[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 21 20:13:54 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
dce3666d by security tracker role at 2026-08-21T19:13:47+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,13 +1,659 @@
-CVE-2026-74583 [net/sched: cls_route: fix fastmap use-after-free on filter]
+CVE-2026-9324
+	REJECTED
+CVE-2026-9321
+	REJECTED
+CVE-2026-9244
+	REJECTED
+CVE-2026-9012
+	REJECTED
+CVE-2026-77815 (to_abs_path in scripts/iib/tool.py normalised the requested path with  ...)
+	TODO: check
+CVE-2026-77814 (is_path_trusted in scripts/iib/api.py compares the requested path agai ...)
+	TODO: check
+CVE-2026-77812 (DJI drones transmit DUML (DJI Universal Markup Language) protocol mess ...)
+	TODO: check
+CVE-2026-77806 (SPIP before 4.4.21 allows unauthenticated remote attackers to execute  ...)
+	TODO: check
+CVE-2026-77795 (A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.6.2.  ...)
+	TODO: check
+CVE-2026-77780 (Authorization Bypass Through User-Controlled Key in the transaction sa ...)
+	TODO: check
+CVE-2026-77776 (Headroom's LLM proxy derives the memory owner from the x-headroom-user ...)
+	TODO: check
+CVE-2026-77775 (Headroom's LLM proxy lets a client choose the upstream destination wit ...)
+	TODO: check
+CVE-2026-77769 (The report.list procedure in packages/trpc/src/routers/report.ts accep ...)
+	TODO: check
+CVE-2026-77768 (The report.get procedure in packages/trpc/src/routers/report.ts accept ...)
+	TODO: check
+CVE-2026-77767 (Reconmap's API applies a fallback authorization policy in apps/api/app ...)
+	TODO: check
+CVE-2026-77763 (The filestore backend in pkg/object/file.go, used for file:// stores a ...)
+	TODO: check
+CVE-2026-77761 (A parser state isolation vulnerability in misp-stix could cause data f ...)
+	TODO: check
+CVE-2026-77759 (Authorization Bypass Through User-Controlled Key in the transaction AP ...)
+	TODO: check
+CVE-2026-77755 (A denial-of-service vulnerability was identified in misp-stix when pro ...)
+	TODO: check
+CVE-2026-77751 (A path traversal vulnerability existed in the handling of MISP object  ...)
+	TODO: check
+CVE-2026-77710 (A vulnerability in misp-stix could allow a crafted STIX document to in ...)
+	TODO: check
+CVE-2026-77686 (A weakness has been identified in Dolibarr up to 23.0.4. This affects  ...)
+	TODO: check
+CVE-2026-77683 (A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affect ...)
+	TODO: check
+CVE-2026-77681 (A vulnerability was identified in CodeAstro Online Job Portal 1.0. Aff ...)
+	TODO: check
+CVE-2026-77651 (The arrayref crate 0.3.10 for Rust can trigger execution of malicious  ...)
+	TODO: check
+CVE-2026-77650 (The append-only-vec crate 0.1.9 for Rust can trigger execution of mali ...)
+	TODO: check
+CVE-2026-77649 (The internment crate 0.8.7 for Rust can trigger execution of malicious ...)
+	TODO: check
+CVE-2026-77646 (AServer-Side Request Forgery (SSRF) vulnerability has beenreported in  ...)
+	TODO: check
+CVE-2026-77645 (A critical remote code execution (RCE) vulnerability has been reported ...)
+	TODO: check
+CVE-2026-77644 (A critical bypass access control vulnerability has been reported in PT ...)
+	TODO: check
+CVE-2026-77392 (A weakness has been identified in SourceCodester Dynamic Input Field G ...)
+	TODO: check
+CVE-2026-77391 (A security flaw has been discovered in SourceCodester Dynamic Input Fi ...)
+	TODO: check
+CVE-2026-77264 (The Automation Web Platform \u2013 Notifications and OTP for WooCommer ...)
+	TODO: check
+CVE-2026-77237 (Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS- ...)
+	TODO: check
+CVE-2026-77236 (Missing minimum size validation in secure context allocation in FreeRT ...)
+	TODO: check
+CVE-2026-77235 (Missing privilege verification in the secure context cleanup handler i ...)
+	TODO: check
+CVE-2026-77234 (Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow ...)
+	TODO: check
+CVE-2026-77151 (A security flaw has been discovered in lin-snow Ech0 up to 5.4.1. Affe ...)
+	TODO: check
+CVE-2026-77113 (Path traversal in apport-unpack in Canonical Apport before2.36.0,2.34. ...)
+	TODO: check
+CVE-2026-77087 (Paperclip before 0.3.1 in default local_trusted mode fails to validate ...)
+	TODO: check
+CVE-2026-77086 (SiYuan before v3.7.4 fails to validate the packageName parameter in Ba ...)
+	TODO: check
+CVE-2026-77029 (Joomla Extension - yootheme.com - Missing CSRF tokens on front-end sta ...)
+	TODO: check
+CVE-2026-77028 (Joomla Extension - yootheme.com - Reflected XSS and open redirect via  ...)
