[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 17 08:45:47 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e4522c41 by Salvatore Bonaccorso at 2026-08-17T09:45:23+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3,7 +3,7 @@ CVE-2026-50602 (A security vulnerability has been identified in Planet9 due to i
 CVE-2026-50601 (A security vulnerability has been identified in the Planet9 desktop ap ...)
 	NOT-FOR-US: Acer
 CVE-2026-22072 (Loading arbitrary external URLs through WebView components introduces  ...)
-	TODO: check
+	NOT-FOR-US: OPPO
 CVE-2026-19997 (A security flaw has been discovered in Webkul Bagisto up to 2.4.4. Thi ...)
 	NOT-FOR-US: Webkul Bagisto
 CVE-2026-19996 (A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vul ...)
@@ -64,11 +64,11 @@ CVE-2026-19967 (A security flaw has been discovered in Open Asset Import Library
 	- assimp <unfixed>
 	NOTE: https://github.com/assimp/assimp/issues/6624
 CVE-2026-19966 (A vulnerability was identified in CodeCanyon TimeCamp Integration for  ...)
-	TODO: check
+	NOT-FOR-US: CodeCanyon TimeCamp Integration for CRM
 CVE-2026-19965 (A vulnerability was determined in automad up to 2.0.0-beta.32. This vu ...)
-	TODO: check
+	NOT-FOR-US: automad
 CVE-2026-19964 (A vulnerability was found in Jij-Inc Jij-MCP-Server 0.1.0. This affect ...)
-	TODO: check
+	NOT-FOR-US: Jij-Inc Jij-MCP-Server
 CVE-2026-19963 (A vulnerability has been found in Edimax EW-7478APC 1.04. Affected by  ...)
 	NOT-FOR-US: Edimax
 CVE-2026-19962 (A flaw has been found in Edimax EW-7478APC 1.04. Affected by this vuln ...)
@@ -80,13 +80,13 @@ CVE-2026-19960 (A security vulnerability has been detected in Edimax EW-7478APC
 CVE-2026-19959 (A weakness has been identified in Edimax EW-7478APC 1.04. This affects ...)
 	NOT-FOR-US: Edimax
 CVE-2026-19958 (A security flaw has been discovered in iatsiuk pptr-mcp up to 0.2.7. T ...)
-	TODO: check
+	NOT-FOR-US: iatsiuk pptr-mcp
 CVE-2026-19957 (A vulnerability was identified in graphlit graphlit-mcp-server 1.0.1.  ...)
-	TODO: check
+	NOT-FOR-US: graphlit graphlit-mcp-server
 CVE-2026-19956 (A vulnerability has been found in gomarble-ai facebook-ads-mcp-server  ...)
-	TODO: check
+	NOT-FOR-US: gomarble-ai facebook-ads-mcp-server
 CVE-2026-19955 (A vulnerability was detected in TrailDB 0.6. Impacted is the function  ...)
-	TODO: check
+	NOT-FOR-US: TrailDB
 CVE-2026-15623 (A SQL Injection vulnerability in a legacy dashboard widget API in Goog ...)
 	TODO: check
 CVE-2026-14832 (The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 d ...)
@@ -8008,7 +8008,7 @@ CVE-2026-29035 (CivetWeb (commit 4a4f0c95) contains a heap and stack buffer over
 	- civetweb <unfixed>
 	TODO: check details upstream
 CVE-2026-19594 (Insufficient input sanitization in Snowflake Python API (`snowflake.co ...)
-	TODO: check
+	NOT-FOR-US: Snowflake Python API
 CVE-2026-19588 (Integer Overflow to Buffer Overflow vulnerability in Samsung Open Sour ...)
 	- rlottie <unfixed> (bug #1144473)
 	[trixie] - rlottie <no-dsa> (Minor issue)
@@ -9813,7 +9813,7 @@ CVE-2026-19546 (A flaw was found in DBI. This is a fix for a partial fix for CVE
 	- libdbi-perl <not-affected> (Red Hat-specific backport issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2513963
 CVE-2026-19539 (Authorization Bypass Through User-Controlled Key in the ticket managem ...)
-	TODO: check
+	NOT-FOR-US: Roskus Prospero Flow CRM
 CVE-2026-19519 (A flaw was found in claircore's RPM package scanner. Crafted RPM heade ...)
 	NOT-FOR-US: claircore
 CVE-2026-19434 (Cross-site Scripting in the finding renderer in maalfer Pentestify bef ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e4522c4131ec6d150f1a9f0f6e7d330409742282

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e4522c4131ec6d150f1a9f0f6e7d330409742282
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260817/cc64b6ef/attachment.htm>


More information about the debian-security-tracker-commits mailing list