[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Aug 20 22:35:48 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
09e8c72a by Salvatore Bonaccorso at 2026-08-20T22:36:41+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -46,11 +46,11 @@ CVE-2026-77069 (n8n before 1.123.69, 2.33.4, and 2.34.1 contains an SSRF protect
CVE-2026-77068 (n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execu ...)
NOT-FOR-US: n8n
CVE-2026-77067 (The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts ...)
- TODO: check
+ NOT-FOR-US: omnivore-app omnivore
CVE-2026-77066 (The scanFeedsResolver in packages/api/src/resolvers/subscriptions/inde ...)
- TODO: check
+ NOT-FOR-US: omnivore-app omnivore
CVE-2026-77036 (A vulnerability was found in elunez eladmin up to 2.7. The impacted el ...)
- TODO: check
+ NOT-FOR-US: elunez eladmin
CVE-2026-77031 (A vulnerability has been found in Tenda CH22 1.0.0.1. The affected ele ...)
NOT-FOR-US: Tenda
CVE-2026-77026 (Joomla Extension - tassos.gr - Client-controlled validation bypass in ...)
@@ -58,7 +58,7 @@ CVE-2026-77026 (Joomla Extension - tassos.gr - Client-controlled validation bypa
CVE-2026-77025 (A weakness has been identified in itsourcecode Hospital Management Sys ...)
NOT-FOR-US: itsourcecode System
CVE-2026-77022 (A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affect ...)
- TODO: check
+ NOT-FOR-US: Comfast
CVE-2026-77020 (A vulnerability was identified in CodeAstro Apartment Visitor Manageme ...)
NOT-FOR-US: CodeAstro
CVE-2026-77019 (A vulnerability was determined in CodeAstro Apartment Visitor Manageme ...)
@@ -71,7 +71,7 @@ CVE-2026-77014 (A flaw was found in libsoup's SoupServer HTTP Range header proce
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libsoup/-/commit/6ece9e52d918cefa1e99b5f359a22b111bdced75
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libsoup/-/commit/546a59d218eadc2f1006d4d9ecf0042666b88113
CVE-2026-77004 (A flaw has been found in Comfast CF-N1-S 2.6.0.1. This impacts the fun ...)
- TODO: check
+ NOT-FOR-US: Comfast
CVE-2026-76999 (A vulnerability was detected in SourceCodester CET Automated Grading S ...)
NOT-FOR-US: SourceCodester
CVE-2026-76998 (A security vulnerability has been detected in SourceCodester Simple On ...)
@@ -83,17 +83,17 @@ CVE-2026-76996 (A security flaw has been discovered in SourceCodester Simple Onl
CVE-2026-76995 (A vulnerability was identified in SourceCodester Simple Online Food Or ...)
NOT-FOR-US: SourceCodester
CVE-2026-76993 (A vulnerability was determined in GreyDGL PentestGPT up to 1.0.0. This ...)
- TODO: check
+ NOT-FOR-US: GreyDGL PentestGPT
CVE-2026-76991 (A vulnerability was found in itsourcecode Hospital Management System 1 ...)
NOT-FOR-US: itsourcecode System
CVE-2026-76990 (A vulnerability has been found in code-projects Simple Inventory Syste ...)
NOT-FOR-US: code-projects
CVE-2026-76989 (A security vulnerability has been detected in liftoff-sr CIPster 18025 ...)
- TODO: check
+ NOT-FOR-US: liftoff-sr CIPster
CVE-2026-76988 (A weakness has been identified in liftoff-sr CIPster 1802525be27d33e19 ...)
- TODO: check
+ NOT-FOR-US: liftoff-sr CIPster
CVE-2026-76987 (A security flaw has been discovered in liftoff-sr CIPster 1802525be27d ...)
- TODO: check
+ NOT-FOR-US: liftoff-sr CIPster
CVE-2026-76833 (@cgauge/yaml npm package contains an arbitrary code execution vulnerab ...)
TODO: check
CVE-2026-76641 (Expat through 2.8.3 contains an out-of-bounds read vulnerability that ...)
@@ -103,7 +103,7 @@ CVE-2026-76641 (Expat through 2.8.3 contains an out-of-bounds read vulnerability
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/98599f6dcc2b460410881fe420f5f55d6bec63bf
NOTE: Vulnerability covered by this CVE is introduced by the fix for CVE-2026-66046.
