[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 21 05:43:02 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c65d14b1 by Salvatore Bonaccorso at 2026-08-21T06:34:56+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -95,7 +95,7 @@ CVE-2026-76988 (A weakness has been identified in liftoff-sr CIPster 1802525be27
 CVE-2026-76987 (A security flaw has been discovered in liftoff-sr CIPster 1802525be27d ...)
 	NOT-FOR-US: liftoff-sr CIPster
 CVE-2026-76833 (@cgauge/yaml npm package contains an arbitrary code execution vulnerab ...)
-	TODO: check
+	NOT-FOR-US: gauge/yaml Node.js module
 CVE-2026-76641 (Expat through 2.8.3 contains an out-of-bounds read vulnerability that  ...)
 	- expat <not-affected> (Vulnerable code not present)
 	NOTE: https://github.com/libexpat/libexpat/pull/1331
@@ -212,7 +212,7 @@ CVE-2026-72844 (The Lean 4 kernel does not verify that the structure named in a
 CVE-2026-71492 (Banks generates meaningful LLM prompts using a simple template languag ...)
 	NOT-FOR-US: Banks
 CVE-2026-71428 (The unstructured library provides open-source components for ingesting ...)
-	TODO: check
+	NOT-FOR-US: unstructured
 CVE-2026-70383 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
 	TODO: check
 CVE-2026-6822
@@ -226,11 +226,11 @@ CVE-2026-68566 (Unauthenticated SQL Injection in BookingPress Appointment Bookin
 CVE-2026-68564 (Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1 ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66788 (A flaw was found in Lighthouse. A remote attacker, by compromising a s ...)
-	TODO: check
+	NOT-FOR-US: Lighthouse (component of Red Hat Advanced Cluster Management for Kubernetes)
 CVE-2026-66787 (A flaw was found in the lighthouse component of Red Hat Advanced Clust ...)
-	TODO: check
+	NOT-FOR-US: Lighthouse (component of Red Hat Advanced Cluster Management for Kubernetes)
 CVE-2026-66785 (A flaw was found in Submariner. This vulnerability allows a malicious  ...)
-	TODO: check
+	NOT-FOR-US: Submariner
 CVE-2026-66682 (Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooComm ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66680 (Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 ve ...)
@@ -292,43 +292,43 @@ CVE-2026-66582 (Unauthenticated Cross Site Scripting (XSS) in TranslatePress <=
 CVE-2026-66581 (Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 ve ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66002 (Frappe is a full-stack web application framework. Prior to 15.115.0 an ...)
-	TODO: check
+	NOT-FOR-US: Frappe
 CVE-2026-66001 (Frappe is a full-stack web application framework. Prior to 15.114.0 an ...)
-	TODO: check
+	NOT-FOR-US: Frappe
 CVE-2026-65842 (Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.2, @p ...)
-	TODO: check
+	NOT-FOR-US: Plate
 CVE-2026-64972 (ATutor is vulnerable to Reflected XSS via popup parameter in preview.p ...)
-	TODO: check
+	NOT-FOR-US: ATutor
 CVE-2026-64971 (ATutor is vulnerable to Reflected XSS in restore functionality. An att ...)
-	TODO: check
+	NOT-FOR-US: ATutor
 CVE-2026-64970 (ATutor is vulnerable to Stored Cross Site Scripting in registration fu ...)
-	TODO: check
+	NOT-FOR-US: ATutor
 CVE-2026-64969 (ATutor is vulnerable to InsecureDirect Object Reference (IDOR) attack  ...)
-	TODO: check
+	NOT-FOR-US: ATutor
 CVE-2026-64968 (ATutor is vulnerable toServer-Side request forgery in import functiona ...)
-	TODO: check
+	NOT-FOR-US: ATutor
 CVE-2026-64967 (A path traversal vulnerability in ATutor's error log viewer allows an  ...)
-	TODO: check
+	NOT-FOR-US: ATutor
 CVE-2026-64966 (ATutor is vulnerable to a Path Traversal vulnerability in ZIP extracti ...)
