[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 17 20:56:08 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
2011e0dd by Salvatore Bonaccorso at 2026-08-17T21:55:37+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -127,29 +127,29 @@ CVE-2026-74253 (Joomla Extension - regularlabs.com - Unauthenticated RCE through
 CVE-2026-74238 (TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerabil ...)
 	NOT-FOR-US: TIER IV Nebula
 CVE-2026-73851 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1  ...)
-	TODO: check
+	NOT-FOR-US: Kiota
 CVE-2026-73646 (PostCSS takes a CSS file and provides an API to analyze and modify its ...)
 	TODO: check
 CVE-2026-73523 (COVESA Open1722 through 0.9.2 contains an integer truncation vulnerabi ...)
-	TODO: check
+	NOT-FOR-US: COVESA Open1722
 CVE-2026-73522 (COVESA Open1722 through 0.9.2 contains a stack buffer overflow vulnera ...)
-	TODO: check
+	NOT-FOR-US: COVESA Open1722
 CVE-2026-73424 (Astro is a web framework for content-driven websites. From 10.0.3 unti ...)
-	TODO: check
+	NOT-FOR-US: Astro
 CVE-2026-71980 (Belledonne Communications bcg729 through 1.1.2 contains an out-of-boun ...)
-	TODO: check
+	NOT-FOR-US: Belledonne Communications bcg729
 CVE-2026-71979 (INDI (Instrument Neutral Distributed Interface) indiserver through 2.2 ...)
-	TODO: check
+	NOT-FOR-US: INDI (Instrument Neutral Distributed Interface) indiserver
 CVE-2026-71693
 	REJECTED
 CVE-2026-71567 (Inopenshift-metal3/fakefish there is a repeated pattern in some of the ...)
-	TODO: check
+	NOT-FOR-US: openshift-metal3/fakefish
 CVE-2026-71566 (FakeFish handles incoming credentials by passing them down  to scripts ...)
-	TODO: check
+	NOT-FOR-US: FakeFish
 CVE-2026-71491 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
 	TODO: check
 CVE-2026-71479 (New API is a large language mode (LLM) gateway and artificial intellig ...)
-	TODO: check
+	NOT-FOR-US: New API
 CVE-2026-70412 (Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version p ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-68762 (In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket deco ...)
@@ -163,15 +163,15 @@ CVE-2026-68518 (Glances is an open-source system cross-platform monitoring tool.
 CVE-2026-68517 (Glances is an open-source system cross-platform monitoring tool. Prior ...)
 	TODO: check
 CVE-2026-66792 (A flaw was found in the multicloud-operators-subscription component. T ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Multicluster Global Hub
 CVE-2026-64868 (New API is a large language mode (LLM) gateway and artificial intellig ...)
-	TODO: check
+	NOT-FOR-US: New API
 CVE-2026-64866 (New API is a large language mode (LLM) gateway and artificial intellig ...)
-	TODO: check
+	NOT-FOR-US: New API
 CVE-2026-64865 (New API is a large language mode (LLM) gateway and artificial intellig ...)
-	TODO: check
+	NOT-FOR-US: New API
 CVE-2026-64859 (New API is a large language mode (LLM) gateway and artificial intellig ...)
-	TODO: check
+	NOT-FOR-US: New API
 CVE-2026-62982 (Glances is an open-source system cross-platform monitoring tool. From  ...)
 	TODO: check
 CVE-2026-61666 (websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...)
@@ -217,13 +217,13 @@ CVE-2026-54284 (sqlparse is a non-validating SQL parser module for Python. Prior
 CVE-2026-53960 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
 	NOT-FOR-US: Discourse
 CVE-2026-51346 (SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x bef ...)
-	TODO: check
+	NOT-FOR-US: StudIP
 CVE-2026-50776 (Directory Traversal vulnerability in Pronis Loisirs Billetterie CSE -  ...)
-	TODO: check
+	NOT-FOR-US: Pronis Loisirs Billetterie CSE
 CVE-2026-50775 (A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to e ...)
-	TODO: check
+	NOT-FOR-US: DataHub
 CVE-2026-50774 (An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate ...)
-	TODO: check
+	NOT-FOR-US: GAPTEQ Designer
 CVE-2026-50773 (An issue in CGM Germany - CompuGroup Medical CGM ISIS MED 2510.1.0.20  ...)
 	TODO: check
 CVE-2026-50772 (An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2011e0dd8a6ad4dd0888ba00802ce1a37869df4b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2011e0dd8a6ad4dd0888ba00802ce1a37869df4b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260817/7acab0c3/attachment.htm>


More information about the debian-security-tracker-commits mailing list