CVE-2026-76635 (baserCMS before 5.3.0 contains a SQL injection vulnerability in BcData ...)
- TODO: check
+ NOT-FOR-US: baserCMS
CVE-2026-76634 (WeGIA before 3.9.2 contains an insecure direct object reference vulner ...)
NOT-FOR-US: WeGIA
CVE-2026-76633 (WeGIA before 3.9.2 contains an authorization bypass vulnerability in t ...)
@@ -121,9 +121,9 @@ CVE-2026-76564 (Joomla Extension - phoca.cz - Stored XSS via User-Agent header
CVE-2026-75948 (Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagend ...)
NOT-FOR-US: Joomla
CVE-2026-75526 (django CMS is an easy-to-use and developer-friendly enterprise content ...)
- TODO: check
+ NOT-FOR-US: Django CMS
CVE-2026-75514 (BunkerWeb is an open-source, next-generation Web Application Firewall. ...)
- TODO: check
+ NOT-FOR-US: BunkerWeb
CVE-2026-75140 (jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolle ...)
TODO: check
CVE-2026-74021 (Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions.)
@@ -167,7 +167,7 @@ CVE-2026-73254 (Mongoose is an embedded web server and network library. Prior to
CVE-2026-73253 (Mongoose is an embedded web server and network library. Prior to versi ...)
TODO: check
CVE-2026-73220 (CVAT is an open source interactive video and image annotation tool for ...)
- TODO: check
+ NOT-FOR-US: Computer Vision Annotation Tool (CVAT)
CVE-2026-73199 (A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authen ...)
TODO: check
CVE-2026-73198 (A flaw was found in FreeIPA. A remote, unauthenticated attacker can ex ...)
@@ -179,15 +179,15 @@ CVE-2026-73196 (A flaw was found in FreeIPA. A low-privilege authenticated user
CVE-2026-72854 (msgpack_unpacker_expand_buffer in src/unpack.c, reached through the pu ...)
TODO: check
CVE-2026-72852 (hank-ai/darknet sizes a convolutional layer's weight and output heap b ...)
- TODO: check
+ NOT-FOR-US: hank-ai/darknet
CVE-2026-72847 (broot renders each file and directory name in its interactive tree vie ...)
TODO: check
CVE-2026-72845
REJECTED
CVE-2026-72844 (The Lean 4 kernel does not verify that the structure named in a projec ...)
- TODO: check
+ NOT-FOR-US: Lean 4 kernel
CVE-2026-71492 (Banks generates meaningful LLM prompts using a simple template languag ...)
- TODO: check
+ NOT-FOR-US: Banks
CVE-2026-71428 (The unstructured library provides open-source components for ingesting ...)
TODO: check
CVE-2026-70383 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
@@ -197,7 +197,7 @@ CVE-2026-6822
CVE-2026-6260
REJECTED
CVE-2026-69183 (Monkeytype is a minimalistic and customizable typing test. In 26.26.0 ...)
- TODO: check
+ NOT-FOR-US: Monkeytype
CVE-2026-68566 (Unauthenticated SQL Injection in BookingPress Appointment Booking Pro ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-68564 (Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1 ...)
@@ -1024,7 +1024,7 @@ CVE-2026-71368 (F-RevoCRM contains a cross-site scripting vulnerability. If a us
CVE-2026-69550 (Out-of-bounds read in Remote Desktop Client allows an unauthorized att ...)
NOT-FOR-US: Microsoft
CVE-2026-69222 (LiquidJS is a Shopify / GitHub Pages compatible template engine in pur ...)
- TODO: check
+ NOT-FOR-US: LiquidJS
CVE-2026-68901 (Wekan is open source kanban built with Meteor. Prior to 10.38, the /ap ...)
- wekan <itp> (bug #819238)
CVE-2026-68900 (Wekan is open source kanban built with Meteor. From 8.72 until 10.23, ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/09e8c72a62c664dd95d528a383a12cc47fbff110
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/09e8c72a62c664dd95d528a383a12cc47fbff110
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260820/528c8486/attachment.htm>
More information about the debian-security-tracker-commits
mailing list