+	TODO: check
+CVE-2026-76613 (Joomla Extension - yootheme.com - Authenticated, privileged SQL inject ...)
+	TODO: check
+CVE-2026-76612 (Joomla Extension - yootheme.com - Unauthenticated stored XSS via user- ...)
+	TODO: check
+CVE-2026-76611 (Joomla Extension - yootheme.com - Unauthenticated arbitrary directory  ...)
+	TODO: check
+CVE-2026-76158 (External Control of File Name or Path in the upload API endpoint of Da ...)
+	TODO: check
+CVE-2026-76157 (Missing authentication for a critical function in the upload API endpo ...)
+	TODO: check
+CVE-2026-76156 (OS command injection in the api endpoint of Datiphy Data Management Ce ...)
+	TODO: check
+CVE-2026-76155 (Use of default credentials in Datiphy Data Management Center from v8.3 ...)
+	TODO: check
+CVE-2026-76137 (Missing authentication for critical function vulnerability exists in V ...)
+	TODO: check
+CVE-2026-76131 (Use of hard-coded credentials issue exists in VOCALOID6 , which may al ...)
+	TODO: check
+CVE-2026-76023 (Improper resource control in Linux Toolkit Theming in Google Chrome pr ...)
+	TODO: check
+CVE-2026-76022 (Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 al ...)
+	TODO: check
+CVE-2026-76021 (Use after free in DOM in Google Chrome prior to 151.0.7922.173 allowed ...)
+	TODO: check
+CVE-2026-76020 (Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed  ...)
+	TODO: check
+CVE-2026-76019 (Incorrect authorization in Workers in Google Chrome prior to 151.0.792 ...)
+	TODO: check
+CVE-2026-76018 (Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 ...)
+	TODO: check
+CVE-2026-76017 (Use after free in Chromoting in Google Chrome prior to 151.0.7922.173  ...)
+	TODO: check
+CVE-2026-75946 (A potential security vulnerability has been identified in the OMEN Gam ...)
+	TODO: check
+CVE-2026-75933 (Jet Admin allows an authenticated attacker to inject JavaScript via th ...)
+	TODO: check
+CVE-2026-75932 (Jet Admin allows an attacker to create a malicious app and connect it  ...)
+	TODO: check
+CVE-2026-75928 (The Brushfire platform's video content streaming application (https:// ...)
+	TODO: check
+CVE-2026-75910 (Incorrect privilege assignment in the ClickHouse connector deployment  ...)
+	TODO: check
+CVE-2026-75796 (The AI Engine  WordPress plugin before 3.6.1 does not verify that the  ...)
+	TODO: check
+CVE-2026-75501 (A vulnerability in the Calix EXOS firmware for the GS7 XGS (GS5239XG)  ...)
+	TODO: check
+CVE-2026-75484 (Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerabi ...)
+	TODO: check
+CVE-2026-75115 (Joomla Extension - yootheme.com - Authenticated, privileged arbitrary  ...)
+	TODO: check
+CVE-2026-74866 (@fastify/busboy is a multipart form-data parser for Node.js. Its multi ...)
+	TODO: check
+CVE-2026-74836 (Allocation of Resources Without Limits or Throttling vulnerability in  ...)
+	TODO: check
+CVE-2026-73537 (Cross-site scripting vulnerability exists in Miraikan Assist App. If t ...)
+	TODO: check
+CVE-2026-73267 (A flaw was found in the clusterclaims-controller component of multiclu ...)
+	TODO: check
+CVE-2026-73137 (A flaw was found in the multicloud-operators-subscription component of ...)
+	TODO: check
+CVE-2026-73040 (Dockge validates a stack name only on the write path. In backend/stack ...)
+	TODO: check
+CVE-2026-72861 (The github-issue-bot templates in appwrite/templates verify the GitHub ...)
+	TODO: check
+CVE-2026-72860 (The POST /api/provider-nodes/validate route in 9router takes a caller- ...)
+	TODO: check
+CVE-2026-72858
+	REJECTED
+CVE-2026-72848 (SitemapLoader.parse_sitemap in langchain_community/document_loaders/si ...)
+	TODO: check
+CVE-2026-72846 (Lightdash stores the webhook URL supplied with a scheduled delivery an ...)
+	TODO: check
+CVE-2026-72843 (The customer update route in EverShop is declared with "access": "publ ...)
+	TODO: check
+CVE-2026-72818 (The URLS regular expression in nltk/tokenize/casual.py, compiled into  ...)
+	TODO: check
+CVE-2026-71862 (Checkmate is an open-source, self-hosted tool designed to track and mo ...)
+	TODO: check
+CVE-2026-71494 (Infracost provides cloud cost intelligence for engineers, AI coding ag ...)
+	TODO: check
+CVE-2026-71493 (Infracost provides cloud cost intelligence for engineers, AI coding ag ...)
+	TODO: check
+CVE-2026-71485 (Centrifugo is an open-source scalable real-time messaging server. Prio ...)
