[Git][security-tracker-team/security-tracker][master] Process some more NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 21 09:27:00 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
53b6abab by Salvatore Bonaccorso at 2026-08-21T10:11:12+02:00
Process some more NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -349,7 +349,7 @@ CVE-2026-63495 (Libevent is an event notification library. From 2.2.0-alpha-dev
 	NOTE: https://github.com/libevent/libevent/security/advisories/GHSA-qx89-wf2v-vgmx
 	NOTE: Fixed by: https://github.com/libevent/libevent/commit/291c4d1cd75695e898030ebd5c4ddf26c094077b (release-2.2.2-alpha)
 CVE-2026-63490 (Handlebars.java provides logic-less and semantic Mustache templates wi ...)
-	TODO: check
+	NOT-FOR-US: Handlebars.java
 CVE-2026-63481 (Hurl is a command line tool that runs and tests HTTP requests defined  ...)
 	- hurl <unfixed>
 	NOTE: https://github.com/Orange-OpenSource/hurl/security/advisories/GHSA-7w2g-9mf9-324m
@@ -402,61 +402,61 @@ CVE-2026-63379 (Libevent is an event notification library. Prior to 2.1.13 and 2
 	NOTE: Fixed by: https://github.com/libevent/libevent/commit/87e8e44fa774e9677b089b1a5114ee68aefa1636 (release-2.1.13-stable)
 	NOTE: Fixed by: https://github.com/libevent/libevent/commit/b847071141b3827900d536594ec9045eb0a4c485 (release-2.2.2-alpha)
 CVE-2026-63044 (Server-Side Request Forgery (SSRF) vulnerability in Apache InLong.Any  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-63043 (Relative Path Traversal vulnerability in Apache InLong.Arbitrary file  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-63042 (Files or Directories Accessible to External Parties vulnerability in A ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-63040 (Files or Directories Accessible to External Parties vulnerability in A ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-63039 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-63038 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-63037 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-63016 (Uncontrolled Resource Consumption vulnerability in Apache InLong. User ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-63015 (Uncontrolled Resource Consumption vulnerability in Apache InLong.Non-t ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-63003 (django CMS is an easy-to-use and developer-friendly enterprise content ...)
 	NOT-FOR-US: Django CMS
 CVE-2026-62315 (Frappe is a full-stack web application framework. In version 16.31.0 a ...)
-	TODO: check
+	NOT-FOR-US: Frappe
 CVE-2026-61704 (Link Preview JS extracts web links information. Prior to 4.0.4, the re ...)
-	TODO: check
+	NOT-FOR-US: Node link-preview-js
 CVE-2026-61663 (django CMS is an easy-to-use and developer-friendly enterprise content ...)
-	TODO: check
+	NOT-FOR-US: Django CMS
 CVE-2026-61625 (VictoriaMetrics is a scalable solution for monitoring and managing tim ...)
-	TODO: check
+	NOT-FOR-US: VictoriaMetrics
 CVE-2026-55642 (dbx is a cross-platform database client for databases. Prior to 0.5.51 ...)
 	TODO: check
 CVE-2026-55586 (SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, ...)
-	TODO: check
+	NOT-FOR-US: SumatraPDF
 CVE-2026-55558 (aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior  ...)
 	TODO: check
 CVE-2026-55095 (OpenProject is open-source, web-based project management software. In  ...)
-	TODO: check
+	NOT-FOR-US: OpenProject
 CVE-2026-54770 (WebOb provides objects for HTTP requests and responses. Prior to 1.8.1 ...)
 	TODO: check
 CVE-2026-54625 (django CMS is a content management system powered by Django. Prior to  ...)
-	TODO: check
+	NOT-FOR-US: Django CMS
 CVE-2026-54624 (django CMS is an easy-to-use and developer-friendly enterprise content ...)
-	TODO: check
+	NOT-FOR-US: Django CMS
 CVE-2026-54623 (django CMS is an easy-to-use and developer-friendly enterprise content ...)
-	TODO: check
+	NOT-FOR-US: Django CMS
 CVE-2026-54622 (django CMS is an easy-to-use and developer-friendly enterprise content ...)
-	TODO: check
+	NOT-FOR-US: Django CMS
 CVE-2026-54616 (NanaZip is the 7-Zip derivative intended for the modern Windows experi ...)
