[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 18 08:13:58 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1f82ed6d by security tracker role at 2026-08-18T07:13:46+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -21,7 +21,7 @@ CVE-2026-75480 (OpenViking debug vector scroll and count endpoints apply only ac
 CVE-2026-75479 (JimuReport contains an authentication bypass vulnerability in the repo ...)
 	TODO: check
 CVE-2026-75151 (A vulnerability has been found in SourceCodester Onlne Examination & L ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-75111 (Evidently UI fails to properly validate the filename parameter in the  ...)
 	TODO: check
 CVE-2026-75110 (MemOS is a memory operating system for LLMs and AI agents. In deployme ...)
@@ -43,35 +43,35 @@ CVE-2026-75094 (A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts t
 CVE-2026-75093 (A security vulnerability has been detected in sonos tract up to 0.23.4 ...)
 	TODO: check
 CVE-2026-75091 (The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes p ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-75090 (A vulnerability was detected in EricLBuehler Mistral.rs up to 0.8.22.  ...)
 	TODO: check
 CVE-2026-75089 (A weakness has been identified in PHPGurukul Complaint Management Syst ...)
-	TODO: check
+	NOT-FOR-US: PHPGurukul
 CVE-2026-75088 (A vulnerability was determined in itsourcecode Hospital Management Sys ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-75087 (A vulnerability was found in itsourcecode Hospital Management System 1 ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-75086 (A vulnerability has been found in itsourcecode Hospital Management Sys ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-75082 (A flaw has been found in Webkul Bagisto up to 2.4.4. The affected elem ...)
 	TODO: check
 CVE-2026-75081 (A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted i ...)
 	TODO: check
 CVE-2026-75080 (A security vulnerability has been detected in SourceCodester Class and ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-75079 (A weakness has been identified in SourceCodester Class and Exam Timeta ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-75078 (A security flaw has been discovered in SourceCodester Class and Exam T ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-75077 (A vulnerability was identified in SourceCodester Class and Exam Timeta ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-75014 (A flaw has been found in SourceCodester Pet Grooming Management Softwa ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-75013 (A vulnerability was detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-75012 (A security vulnerability has been detected in TOTOLINK EX1200L 9.3.5u. ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-74234 (Legora before 2026-08-14 contains a cross-site scripting vulnerability ...)
 	TODO: check
 CVE-2026-73560 (vLLM is an inference and serving engine for large language models. Pri ...)
@@ -93,9 +93,9 @@ CVE-2026-71424 (Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and
 CVE-2026-70495 (A flaw was found in search-v2-operator. This component's `search-servi ...)
 	TODO: check
 CVE-2026-69148 (MLflow is an open source AI engineering platform for agents, large lan ...)
-	TODO: check
+	NOT-FOR-US: mlflow
 CVE-2026-69146 (MLflow is an open source AI engineering platform for agents, large lan ...)
-	TODO: check
+	NOT-FOR-US: mlflow
 CVE-2026-68765 (hashcat master branch builds after v7.1.2 contain a heap buffer overfl ...)
 	TODO: check
 CVE-2026-68005 (An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to ...)
@@ -103,9 +103,9 @@ CVE-2026-68005 (An issue in ACME mini_httpd 1.30 and prior allows a remote attac
 CVE-2026-68004 (An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remo ...)
 	TODO: check
 CVE-2026-67967 (Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-67966 (Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthentic ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-67965 (An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to e ...)
 	TODO: check
 CVE-2026-67961 (An issue in O2OA v.10.0.2 allows a local attacker to execute arbitrary ...)
@@ -141,63 +141,63 @@ CVE-2026-65822 (ERPNext is a free and open source Enterprise Resource Planning t
 CVE-2026-65640 (WordPress is vulnerable to a remote code execution vulnerability via m ...)
 	TODO: check
 CVE-2026-65351 (This issue was addressed through improved state management. This issue ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-65349 (An out-of-bounds read was addressed with improved input validation. Th ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-65347 (The issue was addressed with improved checks. This issue is fixed in i ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-65346 (An integer overflow was addressed with improved input validation. This ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-65343 (A use after free issue was addressed with improved memory management.  ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-65341 (The issue was addressed with improved memory handling. This issue is f ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-65340 (This issue was addressed through improved state management. This issue ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-65339 (A logic issue was addressed with improved checks. This issue is fixed  ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-65338 (The issue was addressed with improved memory handling. This issue is f ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-65337 (This issue was addressed through improved state management. This issue ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-65336 (This issue was addressed through improved state management. This issue ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-65335 (This issue was addressed through improved state management. This issue ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-65334 (A memory corruption issue was addressed with improved state management ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-65333 (This issue was addressed through improved state management. This issue ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-65332 (This issue was addressed through improved state management. This issue ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-65331 (This issue was addressed through improved state management. This issue ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-65330 (The issue was addressed with improved memory handling. This issue is f ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-65329 (An authentication issue was addressed with improved state management.  ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-64849 (MLflow is an open source AI engineering platform for agents, large lan ...)