+	TODO: check
+CVE-2026-70656 (Checkmate is an open-source, self-hosted tool designed to track and mo ...)
+	TODO: check
+CVE-2026-70654 (libvips is a fast image processing library with low memory needs. Prio ...)
+	TODO: check
+CVE-2026-70653 (libvips is a fast image processing library with low memory needs. Prio ...)
+	TODO: check
+CVE-2026-70652 (libvips is a fast image processing library with low memory needs. Prio ...)
+	TODO: check
+CVE-2026-70651 (libvips is a fast image processing library with low memory needs. Prio ...)
+	TODO: check
+CVE-2026-70105 (Improper input validation in Microsoft Office Word allows an unauthori ...)
+	TODO: check
+CVE-2026-69855 (Server-side request forgery (ssrf) in Microsoft Copilot in Azure allow ...)
+	TODO: check
+CVE-2026-69851 (Server-side request forgery (ssrf) in Azure Active Directory allows an ...)
+	TODO: check
+CVE-2026-69836 (Deserialization of untrusted data in Microsoft Entra ID allows an unau ...)
+	TODO: check
+CVE-2026-69701
+	REJECTED
+CVE-2026-69558 (Authorization bypass through user-controlled key in Microsoft Partner  ...)
+	TODO: check
+CVE-2026-69555 (Incorrect authorization in Azure Arc allows an unauthorized attacker t ...)
+	TODO: check
+CVE-2026-69543 (Server-side request forgery (ssrf) in Azure Virtual Machines allows an ...)
+	TODO: check
+CVE-2026-69519 (Observable response discrepancy in Azure Stack HCI allows an unauthori ...)
+	TODO: check
+CVE-2026-69502 (Server-side request forgery (ssrf) in Azure SQL Database allows an una ...)
+	TODO: check
+CVE-2026-69419 (Integer overflow or wraparound in Azure Data Manager for Energy allows ...)
+	TODO: check
+CVE-2026-69400 (Improper limitation of a pathname to a restricted directory ('path tra ...)
+	TODO: check
+CVE-2026-69242 (libvips is a fast image processing library with low memory needs. Prio ...)
+	TODO: check
+CVE-2026-69099
+	REJECTED
+CVE-2026-68921 (DiceBear is an avatar library for designers and developers. Prior to 9 ...)
+	TODO: check
+CVE-2026-68789 (Improper neutralization of special elements used in an sql command ('s ...)
+	TODO: check
+CVE-2026-68782 (Improper neutralization of special elements used in an sql command ('s ...)
+	TODO: check
+CVE-2026-68745 (Certificate validation failures in SAML authentication in Apache Cloud ...)
+	TODO: check
+CVE-2026-67567 (A flaw was found in the multicloud-operators-subscription component. T ...)
+	TODO: check
+CVE-2026-67448 (Mailpit is an email testing tool and API for developers. From 1.29.0 u ...)
+	TODO: check
+CVE-2026-67447 (Mailpit is an email testing tool and API for developers. From 1.30.0 u ...)
+	TODO: check
+CVE-2026-67446 (Mailpit is an email testing tool and API for developers. Prior to 1.30 ...)
+	TODO: check
+CVE-2026-67445 (Mailpit is an email testing tool and API for developers. Prior to 1.30 ...)
+	TODO: check
+CVE-2026-66722 (Improper authorization for CRUD operations on Project Roles and Projec ...)
+	TODO: check
+CVE-2026-66721 (Missing authorization issue for domain admins in CloudStack's host tag ...)
+	TODO: check
+CVE-2026-66309 (Improper access control in Azure SQL Database allows an authorized att ...)
+	TODO: check
+CVE-2026-65816 (Use of incorrectly-resolved name or reference in Azure Arc allows an u ...)
+	TODO: check
+CVE-2026-65801 (Server-side request forgery (ssrf) in Microsoft Exchange Online allows ...)
+	TODO: check
+CVE-2026-65770 (Improper neutralization of argument delimiters in a command ('argument ...)
+	TODO: check
+CVE-2026-65645 (Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3. ...)
+	TODO: check
+CVE-2026-65644 (Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3. ...)
+	TODO: check
+CVE-2026-65613 (Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...)
+	TODO: check
+CVE-2026-64773 (An attacker that can reach a container's published TCP port may be abl ...)
+	TODO: check
+CVE-2026-63726
+	REJECTED
+CVE-2026-63723
+	REJECTED
+CVE-2026-63509 (Relative path traversal in Microsoft Fabric allows an authorized attac ...)
+	TODO: check
+CVE-2026-63466 (Unleash is an open-source feature management platform. Prior to 8.0.3, ...)
+	TODO: check
+CVE-2026-63462 (Unleash is an open-source feature management platform. Prior to 7.5.2, ...)
+	TODO: check
+CVE-2026-63046 (Improper Neutralization of Argument Delimiters in a Command ('Argument ...)
+	TODO: check
+CVE-2026-63004 (Unleash is an open-source feature management platform. Prior to 7.5.2, ...)
+	TODO: check
+CVE-2026-62945 (TREK is a collaborative travel planner. Prior to 3.1.3, TREK file uplo ...)