-	TODO: check
+	NOT-FOR-US: NanaZip
 CVE-2026-54449 (LangBot is a global IM bot platform designed for LLMs. In version 4.10 ...)
-	TODO: check
+	NOT-FOR-US: LangBot
 CVE-2026-54136 (Windmill is an open-source developer platform for internal code: APIs, ...)
-	TODO: check
+	NOT-FOR-US: Windmill
 CVE-2026-53993
 	REJECTED
 CVE-2026-53569 (Frappe is a full-stack web application framework. In version 16.31.0 a ...)
-	TODO: check
+	NOT-FOR-US: Frappe
 CVE-2026-53425 (Insufficient Verification of Data Authenticity vulnerability in dropbo ...)
 	TODO: check
 CVE-2026-53424 (Authentication Bypass by Capture-replay vulnerability in dropbox samly ...)
@@ -1163,15 +1163,15 @@ CVE-2026-63123 (Tina is a headless content management system. Prior to 2.5.2, th
 CVE-2026-62727 (Concurrent execution using shared resource with improper synchronizati ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-62317 (Logto is the modern, open-source auth infrastructure for SaaS and AI a ...)
-	TODO: check
+	NOT-FOR-US: Logto
 CVE-2026-61712 (BuildKit is a toolkit for converting source code to build artifacts in ...)
 	TODO: check
 CVE-2026-61711 (BuildKit is a toolkit for converting source code to build artifacts in ...)
 	TODO: check
 CVE-2026-61556 (LiquidJS is a Shopify / GitHub Pages compatible template engine in pur ...)
-	TODO: check
+	NOT-FOR-US: LiquidJS
 CVE-2026-59992 (Tina is a headless content management system. Prior to next-tinacms-s3 ...)
-	TODO: check
+	NOT-FOR-US: Tina
 CVE-2026-55090 (Etherpad is a real-time collaborative editor. Prior to 3.3.0, getHTMLF ...)
 	- etherpad-lite <itp> (bug #576998)
 CVE-2026-55089 (Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0,  ...)
@@ -1852,13 +1852,13 @@ CVE-2026-54794 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains a
 CVE-2026-54793 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Impro ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-53654 (Grav is a file-based Web platform. Prior to 3.8.5, the Login plugin tw ...)
-	TODO: check
+	NOT-FOR-US: Grav CMS
 CVE-2026-53477 (Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of- ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-53452 (Ground Station is a browser-based suite for satellite tracking, SDR re ...)
-	TODO: check
+	NOT-FOR-US: Ground Station
 CVE-2026-53451 (Ground Station is a browser-based suite for satellite tracking, SDR re ...)
-	TODO: check
+	NOT-FOR-US: Ground Station
 CVE-2026-52889 (Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Form ...)
 	NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-52834 (jxl-oxide is a pure Rust implementation of a JPEG XL decoder. Prior to ...)
@@ -3395,11 +3395,11 @@ CVE-2026-62609 (Vulnerability in the Oracle Reports Developer product of Oracle
 CVE-2026-62608 (Vulnerability in the Oracle Reports Developer product of Oracle Fusion ...)
 	NOT-FOR-US: Oracle
 CVE-2026-62607 (Vulnerability in the Oracle Customer Care product of Oracle E-Business ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-62606 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
 	NOT-FOR-US: Oracle
 CVE-2026-62605 (Vulnerability in the Oracle Partner Management product of Oracle E-Bus ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-62604 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
 	NOT-FOR-US: Oracle
 CVE-2026-62603 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
@@ -3407,11 +3407,11 @@ CVE-2026-62603 (Vulnerability in the Oracle Hyperion Calculation Manager product
 CVE-2026-62602 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
 	NOT-FOR-US: Oracle
 CVE-2026-62601 (Vulnerability in the Oracle Sales product of Oracle E-Business Suite ( ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-62600 (Vulnerability in the Oracle Sales product of Oracle E-Business Suite ( ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-62599 (Vulnerability in the Oracle Trading Community product of Oracle E-Busi ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-62598 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
 	NOT-FOR-US: Oracle
 CVE-2026-62596 (Vulnerability in the Siebel CRM Integration product of Oracle Siebel C ...)
