AI assistants fetch content ...)
- TODO: check
+ NOT-FOR-US: auth-fetch-mcp
CVE-2026-49856 (@jshookmcp/jshook is an MCP server that gives AI agents tools for Java ...)
- TODO: check
+ NOT-FOR-US: jshookmcp/jshook
CVE-2026-49827 (WebErpMesv2 is a Resource Management and Manufacturing execution syste ...)
- TODO: check
+ NOT-FOR-US: WebErpMesv2
CVE-2026-49820 (Probo is a self-hostable governance, risk, and compliance (GRC) platfo ...)
- TODO: check
+ NOT-FOR-US: Probo
CVE-2026-45819 (baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instea ...)
- TODO: check
+ NOT-FOR-US: baseline-browser-mapping
CVE-2026-42931 (Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint)
NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-3639 (The PPWP \u2013 Password Protect Pages plugin for WordPress is vulnera ...)
@@ -1085,7 +1085,7 @@ CVE-2026-28156 (Subscriber SQL Injection in Do Lasso <= 358 versions.)
CVE-2026-28155 (Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso < ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-28154 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28149 (Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-28148 (Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5cd990520013f45621311637cbb153fcfc2803f1
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5cd990520013f45621311637cbb153fcfc2803f1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/33571e16/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list