[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Aug 19 07:36:30 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e2b65a79 by Moritz Muehlenhoff at 2026-08-19T08:35:39+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1034,7 +1034,7 @@ CVE-2026-1199 (Zabbix API and Frontend login lockout mechanism has a flaw where
 CVE-2026-19869 (@neo4j/graphqlfrom5.2.0until the patched versions fails to enforce fie ...)
 	TODO: check
 CVE-2026-19608 (A flaw was found in the group policy provider of Keycloak authorizatio ...)
-	TODO: check
+	NOT-FOR-US: Red Hat build of Keycloak
 CVE-2026-19501 (CSV export functionality in Brainstorm Force SureForms version, <= 2.1 ...)
 	TODO: check
 CVE-2026-19500 (The Entries component in Brainstorm Force SureForms version, less than ...)
@@ -1042,7 +1042,7 @@ CVE-2026-19500 (The Entries component in Brainstorm Force SureForms version, les
 CVE-2026-19447 (Improper neutralization of input during web page generation ('cross-si ...)
 	TODO: check
 CVE-2026-18963 (A flaw was found in the reset-credentials flow of the keycloak-service ...)
-	TODO: check
+	NOT-FOR-US: Red Hat build of Keycloak
 CVE-2026-18929 (Carbone is vulnerable to Denial of Service due to lack of protection a ...)
 	TODO: check
 CVE-2026-18751 (External control of file name or path vulnerability in Citrix WorkSpac ...)
@@ -1086,7 +1086,7 @@ CVE-2026-15806 (The HTTPPasswordMgr class in the urllib.request module, along wi
 CVE-2026-15585 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
 	TODO: check
 CVE-2026-12564 (A flaw was found in the AAP Controller's HashiCorp Vault credential pl ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2025-9211 (Unescaped stored values in application security page in Otalio Ship Pr ...)
 	TODO: check
 CVE-2025-9210 (Missing signature validation in JSON Web Tokens in Otalio Ship Propert ...)
@@ -10081,7 +10081,7 @@ CVE-2026-18844 (The firmware of thePulsetto Vagus Nerve Stimulatoraccepts severa
 CVE-2026-18789 (The Ezoic WordPress plugin before 2.23.1 does not properly restrict ac ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-18710 (A MongoDB driver component could write sensitive configuration informa ...)
-	TODO: check
+	- mongodb <removed>
 CVE-2026-18634 (An insecure handling of serialized objects vulnerability was found in  ...)
 	NOT-FOR-US: SonicWall
 CVE-2026-18474 (The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise a ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e2b65a79d570a3f752f3a0d6e8ed47ae8f20a1c0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e2b65a79d570a3f752f3a0d6e8ed47ae8f20a1c0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260819/a11fee9d/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list