[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 17 20:14:45 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
bdb3893c by security tracker role at 2026-08-17T19:14:39+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,9 +1,9 @@
 CVE-2026-9771 (The flash_copy() system call is verified by z_vrfy_flash_copy() in dri ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-75060 (In JetBrains PyCharm before 2026.2.1 code execution was possible via u ...)
-	TODO: check
+	NOT-FOR-US: JetBrains
 CVE-2026-75059 (In JetBrains PyCharm before 2026.2.1 code execution via Quick Document ...)
-	TODO: check
+	NOT-FOR-US: JetBrains
 CVE-2026-75058 (In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Ecl ...)
 	TODO: check
 CVE-2026-75057 (In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were writte ...)
@@ -19,21 +19,21 @@ CVE-2026-75053 (In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via
 CVE-2026-75052 (In JetBrains IntelliJ IDEA before 2026.2.1 command execution via craft ...)
 	TODO: check
 CVE-2026-75051 (In JetBrains YouTrack before 2026.2.17917 unauthorised project transfe ...)
-	TODO: check
+	NOT-FOR-US: JetBrains
 CVE-2026-75050 (In JetBrains YouTrack before 2026.1.13901,  2026.2.17950 doS attack wa ...)
-	TODO: check
+	NOT-FOR-US: JetBrains
 CVE-2026-75049 (In JetBrains YouTrack before 2026.1.13903,  2026.2.17950 an authentica ...)
-	TODO: check
+	NOT-FOR-US: JetBrains
 CVE-2026-75048 (In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced co ...)
-	TODO: check
+	NOT-FOR-US: JetBrains
 CVE-2026-75047 (In JetBrains YouTrack before 2026.2.18177 doS attack was possible via  ...)
-	TODO: check
+	NOT-FOR-US: JetBrains
 CVE-2026-75046 (In JetBrains YouTrack before 2026.2.18112 an authenticated user could  ...)
-	TODO: check
+	NOT-FOR-US: JetBrains
 CVE-2026-75045 (In JetBrains YouTrack before 2025.3.156085,  2026.1.13913,  2026.2.181 ...)
-	TODO: check
+	NOT-FOR-US: JetBrains
 CVE-2026-75044 (In JetBrains YouTrack before 2025.3.156085,  2026.1.13914,  2026.2.180 ...)
-	TODO: check
+	NOT-FOR-US: JetBrains
 CVE-2026-75011 (A flaw has been found in kylecui NetForensicMCP 2.1.0. Impacted is the ...)
 	TODO: check
 CVE-2026-74901 (openssl_encrypt versions before 1.4.0 contain an authentication bypass ...)
@@ -99,31 +99,31 @@ CVE-2026-74870 (openssl_encrypt (pip) versions <= 1.4.7 contain an information e
 CVE-2026-74869 (stoatchat before 0.15.0 contains a missing authorization vulnerability ...)
 	TODO: check
 CVE-2026-74868 (SiYuan versions before 3.7.4 contain an unthrottled brute-force vulner ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-74867 (SiYuan versions before 3.7.4 contain a cross-site request forgery vuln ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-74858 (A vulnerability has been found in jae-jae fetcher-mcp up to 0.3.9. Imp ...)
 	TODO: check
 CVE-2026-74845 (Official Document Management System developed by 2100 Technology has a ...)
 	TODO: check
 CVE-2026-74843 (A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. ...)
-	TODO: check
+	NOT-FOR-US: Wavlink
 CVE-2026-74842 (A vulnerability was found in Kira-Pgr PromptShopMCP up to 5bc0cd17358e ...)
 	TODO: check
 CVE-2026-74802 (SiYuan versions before 3.7.4 contain a cross-site WebSocket hijacking  ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-74801 (SiYuan before 3.7.4 fails to properly escape workspace directory paths ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-74800 (SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Ty ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-74799 (SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints includ ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-74798 (SiYuan kernel before v3.7.4 contains a path traversal vulnerability in ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-74254 (Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3. ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-74253 (Joomla Extension - regularlabs.com - Unauthenticated RCE through unver ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-74238 (TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerabil ...)
