[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Aug 20 07:12:30 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
88b3181f by Salvatore Bonaccorso at 2026-08-20T08:05:05+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -310,9 +310,9 @@ CVE-2026-63633 (FreeRDP is a free implementation of the Remote Desktop Protocol.
NOTE: https://github.com/FreeRDP/FreeRDP/pull/12993
NOTE: Fixed by: https://github.com/FreeRDP/FreeRDP/commit/0ed1f95d36913581cf31124f94eb5843d4263eae (3.28.0)
CVE-2026-63408 (Grav API Plugin is a RESTful API for Grav CMS that provides full headl ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-63407 (Grav API Plugin is a RESTful API for Grav CMS that provides full headl ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-63117 (FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...)
- freerdp3 3.28.0+dfsg-1
- freerdp2 <removed>
@@ -320,27 +320,27 @@ CVE-2026-63117 (FreeRDP is a free implementation of the Remote Desktop Protocol.
NOTE: https://github.com/FreeRDP/FreeRDP/pull/12980
NOTE: Fixed by: https://github.com/FreeRDP/FreeRDP/commit/b78fc0b138fe8f08a8b102e193ffb32986f4449a (3.28.0)
CVE-2026-62682 (Orval generates type-safe JavaScript clients in TypeScript from OpenAP ...)
- TODO: check
+ NOT-FOR-US: Orval
CVE-2026-62681 (Orval generates type-safe JavaScript clients in TypeScript from OpenAP ...)
- TODO: check
+ NOT-FOR-US: Orval
CVE-2026-62680 (Orval generates type-safe JavaScript clients in TypeScript from OpenAP ...)
- TODO: check
+ NOT-FOR-US: Orval
CVE-2026-62673 (Grav is a file-based Web platform. Prior to 2.0.4, the Grav .htaccess ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-62672 (Grav is a file-based Web platform. Prior to 2.0.4, Grav allowlists the ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-62671 (Grav Login Plugin adds login, basic ACL, and session wide messages to ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-62670 (Grav Flex Objects Plugin allows you to build custom collections of obj ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-62669 (Grav Login Plugin adds login, basic ACL, and session wide messages to ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-62668 (Grav API Plugin is a RESTful API for Grav CMS that provides full headl ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-62667 (Grav API Plugin is a RESTful API for Grav CMS that provides full headl ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-62666 (Grav API Plugin is a RESTful API for Grav CMS that provides full headl ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-61986 (Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0. ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-61842 (Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig conte ...)
@@ -3540,7 +3540,7 @@ CVE-2026-67921 (Cross-Site Request Forgery (CSRF) vulnerability exists in Halo C
CVE-2026-67920 (An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary ...)
NOT-FOR-US: Halo CMS
CVE-2026-67846 (Berkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41380057a2eb ...)
- TODO: check
+ NOT-FOR-US: Berkeley Out-of-Order Machine (BOOM)
CVE-2026-67271 (Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability i ...)
NOT-FOR-US: Dell / EMC
CVE-2026-67262 (Dell PowerStore contains a Missing Authorization vulnerability. An att ...)
@@ -3605,13 +3605,13 @@ CVE-2026-66046 (Expat through 2.8.3 contains a denial of service vulnerability c
CVE-2026-65959 (Vitess is a database clustering system for horizontal scaling of MySQL ...)
NOT-FOR-US: Vitess
CVE-2026-63643 (MagicMirror\xb2 is an open source modular smart mirror platform. Prior ...)
- TODO: check
+ NOT-FOR-US: MagicMirror
CVE-2026-63642 (MagicMirror\xb2 is an open source modular smart mirror platform. Prior ...)
- TODO: check
+ NOT-FOR-US: MagicMirror
CVE-2026-63641 (MagicMirror\xb2 is an open source modular smart mirror platform. Prior ...)
- TODO: check
+ NOT-FOR-US: MagicMirror
CVE-2026-63640 (MagicMirror\xb2 is an open source modular smart mirror platform. Prior ...)
- TODO: check
+ NOT-FOR-US: MagicMirror
CVE-2026-63639 (Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8 ...)
TODO: check
CVE-2026-63632 (Open Neural Network Exchange (ONNX) is an open standard for machine le ...)
@@ -3640,7 +3640,7 @@ CVE-2026-63335 (The RabbitMQ Java client library allows Java and JVM-based appli
CVE-2026-63328 (Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata ...)
TODO: check
CVE-2026-62684 (File Browser is a file managing interface for uploading, deleting, pre ...)
- TODO: check
+ NOT-FOR-US: File Browser
CVE-2026-62357 (Dragonfly is an in-memory data store built for modern application work ...)
TODO: check
CVE-2026-61696 (Forem is open source software for building communities. In versions be ...)
@@ -4196,7 +4196,7 @@ CVE-2026-63667 (ApostropheCMS is an open-source Node.js content management syste
CVE-2026-63409 (Deskflow is a keyboard and mouse sharing app. From 1.17.0 until contin ...)
TODO: check
CVE-2026-63178 (Onyx is an open-source AI platform. Prior to 4.3.0, Onyx Enterprise Ed ...)
- TODO: check
+ NOT-FOR-US: Onyx
CVE-2026-57485 (Stirling-PDF is a locally hosted web application that facilitates vari ...)
TODO: check
CVE-2026-57233 (Notepad++ is a free and open-source source code editor. Prior to 8.9.7 ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/88b3181f563f05a85c45f3a20b0392b2a6e13c49
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/88b3181f563f05a85c45f3a20b0392b2a6e13c49
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260820/ff60a24c/attachment.htm>
More information about the debian-security-tracker-commits
mailing list