[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Aug 15 08:37:08 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5fb623a9 by Salvatore Bonaccorso at 2026-08-15T09:36:34+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -8,29 +8,29 @@ CVE-2026-74248 (OpenStack Octavia through 18.0.0 mishandles quality of service (
 	NOTE: https://www.openwall.com/lists/oss-security/2026/08/13/12
 	NOTE: https://bugs.launchpad.net/octavia/+bug/2161500
 CVE-2026-74247 (A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT en ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Quay
 CVE-2026-74245 (A flaw was found in Red Hat Quay's exported logs feature. An unauthent ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Quay
 CVE-2026-74244 (A flaw was found in Red Hat Quay's Stripe billing webhook handler. Thi ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Quay
 CVE-2026-74243 (A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pr ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Quay
 CVE-2026-74242 (A flaw was found in Red Hat Quay. An administrator of any repository,  ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Quay
 CVE-2026-74241 (A flaw was found in Red Hat Quay's external Lightweight Directory Acce ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Quay
 CVE-2026-74240 (A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Quay
 CVE-2026-73683 (Laravel Socialite's Facebook provider contains an authentication bypas ...)
-	TODO: check
+	NOT-FOR-US: Laravel Socialite's Facebook provider
 CVE-2026-73682 (Semaphore versions prior to 2.18.20 contain an OS command injection (a ...)
-	TODO: check
+	NOT-FOR-US: Semaphore UI
 CVE-2026-73680 (Cockpit CMS 2.14.0 and prior contains a command injection vulnerabilit ...)
-	TODO: check
+	NOT-FOR-US: Cockpit CMS
 CVE-2026-73679 (ImpressCMS contains an authenticated remote code execution vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: ImpressCMS
 CVE-2026-73678 (MindsDB Minds Platform version 26.1.0 and earlier contains an unauthen ...)
-	TODO: check
+	NOT-FOR-US: MindsDB
 CVE-2026-71571 (Joomla Extension - icagenda.com -  Authenticated SQL injection via une ...)
 	NOT-FOR-US: Joomla
 CVE-2026-71570 (Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user e ...)
@@ -50,9 +50,9 @@ CVE-2026-63649 (The Windows interactive service in OpenVPN 2.4.0 through 2.6.21
 CVE-2026-50523 (Improper neutralization of special elements used in a command ('comman ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-50029 (js-toml is a TOML parser for JavaScript, Prior to version 1.1.2, the i ...)
-	TODO: check
+	NOT-FOR-US: js-toml
 CVE-2026-50027 (mcp-memory-service is a semantic memory layer for AI applications. Pri ...)
-	TODO: check
+	NOT-FOR-US: mcp-memory-service
 CVE-2026-39925
 	REJECTED
 CVE-2026-34492 (External control of file name or path vulnerability in Johnson Control ...)
@@ -4130,11 +4130,11 @@ CVE-2026-57469 (Nozomi Networks Labs identified a CWE-352: Cross-Site Request Fo
 CVE-2026-53970 (ZeroBrew version 0.3.1 and prior contains a missing integrity verifica ...)
 	NOT-FOR-US: ZeroBrew
 CVE-2026-49989 (CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3 ...)
-	TODO: check
+	NOT-FOR-US: CrateDB
 CVE-2026-49986 (The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persis ...)
-	TODO: check
+	NOT-FOR-US: Cortex MCP server
 CVE-2026-49826 (Concourse is a container-based automation system written in Go. Prior  ...)
-	TODO: check
+	NOT-FOR-US: Concourse
 CVE-2026-49457 (erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4 ...)
 	TODO: check
 CVE-2026-49282 (Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Ca ...)
@@ -4369,7 +4369,7 @@ CVE-2026-73480 (gdu fails to strip terminal escape sequences from directory and
 	NOTE: https://github.com/dundee/gdu/pull/616
 	NOTE: Fixed by: https://github.com/dundee/gdu/commit/5d76fab735f190fd645896de90ac9982b6382aeb
 CVE-2026-73479 (dua-cli fails to filter terminal escape sequences when printing marked ...)
-	TODO: check
+	NOT-FOR-US: dua-cli
 CVE-2026-73428 (Trix is a what-you-see-is-what-you-get rich text editor for everyday w ...)
 	NOT-FOR-US: Trix
 CVE-2026-73421 (NextAuth.js provides authentication for Next.js. From next-auth 5.0.0- ...)
@@ -4511,9 +4511,9 @@ CVE-2026-72630 (Incorrect Authorization (CWE-863) in Kibana Fleet can lead to pr
 CVE-2026-72629 (Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana c ...)
 	- kibana <itp> (bug #700337)
 CVE-2026-59714 (Open WebUI is an extensible, feature-rich, and user-friendly self-host ...)
-	TODO: check
+	NOT-FOR-US: Open WebUI
 CVE-2026-49864 (wetty provides terminal access in browser over http/https. Prior to ve ...)
