[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 14 14:20:26 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
cbecbe18 by Salvatore Bonaccorso at 2026-08-14T15:18:18+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -61,9 +61,9 @@ CVE-2026-73655 (Trigger.dev is a platform for building and deploying fully manag
 CVE-2026-73654 (Trigger.dev is a platform for building and deploying fully managed AI  ...)
 	NOT-FOR-US: Trigger.dev
 CVE-2026-73531 (django-helpdesk before 2.3.3 contains a stored cross-site scripting vu ...)
-	TODO: check
+	NOT-FOR-US: django-helpdesk
 CVE-2026-73530 (Flyto2 Core before 2.28.0 contains a server-side request forgery guard ...)
-	TODO: check
+	NOT-FOR-US: Flyto2 Core
 CVE-2026-73489 (Russh is a Rust SSH client & server library. Prior to 0.62.4, an authe ...)
 	TODO: check
 CVE-2026-73480 (gdu fails to strip terminal escape sequences from directory and file n ...)
@@ -71,7 +71,7 @@ CVE-2026-73480 (gdu fails to strip terminal escape sequences from directory and
 CVE-2026-73479 (dua-cli fails to filter terminal escape sequences when printing marked ...)
 	TODO: check
 CVE-2026-73428 (Trix is a what-you-see-is-what-you-get rich text editor for everyday w ...)
-	TODO: check
+	NOT-FOR-US: Trix
 CVE-2026-73421 (NextAuth.js provides authentication for Next.js. From next-auth 5.0.0- ...)
 	NOT-FOR-US: Next.js
 CVE-2026-73420 (NextAuth.js provides authentication for Next.js. Prior to @auth/core 0 ...)
@@ -81,39 +81,39 @@ CVE-2026-73417 (jupyterlab is an extensible environment for interactive and repr
 CVE-2026-73416 (jupyterlab is an extensible environment for interactive and reproducib ...)
 	TODO: check
 CVE-2026-73408 (Budibase is an open-source low-code platform. Prior to 3.39.18, packag ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-73305 (Budibase is an open-source low-code platform. Prior to 3.39.24, POST / ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-73304 (Budibase is an open-source low-code platform. Prior to 3.39.25, GET /a ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-73302 (Budibase is an open-source low-code platform. Prior to 3.39.30, the OI ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-73039 (streama contains an insecure direct object reference vulnerability in  ...)
-	TODO: check
+	NOT-FOR-US: streama
 CVE-2026-72857 (Budibase before 3.40.0 fails to redact datasource credentials stored i ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-72856 (Budibase versions before 3.40.0 contain an authorization/authenticatio ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-72855 (Budibase before 3.40.0 contains server-side request forgery vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-72853 (Budibase before 3.40.0 contains a SQL injection vulnerability in the O ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-72851 (Budibase before 3.40.0 contains an unauthenticated SQL injection vulne ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-72850 (Budibase before 3.40.0 fails to properly sanitize S3 object keys, allo ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-72849 (Budibase before 3.40.0 contains a cross-site request forgery vulnerabi ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-72842 (luci-app-lxc contains an ACL inconsistency vulnerability that allows l ...)
-	TODO: check
+	NOT-FOR-US: luci-app-lxc
 CVE-2026-72841 (luci-app-openvpn fails to properly validate the instance_name2 paramet ...)
-	TODO: check
+	NOT-FOR-US: luci-app-openvpn
 CVE-2026-72840 (OpenWrt LuCI contains an overly permissive ACL definition in luci-mod- ...)
-	TODO: check
+	NOT-FOR-US: OpenWrt LuCI
 CVE-2026-72839 (filebrowser through 2.63.16 fails to properly restrict scope and permi ...)
-	TODO: check
+	NOT-FOR-US: filebrowser
 CVE-2026-72776 (AgenticSeek (commit fc242c7) contains an unauthenticated remote code e ...)
-	TODO: check
+	NOT-FOR-US: AgenticSeek
 CVE-2026-72687 (A flaw in Elasticsearch allows a low-privileged authenticated user to  ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-72686 (A flaw in Elasticsearch allows a low-privileged authenticated user to  ...)
@@ -135,7 +135,7 @@ CVE-2026-72678 (Elasticsearch does not validate a size value taken from a user-s
 CVE-2026-72677 (Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorize ...)
 	TODO: check
 CVE-2026-72676 (Improper Control of Generation of Code ('Code Injection') (CWE-94) in  ...)
-	TODO: check
+	NOT-FOR-US: Fleet Server
 CVE-2026-72675 (Missing Authorization (CWE-862) in Kibana can lead to cross-space info ...)
 	TODO: check
 CVE-2026-72674 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
@@ -169,7 +169,7 @@ CVE-2026-72659 (Allocation of Resources Without Limits or Throttling (CWE-770) i
 CVE-2026-72658 (Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege e ...)
 	TODO: check
 CVE-2026-72657 (Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Se ...)
-	TODO: check
+	NOT-FOR-US: Fleet Server
 CVE-2026-72656 (Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL que ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-72655 (Improperly Controlled Modification of Dynamically-Determined Object At ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cbecbe18dd404cf7caf7f6d10df39c788fba20a4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cbecbe18dd404cf7caf7f6d10df39c788fba20a4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/b0f584bb/attachment.htm>


More information about the debian-security-tracker-commits mailing list