@@ -3433,11 +3433,11 @@ CVE-2026-62589 (Vulnerability in the Siebel CRM Integration product of Oracle Si
 CVE-2026-62588 (Vulnerability in the Siebel CRM Integration product of Oracle Siebel C ...)
 	NOT-FOR-US: Oracle
 CVE-2026-62587 (Vulnerability in the Siebel CRM Administration product of Oracle Siebe ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-62586 (Vulnerability in the Siebel CRM Administration product of Oracle Siebe ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-62585 (Vulnerability in the Siebel CRM Administration product of Oracle Siebe ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-62584 (Vulnerability in the Oracle Hyperion Infrastructure Technology product ...)
 	NOT-FOR-US: Oracle
 CVE-2026-62583 (Vulnerability in the Oracle Hyperion Infrastructure Technology product ...)
@@ -3553,7 +3553,7 @@ CVE-2026-62481 (Vulnerability in the Oracle Hyperion Infrastructure Technology p
 CVE-2026-62477 (Vulnerability in the Oracle Hyperion Infrastructure Technology product ...)
 	NOT-FOR-US: Oracle
 CVE-2026-62475 (Vulnerability in the Oracle Shipping Execution product of Oracle E-Bus ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-62471 (Vulnerability in the Oracle Hyperion Infrastructure Technology product ...)
 	NOT-FOR-US: Oracle
 CVE-2026-62467 (Vulnerability in the Oracle Hyperion Infrastructure Technology product ...)
@@ -3561,7 +3561,7 @@ CVE-2026-62467 (Vulnerability in the Oracle Hyperion Infrastructure Technology p
 CVE-2026-62463 (Vulnerability in the Oracle Hyperion Infrastructure Technology product ...)
 	NOT-FOR-US: Oracle
 CVE-2026-62462 (Vulnerability in the Oracle Work in Process product of Oracle E-Busine ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-62461 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
 	NOT-FOR-US: Oracle
 CVE-2026-62460 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
@@ -3569,7 +3569,7 @@ CVE-2026-62460 (Vulnerability in the Oracle Hyperion Calculation Manager product
 CVE-2026-62459 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
 	NOT-FOR-US: Oracle
 CVE-2026-62458 (Vulnerability in the Oracle Work in Process product of Oracle E-Busine ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-62457 (Vulnerability in the Oracle Hyperion Infrastructure Technology product ...)
 	NOT-FOR-US: Oracle
 CVE-2026-62455 (Vulnerability in the Siebel CRM Cloud Applications product of Oracle S ...)
@@ -3579,11 +3579,11 @@ CVE-2026-62454 (Vulnerability in the Siebel CRM Cloud Applications product of Or
 CVE-2026-62452 (Vulnerability in the Siebel CRM Cloud Applications product of Oracle S ...)
 	NOT-FOR-US: Oracle
 CVE-2026-62450 (Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Bus ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-62449 (Vulnerability in the Oracle Work in Process product of Oracle E-Busine ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-62448 (Vulnerability in the Oracle Email Center product of Oracle E-Business  ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-62446 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
 	NOT-FOR-US: Oracle
 CVE-2026-62442 (Vulnerability in the Siebel CRM Cloud Applications product of Oracle S ...)
@@ -3610,7 +3610,7 @@ CVE-2026-61339 (Vulnerability in the Siebel CRM Cloud Applications product of Or
 CVE-2026-61332 (Vulnerability in the Siebel CRM Cloud Applications product of Oracle S ...)
 	NOT-FOR-US: Oracle
 CVE-2026-61331 (Vulnerability in the Oracle Financials Common Modules product of Oracl ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-61330 (Vulnerability in the Siebel CRM Cloud Applications product of Oracle S ...)
 	NOT-FOR-US: Oracle
 CVE-2026-61326 (Vulnerability in the Siebel CRM Cloud Applications product of Oracle S ...)
@@ -3618,7 +3618,7 @@ CVE-2026-61326 (Vulnerability in the Siebel CRM Cloud Applications product of Or
 CVE-2026-61321 (Vulnerability in the Siebel CRM Cloud Applications product of Oracle S ...)