-	TODO: check
+	NOT-FOR-US: wetty
 CVE-2026-49096 (Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of ser ...)
 	TODO: check
 CVE-2026-49089 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
@@ -6032,17 +6032,17 @@ CVE-2026-59916 (Dell Display and Peripheral Manager (DDPM Windows), versions pri
 CVE-2026-59914 (Dell Display and Peripheral Manager (DDPM Windows), versions prior to  ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-50544 (NortheBridge/luminalshine is a Sunshine-compatible game stream host fo ...)
-	TODO: check
+	NOT-FOR-US: NortheBridge/luminalshine
 CVE-2026-4879 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-49819 (UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vuln ...)
-	TODO: check
+	NOT-FOR-US: UpSnap
 CVE-2026-49481 (UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS co ...)
-	TODO: check
+	NOT-FOR-US: UpSnap
 CVE-2026-49473 (@cedar-policy/authorization-for-expressjs is an open-source Express.js ...)
-	TODO: check
+	NOT-FOR-US: cedar-policy/authorization-for-expressjs
 CVE-2026-49466 (Draft List is a WordPress plugin to manage and promote unpublished con ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-48791 (sigstore-java is a sigstore java client for interacting with sigstore  ...)
 	TODO: check
 CVE-2026-47718 (FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ...)
@@ -6497,15 +6497,15 @@ CVE-2026-64639 (Incorrect database cloning process in Plesk from 18.0.52 before
 CVE-2026-58076 (Apache Airflow's serialization layer reconstructed exception nodes by  ...)
 	TODO: check
 CVE-2026-57858 (Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-si ...)
-	TODO: check
+	NOT-FOR-US: Cal.com Cal.diy
 CVE-2026-54183 (Apache Airflow's secrets masker hides values stored under sensitive ke ...)
 	TODO: check
 CVE-2026-53996 (NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a mis ...)
-	TODO: check
+	NOT-FOR-US: NetBSD
 CVE-2026-50561 (Yuxi is a large-model-based intelligent knowledge base and knowledge g ...)
-	TODO: check
+	NOT-FOR-US: Yuxi
 CVE-2026-49467 (Pingvin Share X is a secure and easy self-hosted file sharing platform ...)
-	TODO: check
+	NOT-FOR-US: Pingvin Share X
 CVE-2026-49349 (regclient is a Docker and OCI Registry Client in Go. Prior to version  ...)
 	TODO: check
 CVE-2026-49262 (In the Aimeos Pagible content management system prior to version 0.10. ...)
@@ -6959,7 +6959,7 @@ CVE-2026-66145 (An unauthenticated remote code execution vulnerability was ident
 CVE-2026-66098 (The Mira hormone monitor device firmware accepts a 0x01 write from any ...)
 	NOT-FOR-US: Mira
 CVE-2026-65655 (When OAuth authentication is enabled and browser-facing TLS terminates ...)
-	TODO: check
+	NOT-FOR-US: temporalio ui-server
 CVE-2026-64954 (Velociraptor allows scheduling new collections via VQL queries in note ...)
 	NOT-FOR-US: Velociraptor
 CVE-2026-64934 (The Mira cloud API accepts the firmware version reported by the compan ...)
@@ -9809,9 +9809,9 @@ CVE-2026-63106 (ReadyEcommerce before 4.5.2 contains an unauthenticated SQL inje
 CVE-2026-63105 (ReadyEcommerce before 4.5.2 contains a stored cross-site scripting (XS ...)
 	NOT-FOR-US: ReadyEcommerceCrafty Controller
 CVE-2026-59233 (Missing Authorization in the permission management component in Roskus ...)
-	TODO: check
+	NOT-FOR-US: Roskus Prospero Flow CRM
 CVE-2026-59112 (Improper verification of cryptographic signature and Improper Check fo ...)
-	TODO: check
+	NOT-FOR-US: Estonian Information System Authority (RIA)
 CVE-2026-59091 (A flaw was found in GIMP's file format plugins, including those for PS ...)
 	- gimp <unfixed>
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16510
@@ -9832,7 +9832,7 @@ CVE-2026-59087 (A flaw was found in the GIMP image manipulation program, specifi
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16491
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/bb36034bedb06305402ce836129efe8c8d4ad41d
 CVE-2026-57279 (Cybozu Garoon contains a cross-site scripting vulnerability. If this v ...)
-	TODO: check
+	NOT-FOR-US: Cybozu
 CVE-2026-56620 (HCL BigFix Mobileis vulnerable to information disclosure due to improp ...)
 	NOT-FOR-US: HCL
 CVE-2026-56619 (HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Ref ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5fb623a96febd15fa2fd534e8f3cf165024da52f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5fb623a96febd15fa2fd534e8f3cf165024da52f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260815/825d0014/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list