[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Aug 20 13:40:55 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
5d4f5b65 by Moritz Muehlenhoff at 2026-08-20T14:05:20+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -4392,7 +4392,7 @@ CVE-2026-63328 (Trivy is a security scanner. Prior to 0.72.0, plugin manifest me
CVE-2026-62684 (File Browser is a file managing interface for uploading, deleting, pre ...)
NOT-FOR-US: File Browser
CVE-2026-62357 (Dragonfly is an in-memory data store built for modern application work ...)
- NOT-FOR-US: Dragonfly
+ NOT-FOR-US: DragonflyDB Dragonfly
CVE-2026-61696 (Forem is open source software for building communities. In versions be ...)
NOT-FOR-US: Forem
CVE-2026-61634 (The RabbitMQ Java client library allows Java and JVM-based application ...)
@@ -4440,33 +4440,33 @@ CVE-2026-55163 (Lemur manages TLS certificate creation. Prior to 1.9.2, PUT /api
CVE-2026-55162 (Lemur manages TLS certificate creation. Prior to 1.9.2, lemur/certific ...)
- lemur <itp> (bug #809533)
CVE-2026-55106 (authentik is an open-source identity provider. Prior to 2026.2.6 and 2 ...)
- TODO: check
+ NOT-FOR-US: authentik
CVE-2026-54730 (authentik is an open-source identity provider. Prior to 2026.2.6 and 2 ...)
- TODO: check
+ NOT-FOR-US: authentik
CVE-2026-54570 (AngleSharp is a .NET library for parsing angle bracket based hyper-tex ...)
- TODO: check
+ NOT-FOR-US: AngleSharp
CVE-2026-54552 (sh provides Python process launching. Prior to 2.2.4, the _uid option ...)
TODO: check
CVE-2026-53533 (aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior ...)
TODO: check
CVE-2026-52723 (ePA 3.x Integration implements the authorization workflow and writes M ...)
- TODO: check
+ NOT-FOR-US: ePA3-Service-OpenSource
CVE-2026-52610 (An arbitrary file write/directory traversal vulnerability in reportico ...)
- TODO: check
+ NOT-FOR-US: reportico-web
CVE-2026-52609 (A reflected cross-site scripting (XSS) vulnerability in reportico-web ...)
- TODO: check
+ NOT-FOR-US: reportico-web
CVE-2026-52608 (An incorrect access control vulnerability in reportico-web <= 8.1.0 al ...)
- TODO: check
+ NOT-FOR-US: reportico-web
CVE-2026-52607 (A directory traversal vulnerability in reportico-web <= 8.1.0 allows r ...)
- TODO: check
+ NOT-FOR-US: reportico-web
CVE-2026-52606 (A reflected cross-site scripting (XSS) vulnerability in reportico-web ...)
- TODO: check
+ NOT-FOR-US: reportico-web
CVE-2026-50578 (ePA 3.x Integration implements the authorization workflow and writes M ...)
- TODO: check
+ NOT-FOR-US: ePA3-Service-OpenSource
CVE-2026-50577 (ePA 3.x Integration implements the authorization workflow and writes M ...)
- TODO: check
+ NOT-FOR-US: ePA3-Service-OpenSource
CVE-2026-50576 (ePA 3.x Integration implements the authorization workflow and writes M ...)
- TODO: check
+ NOT-FOR-US: ePA3-Service-OpenSource
CVE-2026-50575 (BetterDesk is a remote desktop management solution. BetterDesk version ...)
TODO: check
CVE-2026-50187 (Oh My Zsh is a community-driven framework for managing Zsh configurati ...)
@@ -4476,33 +4476,33 @@ CVE-2026-50167 (Kurrier is a modern, self-hosted workspace for email, calendar,
CVE-2026-50161 (libre is a generic library for real-time communications with asynchron ...)
TODO: check
CVE-2026-50143 (The Apify MCP server enables AI agents to extract data from websites u ...)
- TODO: check
+ NOT-FOR-US: Apify MCP server
CVE-2026-50139 (goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `Sh ...)
TODO: check
CVE-2026-50138 (goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, whe ...)
TODO: check
CVE-2026-50126 (Adaguc-server is an open source geographical information system to vis ...)
- TODO: check
+ NOT-FOR-US: Vvveb
CVE-2026-49228 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
- TODO: check
+ NOT-FOR-US: Vvveb
CVE-2026-49227 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
- TODO: check
+ NOT-FOR-US: Vvveb
CVE-2026-49226 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
- TODO: check
+ NOT-FOR-US: Vvveb
CVE-2026-49225 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
- TODO: check
+ NOT-FOR-US: Vvveb
CVE-2026-49224 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
- TODO: check
+ NOT-FOR-US: Vvveb
CVE-2026-49223 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
- TODO: check
+ NOT-FOR-US: Vvveb
CVE-2026-49222 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
- TODO: check
+ NOT-FOR-US: Vvveb
CVE-2026-49221 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
- TODO: check
+ NOT-FOR-US: Vvveb
CVE-2026-48798 (SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earl ...)
- TODO: check
+ NOT-FOR-US: SSH.NET
CVE-2026-48744 (Saleor is an e-commerce platform. From 3.14.67 until 3.21.67, 3.22.63, ...)
- TODO: check
+ NOT-FOR-US: Saleor
CVE-2026-48508 (Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePerm ...)
- lemur <itp> (bug #809533)
CVE-2026-47630 (NVIDIA Triton Inference Server for Linux contains a vulnerability wher ...)
@@ -4522,7 +4522,7 @@ CVE-2026-46482 (### Impact The registration component does not validate the text
CVE-2026-45734 (MyBB is free and open source forum software. Prior to 1.8.40, the buil ...)
NOT-FOR-US: MyBB
CVE-2026-45733 (Trilium Notes is a cross-platform, hierarchical note taking applicatio ...)
- TODO: check
+ NOT-FOR-US: Trilium Notes
CVE-2026-45532 (DataEase is an open source data visualization and analysis tool. Versi ...)
NOT-FOR-US: DataEase
CVE-2026-45129 (MyBB is free and open source forum software. Prior to 1.8.40, the Admi ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5d4f5b655636a623def927d32921be992a494cd2
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5d4f5b655636a623def927d32921be992a494cd2
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260820/22f656d4/attachment.htm>
More information about the debian-security-tracker-commits
mailing list