 	TODO: check
 CVE-2026-73851 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1  ...)
@@ -151,9 +151,9 @@ CVE-2026-71491 (sqlparse is a non-validating SQL parser module for Python. Prior
 CVE-2026-71479 (New API is a large language mode (LLM) gateway and artificial intellig ...)
 	TODO: check
 CVE-2026-70412 (Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version p ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-68762 (In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket deco ...)
-	TODO: check
+	NOT-FOR-US: JetBrains
 CVE-2026-68520 (Glances is an open-source system cross-platform monitoring tool. Prior ...)
 	TODO: check
 CVE-2026-68519 (Glances is an open-source system cross-platform monitoring tool. Prior ...)
@@ -181,11 +181,11 @@ CVE-2026-60107
 CVE-2026-60106
 	REJECTED
 CVE-2026-59911 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion o ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-59910 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Ne ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-59909 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Travers ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-59903 (Netty is an asynchronous, event-driven network application framework.  ...)
 	TODO: check
 CVE-2026-59902 (Netty is an asynchronous, event-driven network application framework.  ...)
@@ -195,27 +195,27 @@ CVE-2026-59894 (sqlparse is a non-validating SQL parser module for Python. Prior
 CVE-2026-59893 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
 	TODO: check
 CVE-2026-59829 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
-	TODO: check
+	NOT-FOR-US: Discourse
 CVE-2026-58561 (Null pointer dereference issue in the image codec module.Impact: Succe ...)
-	TODO: check
+	NOT-FOR-US: Huawei
 CVE-2026-58560 (Null pointer dereference issue in the image codec module.Impact: Succe ...)
-	TODO: check
+	NOT-FOR-US: Huawei
 CVE-2026-56686 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Ne ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-56685 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Ne ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-56090 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolle ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-56089 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Travers ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-55704 (Discourse is an open-source discussion platform. Prior o 2026.1.6, 202 ...)
-	TODO: check
+	NOT-FOR-US: Discourse
 CVE-2026-55674 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
-	TODO: check
+	NOT-FOR-US: Discourse
 CVE-2026-54284 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
 	TODO: check
 CVE-2026-53960 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
-	TODO: check
+	NOT-FOR-US: Discourse
 CVE-2026-51346 (SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x bef ...)
 	TODO: check
 CVE-2026-50776 (Directory Traversal vulnerability in Pronis Loisirs Billetterie CSE -  ...)
@@ -237,55 +237,55 @@ CVE-2026-50769 (The CRM+ application before and including version 2025.6 from Br
 CVE-2026-50768 (File Upload vulnerability in T-Systems International GmbH ImageMaster  ...)
 	TODO: check
 CVE-2026-49308 (Permission control vulnerability in the clipboard module.Impact: Succe ...)
-	TODO: check
+	NOT-FOR-US: Huawei
 CVE-2026-49307 (Permission control vulnerability in the multi-mode input module.Impact ...)
-	TODO: check
+	NOT-FOR-US: Huawei
 CVE-2026-49306 (UAF vulnerability in the time and time zone module.Impact: Successful  ...)
-	TODO: check
+	NOT-FOR-US: Huawei
 CVE-2026-49305 (Permission control vulnerability in the Wi-Fi enhancement module.Impac ...)
-	TODO: check
+	NOT-FOR-US: Huawei
 CVE-2026-49304 (Permission control vulnerability in the device key management module.I ...)
-	TODO: check
+	NOT-FOR-US: Huawei
 CVE-2026-49303 (Permission control vulnerability in the notification module.Impact: Su ...)
-	TODO: check
+	NOT-FOR-US: Huawei
 CVE-2026-49302 (Permission control vulnerability in the notification service module.Im ...)
