[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sun Aug 16 22:32:31 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
231b67ce by Moritz Muehlenhoff at 2026-08-16T23:32:03+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -6960,37 +6960,37 @@ CVE-2026-19643 (An out-of-bounds read issue in the Base64 decoder in Amazon aws-
 CVE-2026-19642 (An out-of-bounds write issue in the Base64 decoder in Amazon aws-sdk-c ...)
 	NOT-FOR-US: Amazon
 CVE-2026-19503 (MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not valida ...)
-	TODO: check
+	- mongodb <removed>
 CVE-2026-19502 (MongoDB SQL Schema Builder CLI records its startup configuration to st ...)
-	TODO: check
+	- mongodb <removed>
 CVE-2026-19228 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-19182 (An incorrect authorization check in the v2 Alarm REST API in OpenNMS M ...)
-	TODO: check
+	NOT-FOR-US: OpenNMS
 CVE-2026-19135 (A JEXL expression sandbox bypass exists in multiple versions of OpenNM ...)
-	TODO: check
+	NOT-FOR-US: OpenNMS
 CVE-2026-19130 (A flaw was found in the provider-credential-controller component of mu ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Multicluster Engine for Kubernetes
 CVE-2026-19088 (The ShopEngine Elementor WooCommerce Builder Addon  WordPress plugin b ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-19004 (An application using the MongoDB BI Connector ODBC Driver may experien ...)
-	TODO: check
+	NOT-FOR-US: MongoDB BI Connector
 CVE-2026-19003 (A data source definition containing an over-length file path setting m ...)
-	TODO: check
+	NOT-FOR-US: MongoDB BI Connector
 CVE-2026-19002 (A missing bounds check when parsing stored procedure parameter metadat ...)
-	TODO: check
+	NOT-FOR-US: MongoDB BI Connector
 CVE-2026-19001 (The MongoDB BI Connector ODBC Driver may write outside the bounds of a ...)
-	TODO: check
+	NOT-FOR-US: MongoDB BI Connector
 CVE-2026-18945 (The WP Helper Premium WordPress plugin before 4.7.6 does not verify th ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-18888 (The MongoDB BI Connector ODBC Driver converts floating point column va ...)
-	TODO: check
+	- mongodb <removed>
 CVE-2026-18750 (vinny/views.py: (ModifyEmailNotifications)IDOR: view fetches VinceComm ...)
-	TODO: check
+	NOT-FOR-US: CERT/CC VINCE
 CVE-2026-18749 (The type=track branch authorises on _is_my_case(t_attach.case) only an ...)
-	TODO: check
+	NOT-FOR-US: CERT/CC VINCE
 CVE-2026-18744 (Any authenticated case participant can fetch any OTHER vendor's CaseSt ...)
-	TODO: check
+	NOT-FOR-US: CERT/CC VINCE
 CVE-2026-18728 (A flaw was found in open-iscsi. An integer underflow vulnerability in  ...)
 	TODO: check
 CVE-2026-18727 (A flaw was found in open-iscsi's iscsiuio component. This vulnerabilit ...)
@@ -6998,7 +6998,7 @@ CVE-2026-18727 (A flaw was found in open-iscsi's iscsiuio component. This vulner
 CVE-2026-18726 (A flaw was found in open-iscsi. This vulnerability allows a remote att ...)
 	TODO: check
 CVE-2026-18679 (When kuma-dp is started against an HTTPS control plane and the operato ...)
-	TODO: check
+	NOT-FOR-US: Kuma
 CVE-2026-18433 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-18150 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
@@ -7052,7 +7052,7 @@ CVE-2026-14213 (The Booking for Appointments and Events Calendar  WordPress plug
 CVE-2026-14182 (The Customer Email Verification for WooCommerce WordPress plugin befor ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-13622 (A symlink following vulnerability was found in KubeVirt's virt-handler ...)
-	TODO: check
+	NOT-FOR-US: KubeVirt
 CVE-2026-13610 (The KiviCare  WordPress plugin before 4.5.2 does not restrict the role ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-13476 (IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unau ...)
@@ -7452,15 +7452,15 @@ CVE-2026-18713 (IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to privilege escalatio
 CVE-2026-18683 (IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via ...)
 	NOT-FOR-US: IBM
 CVE-2026-18678 (When an operator adds an HTTPS control plane profile to kumactl withou ...)
-	TODO: check
+	NOT-FOR-US: Kuma
 CVE-2026-18677 (In Kong Mesh running in universal mode with a MeshIdentity whose SPIFF ...)
-	TODO: check
+	NOT-FOR-US: Kuma
 CVE-2026-18676 (The default kuma-cp configuration in Kong Mesh reveals the admin boots ...)
-	TODO: check
+	NOT-FOR-US: Kuma
 CVE-2026-18675 (The dataplane token validator in kuma-cp performs an unchecked Go type ...)
-	TODO: check
+	NOT-FOR-US: Kuma
 CVE-2026-18673 (When kuma-dp is configured with the Envoy admin API on a Unix domain s ...)
-	TODO: check
+	NOT-FOR-US: Kuma
 CVE-2026-18669 (IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation a ...)
 	NOT-FOR-US: IBM
 CVE-2026-18663 (A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() fu ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/231b67ce4f27576e7bd0cdc3117cfb83b6b42bce

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/231b67ce4f27576e7bd0cdc3117cfb83b6b42bce
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260816/58fd41b3/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list