 	NOT-FOR-US: Oracle
 CVE-2026-61319 (Vulnerability in the Oracle U.S. Federal Financials product of Oracle  ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-61318 (Vulnerability in the Siebel CRM Cloud Applications product of Oracle S ...)
 	NOT-FOR-US: Oracle
 CVE-2026-61317 (Vulnerability in the Siebel CRM Cloud Applications product of Oracle S ...)
@@ -3662,19 +3662,19 @@ CVE-2026-61273 (Vulnerability in the JD Edwards EnterpriseOne Tools product of O
 CVE-2026-61272 (Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle  ...)
 	NOT-FOR-US: Oracle
 CVE-2026-61270 (Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of  ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-61268 (Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle  ...)
 	NOT-FOR-US: Oracle
 CVE-2026-61265 (Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of  ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-61259 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
 	NOT-FOR-US: Oracle
 CVE-2026-61258 (Vulnerability in the Oracle Internet Directory product of Oracle Fusio ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-61248 (Vulnerability in the Oracle Internet Directory product of Oracle Fusio ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-61241 (Vulnerability in the Oracle Internet Directory product of Oracle Fusio ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-61231 (Vulnerability in the Oracle Virtual Directory product of Oracle Fusion ...)
 	NOT-FOR-US: Oracle
 CVE-2026-61230 (Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion  ...)
@@ -3702,7 +3702,7 @@ CVE-2026-61206 (Vulnerability in the Oracle Hyperion Calculation Manager product
 CVE-2026-61199 (Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion  ...)
 	NOT-FOR-US: Oracle
 CVE-2026-61198 (Vulnerability in the Oracle Learning Management product of Oracle E-Bu ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-61193 (Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion  ...)
 	NOT-FOR-US: Oracle
 CVE-2026-61177 (Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion  ...)
@@ -3752,7 +3752,7 @@ CVE-2026-61008 (Vulnerability in the Oracle WebCenter Sites product of Oracle Fu
 CVE-2026-61007 (Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion M ...)
 	NOT-FOR-US: Oracle
 CVE-2026-61003 (Vulnerability in the Oracle Managed File Transfer product of Oracle Fu ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-61002 (Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middlew ...)
 	TODO: check
 CVE-2026-61001 (Vulnerability in the Oracle Web Services Manager product of Oracle Fus ...)
@@ -3850,13 +3850,13 @@ CVE-2026-60879 (Vulnerability in the PeopleSoft Enterprise PeopleTools product o
 CVE-2026-60873 (Vulnerability in the PeopleSoft Enterprise PeopleTools product of Orac ...)
 	NOT-FOR-US: Oracle
 CVE-2026-60866 (Vulnerability in the Service Delivery Platform product of Oracle Fusio ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-60865 (Vulnerability in the Service Delivery Platform product of Oracle Fusio ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-60861 (Vulnerability in the Service Delivery Platform product of Oracle Fusio ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-60860 (Vulnerability in the Service Delivery Platform product of Oracle Fusio ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-60858 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
 	NOT-FOR-US: Oracle
 CVE-2026-60856 (Vulnerability in the PeopleSoft Enterprise PeopleTools product of Orac ...)
@@ -4014,7 +4014,7 @@ CVE-2026-56867
 CVE-2026-55593 (Froxlor is open source server administration software. Prior to 2.3.8, ...)
 	- froxlor <itp> (bug #581792)
 CVE-2026-55426 (linuxfabrik-lib provides Python modules for database access, caching,  ...)
-	TODO: check
+	NOT-FOR-US: Linuxfabrik Monitoring Plugins
 CVE-2026-54543 (Froxlor is open source server administration software. Prior to 2.3.8, ...)
 	TODO: check
 CVE-2026-54348 (Froxlor is open source server administration software. Prior to 2.3.8, ...)
@@ -4022,33 +4022,33 @@ CVE-2026-54348 (Froxlor is open source server administration software. Prior to
 CVE-2026-54347 (Froxlor is open source server administration software. Prior to 2.3.8, ...)
 	TODO: check
 CVE-2026-53959 (4gaBoards is a boards system for realtime project management. Prior to ...)
-	TODO: check
+	NOT-FOR-US: 4gaBoards
 CVE-2026-53958 (4gaBoards is a boards system for realtime project management. Prior to ...)