+	TODO: check
+CVE-2026-62834 (Improper verification of cryptographic signature in Azure Data Factory ...)
+	TODO: check
+CVE-2026-62677 (Omnigent is an open-source AI agent framework and meta-harness for orc ...)
+	TODO: check
+CVE-2026-62676 (Omnigent is an open-source AI agent framework and meta-harness for orc ...)
+	TODO: check
+CVE-2026-62675 (Omnigent is an open-source AI agent framework and meta-harness for orc ...)
+	TODO: check
+CVE-2026-62674 (Omnigent is an open-source AI agent framework and meta-harness for orc ...)
+	TODO: check
+CVE-2026-62440 (Improper Access Control vulnerability in Apache CloudStack's Kubernete ...)
+	TODO: check
+CVE-2026-61422 (Authenticated pre-validation SSRF vulnerability in Apache CloudStack's ...)
+	TODO: check
+CVE-2026-61400 (Improper Neutralization of Special Elements used in a Command ('Comman ...)
+	TODO: check
+CVE-2026-61399 (Improper Encoding or Escaping of Output vulnerability in Apache CloudS ...)
+	TODO: check
+CVE-2026-61398 (Improper Encoding or Escaping of Output vulnerability in Apache CloudS ...)
+	TODO: check
+CVE-2026-61397 (Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...)
+	TODO: check
+CVE-2026-59799 (Improper Privilege Management vulnerability in Apache CloudStack's Two ...)
+	TODO: check
+CVE-2026-59780 (Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...)
+	TODO: check
+CVE-2026-59657 (Cleartext Storage of Sensitive Information vulnerability in Apache Clo ...)
+	TODO: check
+CVE-2026-59655 (Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...)
+	TODO: check
+CVE-2026-59654 (Missing Release of Resource after Effective Lifetime vulnerability in  ...)
+	TODO: check
+CVE-2026-59323 (An application using Micrometer Tracing with W3C baggage propagation i ...)
+	TODO: check
+CVE-2026-59318 (In Spring AI's tool calling support, the per-request tool list is adve ...)
+	TODO: check
+CVE-2026-59308 (In Spring AI's Semantic Cache support, the context hash used to isolat ...)
+	TODO: check
+CVE-2026-59296 (Using untrusted, non-normalized input as-is for metrics data (such as  ...)
+	TODO: check
+CVE-2026-59279 (The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) ...)
+	TODO: check
+CVE-2026-59085 (Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack' ...)
+	TODO: check
+CVE-2026-57835
+	REJECTED
+CVE-2026-56875
+	REJECTED
+CVE-2026-55894 (Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Caps ...)
+	TODO: check
+CVE-2026-55893 (Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Caps ...)
+	TODO: check
+CVE-2026-55850 (Element Web is a Matrix web client built using the Matrix React SDK. P ...)
+	TODO: check
+CVE-2026-55769 (CloudNativePG is a platform designed to manage PostgreSQL databases wi ...)
+	TODO: check
+CVE-2026-55765 (CloudNativePG is a platform designed to manage PostgreSQL databases wi ...)
+	TODO: check
+CVE-2026-55491 (BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, Bi ...)
+	TODO: check
+CVE-2026-55489 (BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, Bi ...)
+	TODO: check
+CVE-2026-55241 (Checkmate is an open-source, self-hosted tool designed to track and mo ...)
+	TODO: check
+CVE-2026-55015 (Uncontrolled search path element in Windows Remote Help allows an auth ...)
+	TODO: check
+CVE-2026-55013 (Uncontrolled search path element in Windows Remote Help Defense allows ...)
+	TODO: check
+CVE-2026-54789 (mod_auth_openidc is an OpenID Certified authentication and authorizati ...)
+	TODO: check
+CVE-2026-54682 (DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2 ...)
+	TODO: check
+CVE-2026-54681 (DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2 ...)
+	TODO: check
+CVE-2026-54509 (TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GE ...)
+	TODO: check
+CVE-2026-54508 (TREK is a collaborative travel planner. Prior to 3.1.0, TREK validates ...)
+	TODO: check
+CVE-2026-54505 (TREK is a collaborative travel planner. Prior to 3.1.0, when the Journ ...)
+	TODO: check
+CVE-2026-54389 (Ghidra before 12.1.3 contains an uncontrolled resource consumption vul ...)
+	TODO: check
+CVE-2026-54134 (OctoPrint provides a web interface for controlling consumer 3D printer ...)
+	TODO: check
+CVE-2026-54073 (VeraCrypt provides disk encryption with strong security based on TrueC ...)
+	TODO: check
+CVE-2026-54071 (BabelDOC is a document translation tool. Prior to 0.6.3, BabelDOC's ve ...)
+	TODO: check
+CVE-2026-53991
+	REJECTED
+CVE-2026-53974
+	REJECTED
+CVE-2026-53804 (OTRS Community Edition contains an authenticated OS command injection  ...)
+	TODO: check
+CVE-2026-53762 (VeraCrypt provides disk encryption with strong security based on TrueC ...)
