[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Aug 20 08:52:34 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d6fd7965 by Salvatore Bonaccorso at 2026-08-20T09:23:06+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1019,15 +1019,15 @@ CVE-2026-62666 (Grav API Plugin is a RESTful API for Grav CMS that provides full
CVE-2026-61986 (Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0. ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-61842 (Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig conte ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-61807 (Snipe-IT is an IT asset/license management system. Prior to 8.6.2, a s ...)
TODO: check
CVE-2026-61690 (Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::e ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-61607 (Grav API Plugin is a RESTful API for Grav CMS that provides full headl ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-61518 (ISPConfig contains an authenticated SQL injection vulnerability in the ...)
- TODO: check
+ NOT-FOR-US: ISPConfig
CVE-2026-58565 (Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing ...)
NOT-FOR-US: Dell / EMC
CVE-2026-58564 (Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorre ...)
@@ -1035,21 +1035,21 @@ CVE-2026-58564 (Dell Command Update (DCU), versions prior to 5.7.1, contain an I
CVE-2026-58562 (Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing ...)
NOT-FOR-US: Dell / EMC
CVE-2026-58088 (The ELF core dump code counted the number of dumpable VM map entries, ...)
- TODO: check
+ NOT-FOR-US: FreeBSD
CVE-2026-58087 (The GETALL and SETALL commands in semctl(2) recorded the number of sem ...)
- TODO: check
+ NOT-FOR-US: FreeBSD
CVE-2026-58086 (As an inadvertent side effect of an unrelated code change, PRIV_KTRACE ...)
- TODO: check
+ NOT-FOR-US: FreeBSD
CVE-2026-58085 (After dispatching a decrypt operation to OCF and receiving the result, ...)
- TODO: check
+ NOT-FOR-US: FreeBSD
CVE-2026-58084 (To retrieve the previous timer value, the kernel calls realtimer_getti ...)
- TODO: check
+ NOT-FOR-US: FreeBSD
CVE-2026-58083 (While the kernel was copying knotes during fork, a knote with a timer- ...)
- TODO: check
+ NOT-FOR-US: FreeBSD
CVE-2026-58082 (The ISO-2022 encoding module used a stack buffer sized to MB_LEN_MAX ( ...)
- TODO: check
+ NOT-FOR-US: FreeBSD
CVE-2026-58081 (Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not p ...)
- TODO: check
+ NOT-FOR-US: FreeBSD
CVE-2026-56797 (Dell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Ti ...)
NOT-FOR-US: Dell / EMC
CVE-2026-56796 (Dell Command Update (DCU), versions prior to 5.7.1, contain an Imprope ...)
@@ -3213,7 +3213,7 @@ CVE-2026-60391 (Vulnerability in the Oracle Hyperion Financial Reporting product
CVE-2026-59915 (Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, con ...)
NOT-FOR-US: Dell / EMC
CVE-2026-57826 (An issue was discovered in openHiTLS 0.2.0 through 0.3.2. In the X.509 ...)
- TODO: check
+ NOT-FOR-US: openHiTLS
CVE-2026-56874
REJECTED
CVE-2026-56873
@@ -4325,9 +4325,9 @@ CVE-2026-63328 (Trivy is a security scanner. Prior to 0.72.0, plugin manifest me
CVE-2026-62684 (File Browser is a file managing interface for uploading, deleting, pre ...)
NOT-FOR-US: File Browser
CVE-2026-62357 (Dragonfly is an in-memory data store built for modern application work ...)
- TODO: check
+ NOT-FOR-US: Dragonfly
CVE-2026-61696 (Forem is open source software for building communities. In versions be ...)
- TODO: check
+ NOT-FOR-US: Forem
CVE-2026-61634 (The RabbitMQ Java client library allows Java and JVM-based application ...)
- rabbitmq-java-client <unfixed>
NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-5xwg-cfvj-gff5
@@ -4336,7 +4336,7 @@ CVE-2026-61634 (The RabbitMQ Java client library allows Java and JVM-based appli
NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/1995
NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/b491075f42e89967610c40beded68d3680cfd472 (v5.33.0)
CVE-2026-61574 (authentik is an open-source identity provider. Prior to 2026.2.6 and 2 ...)
- TODO: check
+ NOT-FOR-US: authentik
CVE-2026-61407 (Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Expose ...)
NOT-FOR-US: Dell / EMC
CVE-2026-5224 (Cleartext storage of sensitive information vulnerability in Kriptok Cr ...)
@@ -4344,14 +4344,14 @@ CVE-2026-5224 (Cleartext storage of sensitive information vulnerability in Kript
CVE-2026-59949 (yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JN ...)
TODO: check
CVE-2026-59940 (Seroval facilitates JS value stringification, including complex struct ...)
- TODO: check
+ NOT-FOR-US: Seroval
CVE-2026-59825 (Mastodon is a free, open-source social network server based on Activit ...)
TODO: check
CVE-2026-59781 (When Zabbix Agent was installed on Windows into a custom installation ...)
- zabbix <not-affected> (Windows-specific)
NOTE: https://support.zabbix.com/browse/ZBX-28077
CVE-2026-57580 (authentik is an open-source identity provider. Prior to 2026.2.6 and 2 ...)
- TODO: check
+ NOT-FOR-US: authentik
CVE-2026-56684 (Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8 ...)
TODO: check
CVE-2026-55839 (Kestra is an open-source, event-driven orchestration platform. Prior t ...)
@@ -4883,11 +4883,11 @@ CVE-2026-63409 (Deskflow is a keyboard and mouse sharing app. From 1.17.0 until
CVE-2026-63178 (Onyx is an open-source AI platform. Prior to 4.3.0, Onyx Enterprise Ed ...)
NOT-FOR-US: Onyx
CVE-2026-57485 (Stirling-PDF is a locally hosted web application that facilitates vari ...)
- TODO: check
+ NOT-FOR-US: Stirling-PDF
CVE-2026-57233 (Notepad++ is a free and open-source source code editor. Prior to 8.9.7 ...)
- TODO: check
+ NOT-FOR-US: Notepad++
CVE-2026-56677 (9Router is an AI router & token saver. In 0.5.4 and earlier, the POST ...)
- TODO: check
+ NOT-FOR-US: 9Router
CVE-2026-54758 (Notepad++ is a free and open-source source code editor. Prior to 8.9.7 ...)
TODO: check
CVE-2026-54385
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d6fd796520d4216f1f64b6f454c45d271b8edcf5
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d6fd796520d4216f1f64b6f454c45d271b8edcf5
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260820/e0fe6258/attachment.htm>
More information about the debian-security-tracker-commits
mailing list