[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Aug 17 20:14:45 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
bdb3893c by security tracker role at 2026-08-17T19:14:39+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,9 +1,9 @@
CVE-2026-9771 (The flash_copy() system call is verified by z_vrfy_flash_copy() in dri ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-75060 (In JetBrains PyCharm before 2026.2.1 code execution was possible via u ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-75059 (In JetBrains PyCharm before 2026.2.1 code execution via Quick Document ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-75058 (In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Ecl ...)
TODO: check
CVE-2026-75057 (In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were writte ...)
@@ -19,21 +19,21 @@ CVE-2026-75053 (In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via
CVE-2026-75052 (In JetBrains IntelliJ IDEA before 2026.2.1 command execution via craft ...)
TODO: check
CVE-2026-75051 (In JetBrains YouTrack before 2026.2.17917 unauthorised project transfe ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-75050 (In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack wa ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-75049 (In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authentica ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-75048 (In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced co ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-75047 (In JetBrains YouTrack before 2026.2.18177 doS attack was possible via ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-75046 (In JetBrains YouTrack before 2026.2.18112 an authenticated user could ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-75045 (In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.181 ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-75044 (In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.180 ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-75011 (A flaw has been found in kylecui NetForensicMCP 2.1.0. Impacted is the ...)
TODO: check
CVE-2026-74901 (openssl_encrypt versions before 1.4.0 contain an authentication bypass ...)
@@ -99,31 +99,31 @@ CVE-2026-74870 (openssl_encrypt (pip) versions <= 1.4.7 contain an information e
CVE-2026-74869 (stoatchat before 0.15.0 contains a missing authorization vulnerability ...)
TODO: check
CVE-2026-74868 (SiYuan versions before 3.7.4 contain an unthrottled brute-force vulner ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-74867 (SiYuan versions before 3.7.4 contain a cross-site request forgery vuln ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-74858 (A vulnerability has been found in jae-jae fetcher-mcp up to 0.3.9. Imp ...)
TODO: check
CVE-2026-74845 (Official Document Management System developed by 2100 Technology has a ...)
TODO: check
CVE-2026-74843 (A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. ...)
- TODO: check
+ NOT-FOR-US: Wavlink
CVE-2026-74842 (A vulnerability was found in Kira-Pgr PromptShopMCP up to 5bc0cd17358e ...)
TODO: check
CVE-2026-74802 (SiYuan versions before 3.7.4 contain a cross-site WebSocket hijacking ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-74801 (SiYuan before 3.7.4 fails to properly escape workspace directory paths ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-74800 (SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Ty ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-74799 (SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints includ ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-74798 (SiYuan kernel before v3.7.4 contains a path traversal vulnerability in ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-74254 (Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3. ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-74253 (Joomla Extension - regularlabs.com - Unauthenticated RCE through unver ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-74238 (TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerabil ...)
TODO: check
CVE-2026-73851 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 ...)
@@ -151,9 +151,9 @@ CVE-2026-71491 (sqlparse is a non-validating SQL parser module for Python. Prior
CVE-2026-71479 (New API is a large language mode (LLM) gateway and artificial intellig ...)
TODO: check
CVE-2026-70412 (Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version p ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-68762 (In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket deco ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-68520 (Glances is an open-source system cross-platform monitoring tool. Prior ...)
TODO: check
CVE-2026-68519 (Glances is an open-source system cross-platform monitoring tool. Prior ...)
@@ -181,11 +181,11 @@ CVE-2026-60107
CVE-2026-60106
REJECTED
CVE-2026-59911 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion o ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-59910 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Ne ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-59909 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Travers ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-59903 (Netty is an asynchronous, event-driven network application framework. ...)
TODO: check
CVE-2026-59902 (Netty is an asynchronous, event-driven network application framework. ...)
@@ -195,27 +195,27 @@ CVE-2026-59894 (sqlparse is a non-validating SQL parser module for Python. Prior
CVE-2026-59893 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
TODO: check
CVE-2026-59829 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-58561 (Null pointer dereference issue in the image codec module.Impact: Succe ...)
- TODO: check
+ NOT-FOR-US: Huawei
CVE-2026-58560 (Null pointer dereference issue in the image codec module.Impact: Succe ...)
- TODO: check
+ NOT-FOR-US: Huawei
CVE-2026-56686 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Ne ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-56685 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Ne ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-56090 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolle ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-56089 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Travers ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-55704 (Discourse is an open-source discussion platform. Prior o 2026.1.6, 202 ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-55674 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-54284 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
TODO: check
CVE-2026-53960 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-51346 (SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x bef ...)
TODO: check
CVE-2026-50776 (Directory Traversal vulnerability in Pronis Loisirs Billetterie CSE - ...)