+	TODO: check
+CVE-2026-52021 (An issue in code100xDevs 100xdevs CMS v.1.0 (2026-04-30) allows a remo ...)
+	TODO: check
+CVE-2026-50278 (iccDEV provides a set of libraries and tools for working with ICC colo ...)
+	TODO: check
+CVE-2026-50222 (Missing Authorization, Exposure of Sensitive Information to an Unautho ...)
+	TODO: check
+CVE-2026-50192 (Kerberos Agent is an open source video (surveillance) management agent ...)
+	TODO: check
+CVE-2026-50112 (SSRF via Metalink Mirror URL Resolution:  An authenticated tenant can  ...)
+	TODO: check
+CVE-2026-49436 (LinkAce is a self-hosted archive to collect website links. Prior to ve ...)
+	TODO: check
+CVE-2026-49245 (SFTPGo is an open source, event-driven file transfer solution. From 2. ...)
+	TODO: check
+CVE-2026-49244 (SFTPGo is an open source, event-driven file transfer solution. From 2. ...)
+	TODO: check
+CVE-2026-49217 (Mailu is a mail server as a set of Docker images. Prior to version 202 ...)
+	TODO: check
+CVE-2026-49114 (In ONNX before 1.21.0, the 'save_external_data' function builds the ex ...)
+	TODO: check
+CVE-2026-48590 (XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module ...)
+	TODO: check
+CVE-2026-47827 (Command Injection in BOSH CLI tool on windows in Cloud Foundry allows  ...)
+	TODO: check
+CVE-2026-47359 (Improper Neutralization of Special Elements used in an OS Command ('OS ...)
+	TODO: check
+CVE-2026-47080 (XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module ...)
+	TODO: check
+CVE-2026-47079 (Inappropriate Encoding for Output Context vulnerability in joshnuss xm ...)
+	TODO: check
+CVE-2026-46682 (BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, Bi ...)
+	TODO: check
+CVE-2026-46355 (BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, Bi ...)
+	TODO: check
+CVE-2026-45202 (Software installed and run as a non-privileged user may conduct GPU sy ...)
+	TODO: check
+CVE-2026-45201 (Software installed and run as a non-privileged user may conduct improp ...)
+	TODO: check
+CVE-2026-45199 (Kernel software installed and running inside a Guest VM may post impro ...)
+	TODO: check
+CVE-2026-43798 (A single crafted SSH message gives an unauthenticated network attacker ...)
+	TODO: check
+CVE-2026-43679 (This issue was addressed with improved permissions checking. This issu ...)
+	TODO: check
+CVE-2026-41451 (UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a  ...)
+	TODO: check
+CVE-2026-41450 (UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a  ...)
+	TODO: check
+CVE-2026-41449 (UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a  ...)
+	TODO: check
+CVE-2026-39909 (llama.cpp before b8585 contains a use-after-free vulnerability in the  ...)
+	TODO: check
+CVE-2026-35163 (OctoPrint provides a web interface for controlling consumer 3D printer ...)
+	TODO: check
+CVE-2026-27875 (Cleartext Storage of Sensitive Information in Memory vulnerability in  ...)
+	TODO: check
+CVE-2026-22681 (OpenViking before 0.3.4contains a server-side request forgery vulnerab ...)
+	TODO: check
+CVE-2026-20679 (The issue was addressed with improved checks. This issue is fixed in m ...)
+	TODO: check
+CVE-2026-19848 (The ProfilePress WordPress plugin before 4.17.1 does not strip shortco ...)
+	TODO: check
+CVE-2026-19783 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+	TODO: check
+CVE-2026-19755 (NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw di ...)
+	TODO: check
+CVE-2026-19449 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in c ...)
+	TODO: check
+CVE-2026-19448 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruptio ...)
+	TODO: check
+CVE-2026-19446 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthen ...)
+	TODO: check
+CVE-2026-19442 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation ...)
+	TODO: check
+CVE-2026-19441 (Missing authentication for critical function vulnerability in IKAS Tec ...)
+	TODO: check
+CVE-2026-19437 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-19435 (The Duplicate Post WordPress plugin before 1.5.6 does not check the us ...)
+	TODO: check
+CVE-2026-19085 (The Duplicate Post WordPress plugin before 1.5.6 does not check that a ...)
+	TODO: check
+CVE-2026-18842 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+	TODO: check
+CVE-2026-18840 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+	TODO: check
+CVE-2026-18835 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote aut ...)
+	TODO: check
+CVE-2026-18832 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-18828 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-18824 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote aut ...)
+	TODO: check
+CVE-2026-18822 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+	TODO: check
+CVE-2026-18781 (The Drag and Drop Multiple File Upload for Contact Form 7 WordPress pl ...)
+	TODO: check
+CVE-2026-18716 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote aut ...)
+	TODO: check
+CVE-2026-18670 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-18420 (Improper input validation in the Time Series Visual Builder (TSVB) plu ...)
+	TODO: check
+CVE-2026-18409 (The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Sit ...)