-	TODO: check
+	NOT-FOR-US: mlflow
 CVE-2026-64788 (The issue was addressed with improved memory handling. This issue is f ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-64787 (A use-after-free issue was addressed with improved memory management.  ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-64784 (An out-of-bounds access issue was addressed with improved bounds check ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-64782 (A memory corruption vulnerability was addressed with improved locking. ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-64781 (The issue was addressed with improved input validation. This issue is  ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-64780 (The issue was addressed with improved checks. This issue is fixed in i ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-64779 (A memory corruption vulnerability was addressed with improved locking. ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-64778 (The issue was addressed with improved checks. This issue is fixed in i ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-64760 (An information leakage was addressed with additional validation. This  ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-64715 (A use-after-free issue was addressed with improved memory management.  ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-64657 (Budibase is an open-source low-code platform. Prior to 3.39.19, the Po ...)
 	TODO: check
 CVE-2026-63670 (ApostropheCMS is an open-source Node.js content management system. Pri ...)
@@ -243,11 +243,11 @@ CVE-2026-44846 (JumpServer is an open source bastion host and an operation and m
 CVE-2026-44845 (JumpServer is an open source bastion host and an operation and mainten ...)
 	TODO: check
 CVE-2026-43795 (The issue was addressed with improved memory handling. This issue is f ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-43794 (A memory corruption issue was addressed with improved memory handling. ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-43667 (A reachable assertion was addressed with improved input validation. Th ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-42164 (Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/sect ...)
 	TODO: check
 CVE-2026-42163 (Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access ...)
@@ -255,7 +255,7 @@ CVE-2026-42163 (Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized
 CVE-2026-42162 (Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being acc ...)
 	TODO: check
 CVE-2026-40506 (OpenEMR before 8.2.0 contains a path traversal vulnerability in the st ...)
-	TODO: check
+	NOT-FOR-US: OpenEMR
 CVE-2026-39255 (Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allo ...)
 	TODO: check
 CVE-2026-39254 (Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allo ...)
@@ -263,7 +263,7 @@ CVE-2026-39254 (Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.
 CVE-2026-38165 (A Server-Side Template Injection (SSTI) vulnerability in the Velocity  ...)
 	TODO: check
 CVE-2026-35219 (Budibase is an open-source low-code platform. Prior to 3.41.3, automat ...)
-	TODO: check
+	NOT-FOR-US: n8n
 CVE-2026-34789 (FreeCAD is a free and open-source multiplatform 3D parametric modeler. ...)
 	TODO: check
 CVE-2026-34399 (FreeCAD is a free and open-source multiplatform 3D parametric modeler. ...)
@@ -271,21 +271,21 @@ CVE-2026-34399 (FreeCAD is a free and open-source multiplatform 3D parametric mo
 CVE-2026-34398 (FreeCAD is a free and open-source multiplatform 3D parametric modeler. ...)
 	TODO: check
 CVE-2026-28984 (The issue was addressed with improved memory handling. This issue is f ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-19650 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-19589 (Packer up to 1.15.4 is vulnerable to an issue in the third-party plugi ...)
 	TODO: check
 CVE-2026-19478 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-15748 (The Forminator Forms plugin for WordPress is vulnerable to Arbitrary F ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15371 (Velociraptor's web GUI allows specifying a custom type for columns in  ...)
-	TODO: check
+	NOT-FOR-US: Rapid7
 CVE-2026-11817 (This vulnerability only affects Grafana stacks configured with multipl ...)
 	TODO: check
 CVE-2026-11801 (The WPAdverts \u2013 Classifieds Plugin plugin for WordPress is vulner ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-10080 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 1 ...)
 	TODO: check
 CVE-2026-9771 (The flash_copy() system call is verified by z_vrfy_flash_copy() in dri ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1f82ed6dc40dc42b0d27d05bb64a2e634bba2ee7

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1f82ed6dc40dc42b0d27d05bb64a2e634bba2ee7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260818/b8134a74/attachment.htm>


More information about the debian-security-tracker-commits mailing list