[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 14 22:19:12 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
75203532 by Salvatore Bonaccorso at 2026-08-14T23:18:53+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -470,7 +470,7 @@ CVE-2026-72651 (Allocation of Resources Without Limits or Throttling (CWE-770) i
 CVE-2026-72650 (Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana c ...)
 	- kibana <itp> (bug #700337)
 CVE-2026-72648 (Cleartext Storage of Sensitive Information in an Environment Variable  ...)
-	TODO: check
+	NOT-FOR-US: Elastic Cloud on Kubernetes (ECK)
 CVE-2026-72647 (Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial o ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-72645 (Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch ...)
@@ -480,7 +480,7 @@ CVE-2026-72643 (Kibana Agent Builder determines whether a caller owns a private
 CVE-2026-72642 (The native inference process that Elasticsearch uses to evaluate uploa ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-72640 (The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret  ...)
-	TODO: check
+	NOT-FOR-US: Elastic Cloud on Kubernetes (ECK)
 CVE-2026-72639 (Elasticsearch does not enforce an upper bound on a user-supplied count ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-72638 (Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial o ...)
@@ -1087,7 +1087,7 @@ CVE-2026-6387 (A potential authentication bypass vulnerability was reported in L
 CVE-2026-67991 (crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 cont ...)
 	NOT-FOR-US: ruby_llm
 CVE-2026-67990 (basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f di ...)
-	TODO: check
+	NOT-FOR-US: basecamp/upright
 CVE-2026-67986 (amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c271 ...)
 	- ruby-amazing-print <unfixed>
 	NOTE: https://gist.github.com/Zykis1024/21b13ddabf1a7d9707fd573518cefa71
@@ -1972,13 +1972,13 @@ CVE-2026-71469 (A flaw was found in search-v2-api. An unauthenticated attacker c
 CVE-2026-6821 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-67579 (Deserialization of Untrusted Data vulnerability in ash-project ash all ...)
-	TODO: check
+	NOT-FOR-US: ash-project ash
 CVE-2026-66898 (A path traversal vulnerability in LXD allows an attacker to manipulate ...)
 	TODO: check
 CVE-2026-65370 (ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding w ...)
 	NOT-FOR-US: Apple
 CVE-2026-64826 (rConfig before 8.2.13 contains a path traversal vulnerability that all ...)
-	TODO: check
+	NOT-FOR-US: rConfig
 CVE-2026-63300 (An improper validation vulnerability in the instancePostMigration func ...)
 	TODO: check
 CVE-2026-63299 (An authorization bypass vulnerability in LXD allows an authenticated u ...)
@@ -2427,27 +2427,27 @@ CVE-2026-67283 (Joomla Extension - tabaoca.org - Improper ACL implementation all
 CVE-2026-67282 (Joomla Extension - fabrikar.com - Unauthenticated remote code executio ...)
 	NOT-FOR-US: Joomla
 CVE-2026-67260 (Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer  ...)
-	TODO: check
+	- airflow <itp> (bug #819700)
 CVE-2026-66384 (An authenticated user may write data outside the intended Docker cache ...)
-	TODO: check
+	NOT-FOR-US: JFrog Artifactory
 CVE-2026-66382 (An authenticated user may write files outside the intended Artifactory ...)
-	TODO: check
+	NOT-FOR-US: JFrog Artifactory
 CVE-2026-66381 (A repository reader with cache-deploy permission may access content ou ...)
-	TODO: check
+	NOT-FOR-US: JFrog Artifactory
 CVE-2026-66380 (An authenticated user without repository read permission may access pr ...)
-	TODO: check
+	NOT-FOR-US: JFrog Artifactory
 CVE-2026-66379 (An authenticated user may view private Puppet module metadata without  ...)
-	TODO: check
+	NOT-FOR-US: JFrog Artifactory
 CVE-2026-66378 (An authenticated user without repository read permission may access pr ...)
-	TODO: check
+	NOT-FOR-US: JFrog Artifactory
 CVE-2026-66377 (An unauthenticated user may access restricted repository information u ...)
-	TODO: check
+	NOT-FOR-US: JFrog Artifactory
 CVE-2026-66376 (Credentials for a deleted user may remain valid for a short period und ...)
-	TODO: check
+	NOT-FOR-US: JFrog Artifactory
 CVE-2026-66375 (A low-privilege authenticated user may permanently remove protected in ...)
-	TODO: check
+	NOT-FOR-US: JFrog Artifactory
 CVE-2026-66016 (Under specific self-hosted Helm configurations, generated TLS private  ...)
-	TODO: check
+	NOT-FOR-US: JFrog Artifactory
 CVE-2026-65941 (In WhatsUp Gold versions released before 2026.0.2,an unauthenticated r ...)
 	NOT-FOR-US: Progress Software
 CVE-2026-65940 (In WhatsUp Gold versions released before 2026.0.2, a privileged attack ...)
@@ -2459,7 +2459,7 @@ CVE-2026-65938 (In WhatsUp Gold versions released before 2026.0.2,an improperaut
 CVE-2026-65937 (In WhatsUp Gold versions released before 2026.0.2, an authenticated at ...)
 	NOT-FOR-US: Progress Software
 CVE-2026-65926 (An anonymous caller when anonymous access is enabled, or a low-privile ...)
-	TODO: check
+	NOT-FOR-US: JFrog Artifactory
 CVE-2026-64955 (When Microsoft Excel imports a CSV file, it executes cells beginning w ...)
 	NOT-FOR-US: Rapid7
 CVE-2026-64952 (The hunt_delete() VQL function allows deleting hunts.  Velociraptor mi ...)
@@ -2467,7 +2467,7 @@ CVE-2026-64952 (The hunt_delete() VQL function allows deleting hunts.  Velocirap
 CVE-2026-64951 (A rogue Velociraptor client can upload a malformed sparse file such th ...)
 	NOT-FOR-US: Rapid7
 CVE-2026-64639 (Incorrect database cloning process in Plesk from 18.0.52 before 18.0.7 ...)
-	TODO: check
+	NOT-FOR-US: Plesk
 CVE-2026-58076 (Apache Airflow's serialization layer reconstructed exception nodes by  ...)
 	TODO: check
 CVE-2026-57858 (Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-si ...)
@@ -3784,9 +3784,9 @@ CVE-2026-68793 (Out-of-bounds read in Microsoft Office Excel allows an unauthori
 CVE-2026-68792 (Improper neutralization of special elements used in a command ('comman ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-67180 (Google Turbinia allows arbitrary command execution via worker tasks. A ...)
-	TODO: check
+	NOT-FOR-US: Google Turbinia
 CVE-2026-67179 (Genkit does not properly validate host request headers. Any host on th ...)
-	TODO: check
+	NOT-FOR-US: Genkit
 CVE-2026-66810 (Heap-based buffer overflow in Microsoft Office Word allows an unauthor ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-66809 (Out-of-bounds read in Microsoft Office allows an unauthorized attacker ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/75203532a114a8a3c89f8f62e2bfc7ddb33f50ae

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/75203532a114a8a3c89f8f62e2bfc7ddb33f50ae
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/761fdf57/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list