[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Aug 20 13:40:55 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5d4f5b65 by Moritz Muehlenhoff at 2026-08-20T14:05:20+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -4392,7 +4392,7 @@ CVE-2026-63328 (Trivy is a security scanner. Prior to 0.72.0, plugin manifest me
 CVE-2026-62684 (File Browser is a file managing interface for uploading, deleting, pre ...)
 	NOT-FOR-US: File Browser
 CVE-2026-62357 (Dragonfly is an in-memory data store built for modern application work ...)
-	NOT-FOR-US: Dragonfly
+	NOT-FOR-US: DragonflyDB Dragonfly
 CVE-2026-61696 (Forem is open source software for building communities. In versions be ...)
 	NOT-FOR-US: Forem
 CVE-2026-61634 (The RabbitMQ Java client library allows Java and JVM-based application ...)
@@ -4440,33 +4440,33 @@ CVE-2026-55163 (Lemur manages TLS certificate creation. Prior to 1.9.2, PUT /api
 CVE-2026-55162 (Lemur manages TLS certificate creation. Prior to 1.9.2, lemur/certific ...)
 	- lemur <itp> (bug #809533)
 CVE-2026-55106 (authentik is an open-source identity provider. Prior to 2026.2.6 and 2 ...)
-	TODO: check
+	NOT-FOR-US: authentik
 CVE-2026-54730 (authentik is an open-source identity provider. Prior to 2026.2.6 and 2 ...)
-	TODO: check
+	NOT-FOR-US: authentik
 CVE-2026-54570 (AngleSharp is a .NET library for parsing angle bracket based hyper-tex ...)
-	TODO: check
+	NOT-FOR-US: AngleSharp
 CVE-2026-54552 (sh provides Python process launching. Prior to 2.2.4, the _uid option  ...)
 	TODO: check
 CVE-2026-53533 (aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior  ...)
 	TODO: check
 CVE-2026-52723 (ePA 3.x Integration implements the authorization workflow and writes M ...)
-	TODO: check
+	NOT-FOR-US: ePA3-Service-OpenSource
 CVE-2026-52610 (An arbitrary file write/directory traversal vulnerability in reportico ...)
-	TODO: check
+	NOT-FOR-US: reportico-web
 CVE-2026-52609 (A reflected cross-site scripting (XSS) vulnerability in reportico-web  ...)
-	TODO: check
+	NOT-FOR-US: reportico-web
 CVE-2026-52608 (An incorrect access control vulnerability in reportico-web <= 8.1.0 al ...)
-	TODO: check
+	NOT-FOR-US: reportico-web
 CVE-2026-52607 (A directory traversal vulnerability in reportico-web <= 8.1.0 allows r ...)
-	TODO: check
+	NOT-FOR-US: reportico-web
 CVE-2026-52606 (A reflected cross-site scripting (XSS) vulnerability in reportico-web  ...)
-	TODO: check
+	NOT-FOR-US: reportico-web
 CVE-2026-50578 (ePA 3.x Integration implements the authorization workflow and writes M ...)
-	TODO: check
+	NOT-FOR-US: ePA3-Service-OpenSource
 CVE-2026-50577 (ePA 3.x Integration implements the authorization workflow and writes M ...)
-	TODO: check
+	NOT-FOR-US: ePA3-Service-OpenSource
 CVE-2026-50576 (ePA 3.x Integration implements the authorization workflow and writes M ...)
-	TODO: check
+	NOT-FOR-US: ePA3-Service-OpenSource
 CVE-2026-50575 (BetterDesk is a remote desktop management solution. BetterDesk version ...)
 	TODO: check
 CVE-2026-50187 (Oh My Zsh is a community-driven framework for managing Zsh configurati ...)
@@ -4476,33 +4476,33 @@ CVE-2026-50167 (Kurrier is a modern, self-hosted workspace for email, calendar,
 CVE-2026-50161 (libre is a generic library for real-time communications with asynchron ...)
 	TODO: check
 CVE-2026-50143 (The Apify MCP server enables AI agents to extract data from websites u ...)
-	TODO: check
+	NOT-FOR-US: Apify MCP server
 CVE-2026-50139 (goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `Sh ...)
 	TODO: check
 CVE-2026-50138 (goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, whe ...)
 	TODO: check
 CVE-2026-50126 (Adaguc-server is an open source geographical information system to vis ...)
-	TODO: check
+	NOT-FOR-US: Vvveb
 CVE-2026-49228 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
-	TODO: check
+	NOT-FOR-US: Vvveb
 CVE-2026-49227 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
-	TODO: check
+	NOT-FOR-US: Vvveb
 CVE-2026-49226 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
-	TODO: check
+	NOT-FOR-US: Vvveb
 CVE-2026-49225 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
-	TODO: check
+	NOT-FOR-US: Vvveb
 CVE-2026-49224 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
-	TODO: check
+	NOT-FOR-US: Vvveb
 CVE-2026-49223 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
-	TODO: check
+	NOT-FOR-US: Vvveb
 CVE-2026-49222 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
-	TODO: check
+	NOT-FOR-US: Vvveb
 CVE-2026-49221 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
-	TODO: check
+	NOT-FOR-US: Vvveb
 CVE-2026-48798 (SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earl ...)
-	TODO: check
+	NOT-FOR-US: SSH.NET
 CVE-2026-48744 (Saleor is an e-commerce platform. From 3.14.67 until 3.21.67, 3.22.63, ...)
-	TODO: check
+	NOT-FOR-US: Saleor
 CVE-2026-48508 (Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePerm ...)
 	- lemur <itp> (bug #809533)
 CVE-2026-47630 (NVIDIA Triton Inference Server for Linux contains a vulnerability wher ...)
@@ -4522,7 +4522,7 @@ CVE-2026-46482 (### Impact The registration component does not validate the text
 CVE-2026-45734 (MyBB is free and open source forum software. Prior to 1.8.40, the buil ...)
 	NOT-FOR-US: MyBB
 CVE-2026-45733 (Trilium Notes is a cross-platform, hierarchical note taking applicatio ...)
-	TODO: check
+	NOT-FOR-US: Trilium Notes
 CVE-2026-45532 (DataEase is an open source data visualization and analysis tool. Versi ...)
 	NOT-FOR-US: DataEase
 CVE-2026-45129 (MyBB is free and open source forum software. Prior to 1.8.40, the Admi ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5d4f5b655636a623def927d32921be992a494cd2

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5d4f5b655636a623def927d32921be992a494cd2
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260820/22f656d4/attachment.htm>


More information about the debian-security-tracker-commits mailing list