-	TODO: check
+	NOT-FOR-US: 4gaBoards
 CVE-2026-53759 (linuxfabrik-lib provides Python modules for database access, caching,  ...)
-	TODO: check
+	NOT-FOR-US: linuxfabrik-lib
 CVE-2026-53458 (Blueprint Studio is a VS Code-like file editor for Home Assistant conf ...)
-	TODO: check
+	NOT-FOR-US: Blueprint Studio
 CVE-2026-53457 (Blueprint Studio is a VS Code-like file editor for Home Assistant conf ...)
-	TODO: check
+	NOT-FOR-US: Blueprint Studio
 CVE-2026-53456 (Blueprint Studio is a VS Code-like file editor for Home Assistant conf ...)
-	TODO: check
+	NOT-FOR-US: Blueprint Studio
 CVE-2026-53455 (Blueprint Studio is a VS Code-like file editor for Home Assistant conf ...)
-	TODO: check
+	NOT-FOR-US: Blueprint Studio
 CVE-2026-53454 (Blueprint Studio is a VS Code-like file editor for Home Assistant conf ...)
-	TODO: check
+	NOT-FOR-US: Blueprint Studio
 CVE-2026-53453 (Blueprint Studio is a VS Code-like file editor for Home Assistant conf ...)
-	TODO: check
+	NOT-FOR-US: Blueprint Studio
 CVE-2026-52877 (Streambert is a cross-platform Electron Desktop App to stream and down ...)
-	TODO: check
+	NOT-FOR-US: Streambert
 CVE-2026-52876 (Streambert is a cross-platform Electron Desktop App to stream and down ...)
-	TODO: check
+	NOT-FOR-US: Streambert
 CVE-2026-52875 (Streambert is a cross-platform Electron Desktop App to stream and down ...)
-	TODO: check
+	NOT-FOR-US: Streambert
 CVE-2026-52873 (Streambert is a cross-platform Electron Desktop App to stream and down ...)
-	TODO: check
+	NOT-FOR-US: Streambert
 CVE-2026-52872 (Streambert is a cross-platform Electron Desktop App to stream and down ...)
-	TODO: check
+	NOT-FOR-US: Streambert
 CVE-2026-52854 (Maps is a MediaWiki extension that enables visualization of geographic ...)
 	TODO: check
 CVE-2026-52829 (ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an una ...)
@@ -5147,7 +5147,7 @@ CVE-2026-56684 (Valkey is a distributed key-value database. Prior to 7.2.14, 8.0
 	NOTE: Fixed by: https://github.com/valkey-io/valkey/commit/33b14adf2026cfd8728607b026edb24843805844 (8.1.9)
 	TODO: check redis and redict
 CVE-2026-55839 (Kestra is an open-source, event-driven orchestration platform. Prior t ...)
-	TODO: check
+	NOT-FOR-US: Kestra
 CVE-2026-55166 (Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated  ...)
 	- lemur <itp> (bug #809533)
 CVE-2026-55165 (Lemur manages TLS certificate creation. Prior to 1.9.2, the JWT verifi ...)
@@ -5690,15 +5690,15 @@ CVE-2026-57233 (Notepad++ is a free and open-source source code editor. Prior to
 CVE-2026-56677 (9Router is an AI router & token saver. In 0.5.4 and earlier, the POST  ...)
 	NOT-FOR-US: 9Router
 CVE-2026-54758 (Notepad++ is a free and open-source source code editor. Prior to 8.9.7 ...)
-	TODO: check
+	NOT-FOR-US: Notepad++
 CVE-2026-54385
 	REJECTED
 CVE-2026-54356 (Budibase is an open-source low-code platform. Prior to 3.41.3, POST /a ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-54336 (JumpServer is an open source bastion host and an operation and mainten ...)
-	TODO: check
+	NOT-FOR-US: JumpServer
 CVE-2026-52886 (Notepad++ is a free and open-source source code editor. Prior to 8.9.7 ...)
-	TODO: check
+	NOT-FOR-US: Notepad++
 CVE-2026-51977 (An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Ve ...)
 	TODO: check
 CVE-2026-47698 (vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bri ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/53b6ababd09271bdff4e996eead40b5c92d28824

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/53b6ababd09271bdff4e996eead40b5c92d28824
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260821/891fc519/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list