+	TODO: check
+CVE-2026-18356 (The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does n ...)
+	TODO: check
+CVE-2026-17559 (The Passster WordPress plugin before 4.3.9 does not correctly match it ...)
+	TODO: check
+CVE-2026-17436 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-17425 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-17424 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-17423 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-17422 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+	TODO: check
+CVE-2026-17252 (A stack-based out-of-bounds write vulnerability exists in the login re ...)
+	TODO: check
+CVE-2026-17251 (A NULL pointer dereference vulnerability exists in the HTTP request pa ...)
+	TODO: check
+CVE-2026-17250 (A stack-based buffer overflow vulnerability exists in the firmware upd ...)
+	TODO: check
+CVE-2026-17195 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+	TODO: check
+CVE-2026-17171 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+	TODO: check
+CVE-2026-17170 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-17168 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote aut ...)
+	TODO: check
+CVE-2026-17165 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-17163 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-17160 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-17159 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-17157 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-17152 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-17145 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-17142 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-17141 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-17138 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-17136 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-17124 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+	TODO: check
+CVE-2026-17122 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-17121 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-17120 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-17118 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-17060 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-17040 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-17024 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-17009 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+	TODO: check
+CVE-2026-17007 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+	TODO: check
+CVE-2026-17006 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-17003 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-17000 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-16997 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+	TODO: check
+CVE-2026-16996 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+	TODO: check
+CVE-2026-16991 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+	TODO: check
+CVE-2026-16989 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+	TODO: check
+CVE-2026-16980 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+	TODO: check
+CVE-2026-16973 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+	TODO: check
+CVE-2026-16972 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-16964 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-16962 (The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify  ...)
+	TODO: check
+CVE-2026-16959 (The Media Library Assistant WordPress plugin before 3.40 does not vali ...)
+	TODO: check
+CVE-2026-16958 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-16952 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+	TODO: check
+CVE-2026-16951 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local auth ...)
+	TODO: check
+CVE-2026-16946 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+	TODO: check
+CVE-2026-16945 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+	TODO: check
+CVE-2026-16944 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+	TODO: check
+CVE-2026-16943 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+	TODO: check
+CVE-2026-16937 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+	TODO: check
+CVE-2026-16936 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+	TODO: check
+CVE-2026-16935 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+	TODO: check
+CVE-2026-16934 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+	TODO: check
+CVE-2026-16650 (The Charitable WordPress plugin before 1.8.12 does not verify the auth ...)
+	TODO: check
+CVE-2026-16577 (The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution  Wo ...)
+	TODO: check
+CVE-2026-16576 (The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution  Wo ...)
+	TODO: check
+CVE-2026-16575 (The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution  Wo ...)
+	TODO: check
+CVE-2026-16520 (Improper input validation and Exposure of sensitive information throug ...)
+	TODO: check
+CVE-2026-16323 (Execution after redirect (EAR) vulnerability in FuyaWeb Internet and I ...)
+	TODO: check
+CVE-2026-15580 (vault token disclosure via unvalidated postMessage vulnerability in N- ...)
+	TODO: check
+CVE-2026-15576 (Improper authentication in the agent receiver of Checkmk <2.5.0p10 all ...)
+	TODO: check
+CVE-2026-15150 (The myCred WordPress plugin before 3.2.5 does not verify that the rece ...)
+	TODO: check
+CVE-2026-15046 (The LitExtension WordPress plugin through 1.2.5 does not verify a nonc ...)
+	TODO: check
+CVE-2026-14601 (The Link Whisper Free WordPress plugin before 0.9.7 does not properly  ...)
+	TODO: check
+CVE-2026-14325 (The Drag and Drop Multiple File Upload for Contact Form 7 WordPress pl ...)
+	TODO: check
+CVE-2026-14208 (Remote Utilities Host <=7.7.3.0 sets insecure ACLs on all DLL files in ...)
+	TODO: check
+CVE-2026-13736 (The NewPath WildApricotPress Add-on  WordPress plugin through 1.0.0 do ...)
+	TODO: check
+CVE-2026-13176 (The Eventin WordPress plugin before 4.1.21 does not validate a user-su ...)
+	TODO: check
+CVE-2026-11938
+	REJECTED
+CVE-2026-11902
+	REJECTED
+CVE-2026-11830
+	REJECTED
+CVE-2026-11427
+	REJECTED
+CVE-2025-52182 (The Library Corporation LS2 Admin v5.7 to v5.8.0 was discovered to con ...)
+	TODO: check
+CVE-2025-3127
+	REJECTED
+CVE-2025-2795
+	REJECTED
+CVE-2025-15671 (The Welcart e-Commerce WordPress plugin before 2.12.1 does not regener ...)
+	TODO: check
+CVE-2023-7344
+	REJECTED
+CVE-2023-7336
+	REJECTED
+CVE-2023-7310
+	REJECTED
+CVE-2021-4482
+	REJECTED
+CVE-2021-4476
+	REJECTED
+CVE-2021-4475
+	REJECTED
+CVE-2019-25725
+	REJECTED
+CVE-2019-25715
+	REJECTED
+CVE-2017-20232
+	REJECTED
+CVE-2026-74583 (In the Linux kernel, the following vulnerability has been resolved:  n ...)
