[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 14 22:19:12 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
75203532 by Salvatore Bonaccorso at 2026-08-14T23:18:53+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -470,7 +470,7 @@ CVE-2026-72651 (Allocation of Resources Without Limits or Throttling (CWE-770) i
CVE-2026-72650 (Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana c ...)
- kibana <itp> (bug #700337)
CVE-2026-72648 (Cleartext Storage of Sensitive Information in an Environment Variable ...)
- TODO: check
+ NOT-FOR-US: Elastic Cloud on Kubernetes (ECK)
CVE-2026-72647 (Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial o ...)
NOT-FOR-US: Elasticsearch
CVE-2026-72645 (Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch ...)
@@ -480,7 +480,7 @@ CVE-2026-72643 (Kibana Agent Builder determines whether a caller owns a private
CVE-2026-72642 (The native inference process that Elasticsearch uses to evaluate uploa ...)
NOT-FOR-US: Elasticsearch
CVE-2026-72640 (The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret ...)
- TODO: check
+ NOT-FOR-US: Elastic Cloud on Kubernetes (ECK)
CVE-2026-72639 (Elasticsearch does not enforce an upper bound on a user-supplied count ...)
NOT-FOR-US: Elasticsearch
CVE-2026-72638 (Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial o ...)
@@ -1087,7 +1087,7 @@ CVE-2026-6387 (A potential authentication bypass vulnerability was reported in L
CVE-2026-67991 (crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 cont ...)
NOT-FOR-US: ruby_llm
CVE-2026-67990 (basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f di ...)
- TODO: check
+ NOT-FOR-US: basecamp/upright
CVE-2026-67986 (amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c271 ...)
- ruby-amazing-print <unfixed>
NOTE: https://gist.github.com/Zykis1024/21b13ddabf1a7d9707fd573518cefa71
@@ -1972,13 +1972,13 @@ CVE-2026-71469 (A flaw was found in search-v2-api. An unauthenticated attacker c
CVE-2026-6821 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-67579 (Deserialization of Untrusted Data vulnerability in ash-project ash all ...)
- TODO: check
+ NOT-FOR-US: ash-project ash
CVE-2026-66898 (A path traversal vulnerability in LXD allows an attacker to manipulate ...)
TODO: check
CVE-2026-65370 (ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding w ...)
NOT-FOR-US: Apple
CVE-2026-64826 (rConfig before 8.2.13 contains a path traversal vulnerability that all ...)
- TODO: check
+ NOT-FOR-US: rConfig
CVE-2026-63300 (An improper validation vulnerability in the instancePostMigration func ...)
TODO: check
CVE-2026-63299 (An authorization bypass vulnerability in LXD allows an authenticated u ...)
@@ -2427,27 +2427,27 @@ CVE-2026-67283 (Joomla Extension - tabaoca.org - Improper ACL implementation all
CVE-2026-67282 (Joomla Extension - fabrikar.com - Unauthenticated remote code executio ...)
NOT-FOR-US: Joomla
CVE-2026-67260 (Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer ...)
- TODO: check
+ - airflow <itp> (bug #819700)
CVE-2026-66384 (An authenticated user may write data outside the intended Docker cache ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-66382 (An authenticated user may write files outside the intended Artifactory ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-66381 (A repository reader with cache-deploy permission may access content ou ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-66380 (An authenticated user without repository read permission may access pr ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-66379 (An authenticated user may view private Puppet module metadata without ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-66378 (An authenticated user without repository read permission may access pr ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-66377 (An unauthenticated user may access restricted repository information u ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-66376 (Credentials for a deleted user may remain valid for a short period und ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-66375 (A low-privilege authenticated user may permanently remove protected in ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-66016 (Under specific self-hosted Helm configurations, generated TLS private ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-65941 (In WhatsUp Gold versions released before 2026.0.2,an unauthenticated r ...)
NOT-FOR-US: Progress Software
CVE-2026-65940 (In WhatsUp Gold versions released before 2026.0.2, a privileged attack ...)
@@ -2459,7 +2459,7 @@ CVE-2026-65938 (In WhatsUp Gold versions released before 2026.0.2,an improperaut
CVE-2026-65937 (In WhatsUp Gold versions released before 2026.0.2, an authenticated at ...)
NOT-FOR-US: Progress Software
CVE-2026-65926 (An anonymous caller when anonymous access is enabled, or a low-privile ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-64955 (When Microsoft Excel imports a CSV file, it executes cells beginning w ...)
NOT-FOR-US: Rapid7
CVE-2026-64952 (The hunt_delete() VQL function allows deleting hunts. Velociraptor mi ...)
@@ -2467,7 +2467,7 @@ CVE-2026-64952 (The hunt_delete() VQL function allows deleting hunts. Velocirap
CVE-2026-64951 (A rogue Velociraptor client can upload a malformed sparse file such th ...)
NOT-FOR-US: Rapid7
CVE-2026-64639 (Incorrect database cloning process in Plesk from 18.0.52 before 18.0.7 ...)
- TODO: check
+ NOT-FOR-US: Plesk
CVE-2026-58076 (Apache Airflow's serialization layer reconstructed exception nodes by ...)
TODO: check
CVE-2026-57858 (Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-si ...)
@@ -3784,9 +3784,9 @@ CVE-2026-68793 (Out-of-bounds read in Microsoft Office Excel allows an unauthori
CVE-2026-68792 (Improper neutralization of special elements used in a command ('comman ...)
NOT-FOR-US: Microsoft
CVE-2026-67180 (Google Turbinia allows arbitrary command execution via worker tasks. A ...)
- TODO: check
+ NOT-FOR-US: Google Turbinia
CVE-2026-67179 (Genkit does not properly validate host request headers. Any host on th ...)
- TODO: check
+ NOT-FOR-US: Genkit
CVE-2026-66810 (Heap-based buffer overflow in Microsoft Office Word allows an unauthor ...)
NOT-FOR-US: Microsoft
CVE-2026-66809 (Out-of-bounds read in Microsoft Office allows an unauthorized attacker ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/75203532a114a8a3c89f8f62e2bfc7ddb33f50ae
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/75203532a114a8a3c89f8f62e2bfc7ddb33f50ae
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/761fdf57/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list