[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 19 08:04:21 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8e862571 by Salvatore Bonaccorso at 2026-08-19T09:04:09+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -676,13 +676,13 @@ CVE-2026-71551 (Super Productivity is an advanced todo list app with integrated
 CVE-2026-71539 (n8n is an open source workflow automation platform. Prior to 1.123.64, ...)
 	NOT-FOR-US: n8n
 CVE-2026-71477 (mise manages dev tools like node, python, cmake, and terraform. Prior  ...)
-	TODO: check
+	NOT-FOR-US: mise
 CVE-2026-71365 (A server-side request forgery (SSRF) vulnerability was found in AWX's  ...)
 	TODO: check
 CVE-2026-70667 (Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_revo ...)
 	- lemur <itp> (bug #809533)
 CVE-2026-70657 (Copyparty is a portable file server. Prior to 1.20.17, copyparty volum ...)
-	TODO: check
+	NOT-FOR-US: Copyparty
 CVE-2026-70415 (Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of  ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-69220 (The RabbitMQ Java client library allows Java and JVM-based application ...)
@@ -700,9 +700,9 @@ CVE-2026-69219 (The RabbitMQ Java client library allows Java and JVM-based appli
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/2008
 	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/388209356c6478088efce4d8a07b68e73837a7a0 (v5.33.1)
 CVE-2026-69189 (Hoppscotch is an open source API development ecosystem. Prior to 2026. ...)
-	TODO: check
+	NOT-FOR-US: Hoppscotch
 CVE-2026-69160 (OpenList a file list program that supports multiple storage. Prior to  ...)
-	TODO: check
+	NOT-FOR-US: OpenList
 CVE-2026-68939 (Pyenv provides simple Python version management. Prior to 2.8.0, is_ve ...)
 	- pyenv <unfixed>
 	NOTE: https://github.com/pyenv/pyenv/security/advisories/GHSA-g478-f579-9vp9



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8e862571fa13cd91959b82e3a46e6ca34c82435d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8e862571fa13cd91959b82e3a46e6ca34c82435d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260819/9c060f69/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list