[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 20 08:52:34 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d6fd7965 by Salvatore Bonaccorso at 2026-08-20T09:23:06+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1019,15 +1019,15 @@ CVE-2026-62666 (Grav API Plugin is a RESTful API for Grav CMS that provides full
 CVE-2026-61986 (Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0. ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61842 (Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig conte ...)
-	TODO: check
+	NOT-FOR-US: Grav CMS
 CVE-2026-61807 (Snipe-IT is an IT asset/license management system. Prior to 8.6.2, a s ...)
 	TODO: check
 CVE-2026-61690 (Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::e ...)
-	TODO: check
+	NOT-FOR-US: Grav CMS
 CVE-2026-61607 (Grav API Plugin is a RESTful API for Grav CMS that provides full headl ...)
-	TODO: check
+	NOT-FOR-US: Grav plugin
 CVE-2026-61518 (ISPConfig contains an authenticated SQL injection vulnerability in the ...)
-	TODO: check
+	NOT-FOR-US: ISPConfig
 CVE-2026-58565 (Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing  ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-58564 (Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorre ...)
@@ -1035,21 +1035,21 @@ CVE-2026-58564 (Dell Command Update (DCU), versions prior to 5.7.1, contain an I
 CVE-2026-58562 (Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing  ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-58088 (The ELF core dump code counted the number of dumpable VM map entries,  ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-58087 (The GETALL and SETALL commands in semctl(2) recorded the number of sem ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-58086 (As an inadvertent side effect of an unrelated code change, PRIV_KTRACE ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-58085 (After dispatching a decrypt operation to OCF and receiving the result, ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-58084 (To retrieve the previous timer value, the kernel calls realtimer_getti ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-58083 (While the kernel was copying knotes during fork, a knote with a timer- ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-58082 (The ISO-2022 encoding module used a stack buffer sized to MB_LEN_MAX ( ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-58081 (Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not p ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-56797 (Dell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Ti ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-56796 (Dell Command Update (DCU), versions prior to 5.7.1, contain an Imprope ...)
@@ -3213,7 +3213,7 @@ CVE-2026-60391 (Vulnerability in the Oracle Hyperion Financial Reporting product
 CVE-2026-59915 (Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, con ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-57826 (An issue was discovered in openHiTLS 0.2.0 through 0.3.2. In the X.509 ...)
-	TODO: check
+	NOT-FOR-US: openHiTLS
 CVE-2026-56874
 	REJECTED
 CVE-2026-56873
@@ -4325,9 +4325,9 @@ CVE-2026-63328 (Trivy is a security scanner. Prior to 0.72.0, plugin manifest me
 CVE-2026-62684 (File Browser is a file managing interface for uploading, deleting, pre ...)
 	NOT-FOR-US: File Browser
 CVE-2026-62357 (Dragonfly is an in-memory data store built for modern application work ...)
-	TODO: check
+	NOT-FOR-US: Dragonfly
 CVE-2026-61696 (Forem is open source software for building communities. In versions be ...)
-	TODO: check
+	NOT-FOR-US: Forem
 CVE-2026-61634 (The RabbitMQ Java client library allows Java and JVM-based application ...)
 	- rabbitmq-java-client <unfixed>
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-5xwg-cfvj-gff5
@@ -4336,7 +4336,7 @@ CVE-2026-61634 (The RabbitMQ Java client library allows Java and JVM-based appli
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/1995
 	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/b491075f42e89967610c40beded68d3680cfd472 (v5.33.0)
 CVE-2026-61574 (authentik is an open-source identity provider. Prior to 2026.2.6 and 2 ...)
-	TODO: check
+	NOT-FOR-US: authentik
 CVE-2026-61407 (Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Expose ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-5224 (Cleartext storage of sensitive information vulnerability in Kriptok Cr ...)
@@ -4344,14 +4344,14 @@ CVE-2026-5224 (Cleartext storage of sensitive information vulnerability in Kript
 CVE-2026-59949 (yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JN ...)
 	TODO: check
 CVE-2026-59940 (Seroval facilitates JS value stringification, including complex struct ...)
-	TODO: check
+	NOT-FOR-US: Seroval
 CVE-2026-59825 (Mastodon is a free, open-source social network server based on Activit ...)
 	TODO: check
 CVE-2026-59781 (When Zabbix Agent was installed on Windows into a custom installation  ...)
 	- zabbix <not-affected> (Windows-specific)
 	NOTE: https://support.zabbix.com/browse/ZBX-28077
 CVE-2026-57580 (authentik is an open-source identity provider. Prior to 2026.2.6 and 2 ...)
-	TODO: check
+	NOT-FOR-US: authentik
 CVE-2026-56684 (Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8 ...)
 	TODO: check
 CVE-2026-55839 (Kestra is an open-source, event-driven orchestration platform. Prior t ...)
@@ -4883,11 +4883,11 @@ CVE-2026-63409 (Deskflow is a keyboard and mouse sharing app. From 1.17.0 until
 CVE-2026-63178 (Onyx is an open-source AI platform. Prior to 4.3.0, Onyx Enterprise Ed ...)
 	NOT-FOR-US: Onyx
 CVE-2026-57485 (Stirling-PDF is a locally hosted web application that facilitates vari ...)
-	TODO: check
+	NOT-FOR-US: Stirling-PDF
 CVE-2026-57233 (Notepad++ is a free and open-source source code editor. Prior to 8.9.7 ...)
-	TODO: check
+	NOT-FOR-US: Notepad++
 CVE-2026-56677 (9Router is an AI router & token saver. In 0.5.4 and earlier, the POST  ...)
-	TODO: check
+	NOT-FOR-US: 9Router
 CVE-2026-54758 (Notepad++ is a free and open-source source code editor. Prior to 8.9.7 ...)
 	TODO: check
 CVE-2026-54385



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d6fd796520d4216f1f64b6f454c45d271b8edcf5

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d6fd796520d4216f1f64b6f454c45d271b8edcf5
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260820/e0fe6258/attachment.htm>


More information about the debian-security-tracker-commits mailing list