-	TODO: check
+	NOT-FOR-US: Huawei
 CVE-2026-49301 (Permission control vulnerability in the Gallery module.Impact: Success ...)
-	TODO: check
+	NOT-FOR-US: Huawei
 CVE-2026-48053 (Kolibri is an offline-first education platform. Prior to version 0.19. ...)
 	TODO: check
 CVE-2026-46345 (compliance-trestle is a tooling platform for managing compliance as co ...)
 	TODO: check
 CVE-2026-40145 (A vulnerability exists in the interaction between a Endpoint Privilege ...)
-	TODO: check
+	NOT-FOR-US: BeyondTrust
 CVE-2026-40144 (A memory-corruption vulnerability exists in a kernel-mode component of ...)
-	TODO: check
+	NOT-FOR-US: BeyondTrust
 CVE-2026-40126 (OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scri ...)
 	TODO: check
 CVE-2026-33437 (Stirling-PDF is a locally hosted web application that facilitates vari ...)
 	TODO: check
 CVE-2026-20000 (A vulnerability was detected in itsourcecode Hospital Management Syste ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-19999 (A security vulnerability has been detected in Open Asset Import Librar ...)
 	TODO: check
 CVE-2026-19998 (A weakness has been identified in code-projects Online Shopping System ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2026-19693 (extract-zip through 2.0.1 containment-checks only the parent directory ...)
 	TODO: check
 CVE-2026-18674 (On a Kong Mesh global control plane, resources received over the zone- ...)
 	TODO: check
 CVE-2026-17639 (Certain HP Smart Tank All-in-One printers may be potentially vulnerabl ...)
-	TODO: check
+	NOT-FOR-US: HP
 CVE-2026-16471 (Missing Authorization vulnerability in Dolusoft Software Technologies  ...)
 	TODO: check
 CVE-2026-16467 (Missing Authorization vulnerability in Dolusoft Software Technologies  ...)
 	TODO: check
 CVE-2026-16139 (In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and  ...)
-	TODO: check
+	NOT-FOR-US: Progress Software
 CVE-2026-16138 (In Progress ShareFile Storage Zones Controller v5.12.5 and below versi ...)
-	TODO: check
+	NOT-FOR-US: Progress Software
 CVE-2026-16137 (In Progress ShareFile Storage Zones Controller v5.12.5 and below, a pa ...)
-	TODO: check
+	NOT-FOR-US: Progress Software
 CVE-2026-16049 (Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The Mattermost G ...)
 	TODO: check
 CVE-2026-16048 (Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10. ...)
@@ -305,15 +305,15 @@ CVE-2026-15218 (A flaw was found in the maas-api and maas-controller ServiceAcco
 CVE-2026-14564 (Insufficiently Protected Credentials vulnerability in Innotim Software ...)
 	TODO: check
 CVE-2026-13202 (A vulnerability in OpenText Opentext Directory Services allows Input D ...)
-	TODO: check
+	NOT-FOR-US: OpenText
 CVE-2026-12630 (Zephyr's 6LoWPAN IP Header Compression (IPHC) uncompression code conta ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-12629 (The ARM PL011 UART driver in drivers/serial/uart_pl011.c fails to ackn ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-12553 (HP has identified a potential vulnerability in HP Web Jetadmin (WJA) t ...)
-	TODO: check
+	NOT-FOR-US: HP
 CVE-2026-12519 (The WNC-M14A2A LTE-M modem driver mishandles unsolicited %NOTIFYEV: ev ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-10527 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 1 ...)
 	TODO: check
 CVE-2025-27772 (UpTrain is an open-source platform to evaluate and improve generative  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bdb3893cef07598bd195575cbf6d48cc56307606

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bdb3893cef07598bd195575cbf6d48cc56307606
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260817/31c97ad7/attachment.htm>


More information about the debian-security-tracker-commits mailing list