[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 14 14:20:26 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
cbecbe18 by Salvatore Bonaccorso at 2026-08-14T15:18:18+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -61,9 +61,9 @@ CVE-2026-73655 (Trigger.dev is a platform for building and deploying fully manag
CVE-2026-73654 (Trigger.dev is a platform for building and deploying fully managed AI ...)
NOT-FOR-US: Trigger.dev
CVE-2026-73531 (django-helpdesk before 2.3.3 contains a stored cross-site scripting vu ...)
- TODO: check
+ NOT-FOR-US: django-helpdesk
CVE-2026-73530 (Flyto2 Core before 2.28.0 contains a server-side request forgery guard ...)
- TODO: check
+ NOT-FOR-US: Flyto2 Core
CVE-2026-73489 (Russh is a Rust SSH client & server library. Prior to 0.62.4, an authe ...)
TODO: check
CVE-2026-73480 (gdu fails to strip terminal escape sequences from directory and file n ...)
@@ -71,7 +71,7 @@ CVE-2026-73480 (gdu fails to strip terminal escape sequences from directory and
CVE-2026-73479 (dua-cli fails to filter terminal escape sequences when printing marked ...)
TODO: check
CVE-2026-73428 (Trix is a what-you-see-is-what-you-get rich text editor for everyday w ...)
- TODO: check
+ NOT-FOR-US: Trix
CVE-2026-73421 (NextAuth.js provides authentication for Next.js. From next-auth 5.0.0- ...)
NOT-FOR-US: Next.js
CVE-2026-73420 (NextAuth.js provides authentication for Next.js. Prior to @auth/core 0 ...)
@@ -81,39 +81,39 @@ CVE-2026-73417 (jupyterlab is an extensible environment for interactive and repr
CVE-2026-73416 (jupyterlab is an extensible environment for interactive and reproducib ...)
TODO: check
CVE-2026-73408 (Budibase is an open-source low-code platform. Prior to 3.39.18, packag ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-73305 (Budibase is an open-source low-code platform. Prior to 3.39.24, POST / ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-73304 (Budibase is an open-source low-code platform. Prior to 3.39.25, GET /a ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-73302 (Budibase is an open-source low-code platform. Prior to 3.39.30, the OI ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-73039 (streama contains an insecure direct object reference vulnerability in ...)
- TODO: check
+ NOT-FOR-US: streama
CVE-2026-72857 (Budibase before 3.40.0 fails to redact datasource credentials stored i ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-72856 (Budibase versions before 3.40.0 contain an authorization/authenticatio ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-72855 (Budibase before 3.40.0 contains server-side request forgery vulnerabil ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-72853 (Budibase before 3.40.0 contains a SQL injection vulnerability in the O ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-72851 (Budibase before 3.40.0 contains an unauthenticated SQL injection vulne ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-72850 (Budibase before 3.40.0 fails to properly sanitize S3 object keys, allo ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-72849 (Budibase before 3.40.0 contains a cross-site request forgery vulnerabi ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-72842 (luci-app-lxc contains an ACL inconsistency vulnerability that allows l ...)
- TODO: check
+ NOT-FOR-US: luci-app-lxc
CVE-2026-72841 (luci-app-openvpn fails to properly validate the instance_name2 paramet ...)
- TODO: check
+ NOT-FOR-US: luci-app-openvpn
CVE-2026-72840 (OpenWrt LuCI contains an overly permissive ACL definition in luci-mod- ...)
- TODO: check
+ NOT-FOR-US: OpenWrt LuCI
CVE-2026-72839 (filebrowser through 2.63.16 fails to properly restrict scope and permi ...)
- TODO: check
+ NOT-FOR-US: filebrowser
CVE-2026-72776 (AgenticSeek (commit fc242c7) contains an unauthenticated remote code e ...)
- TODO: check
+ NOT-FOR-US: AgenticSeek
CVE-2026-72687 (A flaw in Elasticsearch allows a low-privileged authenticated user to ...)
NOT-FOR-US: Elasticsearch
CVE-2026-72686 (A flaw in Elasticsearch allows a low-privileged authenticated user to ...)
@@ -135,7 +135,7 @@ CVE-2026-72678 (Elasticsearch does not validate a size value taken from a user-s
CVE-2026-72677 (Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorize ...)
TODO: check
CVE-2026-72676 (Improper Control of Generation of Code ('Code Injection') (CWE-94) in ...)
- TODO: check
+ NOT-FOR-US: Fleet Server
CVE-2026-72675 (Missing Authorization (CWE-862) in Kibana can lead to cross-space info ...)
TODO: check
CVE-2026-72674 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
@@ -169,7 +169,7 @@ CVE-2026-72659 (Allocation of Resources Without Limits or Throttling (CWE-770) i
CVE-2026-72658 (Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege e ...)
TODO: check
CVE-2026-72657 (Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Se ...)
- TODO: check
+ NOT-FOR-US: Fleet Server
CVE-2026-72656 (Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL que ...)
NOT-FOR-US: Elasticsearch
CVE-2026-72655 (Improperly Controlled Modification of Dynamically-Determined Object At ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cbecbe18dd404cf7caf7f6d10df39c788fba20a4
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cbecbe18dd404cf7caf7f6d10df39c788fba20a4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/b0f584bb/attachment.htm>
More information about the debian-security-tracker-commits
mailing list