 	- linux 7.1.9-1
 	NOTE: https://git.kernel.org/linus/47d7f7051253bdc02b1d245d87e38f16d31a74df (7.2-rc7)
-CVE-2026-74582 [packet: use consistent hard_header_len in non-ring send paths]
+CVE-2026-74582 (In the Linux kernel, the following vulnerability has been resolved:  p ...)
 	- linux 7.1.9-1
 	NOTE: https://git.kernel.org/linus/03390aa32e669cc4ecd7d34108e2e1afc13d689d (7.2-rc7)
-CVE-2026-74581 [net: ipv6: clear suppressed fib6 rule result]
+CVE-2026-74581 (In the Linux kernel, the following vulnerability has been resolved:  n ...)
 	- linux 7.1.8-1
 	NOTE: https://git.kernel.org/linus/6aea62e433fe1b586202a5fee8b5807ce635e1d7 (7.2-rc6)
-CVE-2026-74580 [vhost: reset the vring metadata cache on vring reconfiguration]
+CVE-2026-74580 (In the Linux kernel, the following vulnerability has been resolved:  v ...)
 	- linux 7.1.9-1
 	NOTE: https://git.kernel.org/linus/de845981da67a6b049080c87e605130b0c30adc5 (7.2-rc7)
 CVE-2026-19685
@@ -1550,7 +2196,7 @@ CVE-2026-76216 (Vikunja through 2.4.0 contains a principal-type confusion vulner
 	NOT-FOR-US: Vikunja
 CVE-2026-76215 (phpMyFAQ before 4.1.7 fails to apply parent FAQ visibility checks befo ...)
 	NOT-FOR-US: phpMyFAQ
-CVE-2026-76214 (phpMyFAQ before 4.1.7 (affected versions <= 4.1.5) fails to persist th ...)
+CVE-2026-76214 (phpMyFAQ before 4.1.7 fails to persist the WebAuthn login challenge ge ...)
 	NOT-FOR-US: phpMyFAQ
 CVE-2026-76213 (phpMyFAQ before 4.1.7 contains a brute-force vulnerability in the two- ...)
 	NOT-FOR-US: phpMyFAQ
@@ -1558,7 +2204,7 @@ CVE-2026-76212 (phpMyFAQ before 4.1.7, when configured to use PostgreSQL via the
 	NOT-FOR-US: phpMyFAQ
 CVE-2026-76211 (phpMyFAQ before 4.1.7 fails to properly enforce CONFIGURATION_EDIT per ...)
 	NOT-FOR-US: phpMyFAQ
-CVE-2026-76210 (phpMyFAQ before 4.1.7 does not adequately sanitize HTML in FAQ answers ...)
+CVE-2026-76210 (phpMyFAQ before 4.1.6 does not adequately sanitize HTML in FAQ answers ...)
 	NOT-FOR-US: phpMyFAQ
 CVE-2026-76209 (phpMyFAQ versions before v4.1.6 fail to validate the security.enableRe ...)
 	NOT-FOR-US: phpMyFAQ
@@ -1748,7 +2394,8 @@ CVE-2026-70422 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains an
 	NOT-FOR-US: Dell / EMC
 CVE-2026-70421 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Impro ...)
 	NOT-FOR-US: Dell / EMC
-CVE-2026-69159 (FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...)
+CVE-2026-69159
+	REJECTED
 	- freerdp3 3.29.0+dfsg-1
 	[trixie] - freerdp3 <no-dsa> (Minor issue)
 	- freerdp2 <removed>
@@ -4326,48 +4973,63 @@ CVE-2026-60589 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Ora
 	- openjdk-8 8u504-ga-1
 	NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-08-18
 CVE-2026-76034 (Buffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allo ...)
+	{DSA-6455-1 DLA-4749-1}
 	- chromium 151.0.7922.169-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76036 (Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0. ...)
+	{DSA-6455-1 DLA-4749-1}
 	- chromium 151.0.7922.169-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76033 (Inappropriate implementation in CORS in Google Chrome prior to 151.0.7 ...)
+	{DSA-6455-1 DLA-4749-1}
 	- chromium 151.0.7922.169-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76037 (Link following in CredentialProvider in Google Chrome on on Windows pr ...)
+	{DSA-6455-1 DLA-4749-1}
 	- chromium 151.0.7922.169-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76044 (Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed ...)
+	{DSA-6455-1 DLA-4749-1}
 	- chromium 151.0.7922.169-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76039 (Incorrect reference resolution in Core in Google Chrome on on Android  ...)
+	{DSA-6455-1 DLA-4749-1}
 	- chromium 151.0.7922.169-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76040 (Use after free in Browser in Google Chrome on on Mac prior to 151.0.79 ...)
+	{DSA-6455-1 DLA-4749-1}
 	- chromium 151.0.7922.169-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76035 (Inappropriate implementation in Media in Google Chrome on on Mac prior ...)