-	TODO: check
+	NOT-FOR-US: ATutor
 CVE-2026-64965 (ATutor is vulnerable to Missing Authorization Check on Test and Questi ...)
-	TODO: check
+	NOT-FOR-US: ATutor
 CVE-2026-64964 (ATutor generates predictable email confirmation tokens due to the use  ...)
-	TODO: check
+	NOT-FOR-US: ATutor
 CVE-2026-64963 (A path traversal vulnerability in ATutor allows an authenticated user  ...)
-	TODO: check
+	NOT-FOR-US: ATutor
 CVE-2026-64962 (ATutor is vulnerable to Cross-Site Request Forgery (CSRF) in profile u ...)
-	TODO: check
+	NOT-FOR-US: ATutor
 CVE-2026-64961 (ATutor is vulnerable to authentication bypass .Although a token valida ...)
-	TODO: check
+	NOT-FOR-US: ATutor
 CVE-2026-64960 (ATutor Gameme module allows users to upload files of any type and exte ...)
-	TODO: check
+	NOT-FOR-US: ATutor
 CVE-2026-64846 (Nix is a package manager for Linux and other Unix systems. Prior to 2. ...)
 	TODO: check
 CVE-2026-64777 (A malicious builder peer may be able to request an in-context file by  ...)
 	NOT-FOR-US: Apple
 CVE-2026-63654 (Frappe is a full-stack web application framework. In version 16.31.0 a ...)
-	TODO: check
+	NOT-FOR-US: Frappe
 CVE-2026-63495 (Libevent is an event notification library. From 2.2.0-alpha-dev until  ...)
 	TODO: check
 CVE-2026-63490 (Handlebars.java provides logic-less and semantic Mustache templates wi ...)
@@ -372,7 +372,7 @@ CVE-2026-63016 (Uncontrolled Resource Consumption vulnerability in Apache InLong
 CVE-2026-63015 (Uncontrolled Resource Consumption vulnerability in Apache InLong.Non-t ...)
 	TODO: check
 CVE-2026-63003 (django CMS is an easy-to-use and developer-friendly enterprise content ...)
-	TODO: check
+	NOT-FOR-US: Django CMS
 CVE-2026-62315 (Frappe is a full-stack web application framework. In version 16.31.0 a ...)
 	TODO: check
 CVE-2026-61704 (Link Preview JS extracts web links information. Prior to 4.0.4, the re ...)
@@ -1071,15 +1071,15 @@ CVE-2026-68553 (Coturn is a free open source implementation of TURN and STUN Ser
 CVE-2026-68552 (Coturn is a free open source implementation of TURN and STUN Server. P ...)
 	TODO: check
 CVE-2026-67189 (pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a store ...)
-	TODO: check
+	NOT-FOR-US: pfSense Plus
 CVE-2026-63722 (ICEcoder 8.1 contains an unauthenticated remote code execution vulnera ...)
-	TODO: check
+	NOT-FOR-US: ICEcoder
 CVE-2026-63188 (Logto is the modern, open-source auth infrastructure for SaaS and AI a ...)
-	TODO: check
+	NOT-FOR-US: Logto
 CVE-2026-63187 (Logto is the modern, open-source auth infrastructure for SaaS and AI a ...)
-	TODO: check
+	NOT-FOR-US: Logto
 CVE-2026-63123 (Tina is a headless content management system. Prior to 2.5.2, the Tina ...)
-	TODO: check
+	NOT-FOR-US: Tina CMS
 CVE-2026-62727 (Concurrent execution using shared resource with improper synchronizati ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-62317 (Logto is the modern, open-source auth infrastructure for SaaS and AI a ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c65d14b16cd5e174e5357a59198c50d49eba18b9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c65d14b16cd5e174e5357a59198c50d49eba18b9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260821/1e8bc1b8/attachment.htm>


More information about the debian-security-tracker-commits mailing list