@@ -237,55 +237,55 @@ CVE-2026-50769 (The CRM+ application before and including version 2025.6 from Br
CVE-2026-50768 (File Upload vulnerability in T-Systems International GmbH ImageMaster ...)
TODO: check
CVE-2026-49308 (Permission control vulnerability in the clipboard module.Impact: Succe ...)
- TODO: check
+ NOT-FOR-US: Huawei
CVE-2026-49307 (Permission control vulnerability in the multi-mode input module.Impact ...)
- TODO: check
+ NOT-FOR-US: Huawei
CVE-2026-49306 (UAF vulnerability in the time and time zone module.Impact: Successful ...)
- TODO: check
+ NOT-FOR-US: Huawei
CVE-2026-49305 (Permission control vulnerability in the Wi-Fi enhancement module.Impac ...)
- TODO: check
+ NOT-FOR-US: Huawei
CVE-2026-49304 (Permission control vulnerability in the device key management module.I ...)
- TODO: check
+ NOT-FOR-US: Huawei
CVE-2026-49303 (Permission control vulnerability in the notification module.Impact: Su ...)
- TODO: check
+ NOT-FOR-US: Huawei
CVE-2026-49302 (Permission control vulnerability in the notification service module.Im ...)
- TODO: check
+ NOT-FOR-US: Huawei
CVE-2026-49301 (Permission control vulnerability in the Gallery module.Impact: Success ...)
- TODO: check
+ NOT-FOR-US: Huawei
CVE-2026-48053 (Kolibri is an offline-first education platform. Prior to version 0.19. ...)
TODO: check
CVE-2026-46345 (compliance-trestle is a tooling platform for managing compliance as co ...)
TODO: check
CVE-2026-40145 (A vulnerability exists in the interaction between a Endpoint Privilege ...)
- TODO: check
+ NOT-FOR-US: BeyondTrust
CVE-2026-40144 (A memory-corruption vulnerability exists in a kernel-mode component of ...)
- TODO: check
+ NOT-FOR-US: BeyondTrust
CVE-2026-40126 (OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scri ...)
TODO: check
CVE-2026-33437 (Stirling-PDF is a locally hosted web application that facilitates vari ...)
TODO: check
CVE-2026-20000 (A vulnerability was detected in itsourcecode Hospital Management Syste ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-19999 (A security vulnerability has been detected in Open Asset Import Librar ...)
TODO: check
CVE-2026-19998 (A weakness has been identified in code-projects Online Shopping System ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-19693 (extract-zip through 2.0.1 containment-checks only the parent directory ...)
TODO: check
CVE-2026-18674 (On a Kong Mesh global control plane, resources received over the zone- ...)
TODO: check
CVE-2026-17639 (Certain HP Smart Tank All-in-One printers may be potentially vulnerabl ...)
- TODO: check
+ NOT-FOR-US: HP
CVE-2026-16471 (Missing Authorization vulnerability in Dolusoft Software Technologies ...)
TODO: check
CVE-2026-16467 (Missing Authorization vulnerability in Dolusoft Software Technologies ...)
TODO: check
CVE-2026-16139 (In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-16138 (In Progress ShareFile Storage Zones Controller v5.12.5 and below versi ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-16137 (In Progress ShareFile Storage Zones Controller v5.12.5 and below, a pa ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-16049 (Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The Mattermost G ...)
TODO: check
CVE-2026-16048 (Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10. ...)
@@ -305,15 +305,15 @@ CVE-2026-15218 (A flaw was found in the maas-api and maas-controller ServiceAcco
CVE-2026-14564 (Insufficiently Protected Credentials vulnerability in Innotim Software ...)
TODO: check
CVE-2026-13202 (A vulnerability in OpenText Opentext Directory Services allows Input D ...)
- TODO: check
+ NOT-FOR-US: OpenText
CVE-2026-12630 (Zephyr's 6LoWPAN IP Header Compression (IPHC) uncompression code conta ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-12629 (The ARM PL011 UART driver in drivers/serial/uart_pl011.c fails to ackn ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-12553 (HP has identified a potential vulnerability in HP Web Jetadmin (WJA) t ...)
- TODO: check
+ NOT-FOR-US: HP
CVE-2026-12519 (The WNC-M14A2A LTE-M modem driver mishandles unsolicited %NOTIFYEV: ev ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-10527 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 1 ...)
TODO: check
CVE-2025-27772 (UpTrain is an open-source platform to evaluate and improve generative ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bdb3893cef07598bd195575cbf6d48cc56307606
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bdb3893cef07598bd195575cbf6d48cc56307606
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260817/31c97ad7/attachment.htm>
More information about the debian-security-tracker-commits
mailing list