+	{DSA-6455-1 DLA-4749-1}
 	- chromium 151.0.7922.169-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76042 (Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7 ...)
+	{DSA-6455-1 DLA-4749-1}
 	- chromium 151.0.7922.169-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76046 (Buffer overflow in ANGLE in Google Chrome on on Android prior to 151.0 ...)
+	{DSA-6455-1 DLA-4749-1}
 	- chromium 151.0.7922.169-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76043 (Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 a ...)
+	{DSA-6455-1 DLA-4749-1}
 	- chromium 151.0.7922.169-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76041 (Information leak in Skia in Google Chrome prior to 151.0.7922.169 allo ...)
+	{DSA-6455-1 DLA-4749-1}
 	- chromium 151.0.7922.169-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76047 (Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed  ...)
+	{DSA-6455-1 DLA-4749-1}
 	- chromium 151.0.7922.169-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76038 (Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed  ...)
+	{DSA-6455-1 DLA-4749-1}
 	- chromium 151.0.7922.169-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76045 (Use after free in WebGL in Google Chrome prior to 151.0.7922.169 allow ...)
+	{DSA-6455-1 DLA-4749-1}
 	- chromium 151.0.7922.169-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-75926 (Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permis ...)
@@ -4496,7 +5158,7 @@ CVE-2026-75032 (A flaw was found in BlueZ. Insufficient validation of packet len
 	NOTE: Fixed by: https://github.com/bluez/bluez/commit/bd8989620ed6e80755f06cfdb18f5b4a3913493c
 	NOTE: Followup: https://github.com/bluez/bluez/commit/58088149872d014684a582fdb7ad01a5180c9bc5
 CVE-2026-74990 (Internally found bugs present in Thunderbird ESR 140.13, Thunderbird E ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4510,7 +5172,7 @@ CVE-2026-74988 (Internally found bugs present in Thunderbird ESR 153.0 and Thund
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74988
 CVE-2026-74987 (Internally found bugs present in Thunderbird ESR 140.13, Thunderbird E ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4527,7 +5189,7 @@ CVE-2026-74984 (Race condition in the JavaScript Engine component. This vulnerab
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74984
 CVE-2026-74983 (Mitigation bypass in the Data Loss Prevention component. This vulnerab ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4553,7 +5215,7 @@ CVE-2026-74977 (Integer overflow in the Graphics component. This vulnerability w
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74977
 CVE-2026-74976 (JIT miscompilation in the JavaScript Engine: JIT component. This vulne ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4564,7 +5226,7 @@ CVE-2026-74975 (Spoofing issue in the Downloads component in Firefox for Android
 	- firefox <not-affected> (Only affects Firefox on Android)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74975
 CVE-2026-74974 (Same-origin policy bypass in the Graphics: ImageLib component. This vu ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4572,7 +5234,7 @@ CVE-2026-74974 (Same-origin policy bypass in the Graphics: ImageLib component. T
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74974
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74974
 CVE-2026-74973 (Race condition, use-after-free in the Graphics component. This vulnera ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4580,7 +5242,7 @@ CVE-2026-74973 (Race condition, use-after-free in the Graphics component. This v
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74973
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74973
 CVE-2026-74972 (Information disclosure in the DOM: Push Subscriptions component. This  ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4588,7 +5250,7 @@ CVE-2026-74972 (Information disclosure in the DOM: Push Subscriptions component.
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74972
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74972
 CVE-2026-74971 (Information disclosure in the DOM: UI Events & Focus Handling componen ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4599,7 +5261,7 @@ CVE-2026-74970 (Site isolation issue in the Graphics component. This vulnerabili
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74970
 CVE-2026-74969 (Use-after-free in the Layout: Text and Fonts component. This vulnerabi ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4610,7 +5272,7 @@ CVE-2026-74968 (Site isolation issue in the Graphics: WebRender component. This
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74968
 CVE-2026-74967 (Same-origin policy bypass in the Audio/Video: Playback component. This ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4621,7 +5283,7 @@ CVE-2026-74966 (Information disclosure in the Form Autofill component. This vuln
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74966
 CVE-2026-74965 (Privilege escalation in the Shell Integration component. This vulnerab ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4629,7 +5291,7 @@ CVE-2026-74965 (Privilege escalation in the Shell Integration component. This vu
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74965
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74965
 CVE-2026-74964 (Integer overflow in the Graphics component. This vulnerability was fix ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4637,7 +5299,7 @@ CVE-2026-74964 (Integer overflow in the Graphics component. This vulnerability w
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74964
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74964
 CVE-2026-74963 (Same-origin policy bypass in the Networking: Cookies component. This v ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4645,7 +5307,7 @@ CVE-2026-74963 (Same-origin policy bypass in the Networking: Cookies component.
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74963
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74963
 CVE-2026-74962 (Site isolation issue in the Networking: Cookies component. This vulner ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4656,7 +5318,7 @@ CVE-2026-74961 (Side-channel in the Web Audio component. This vulnerability was
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74961
 CVE-2026-74960 (Site isolation issue in the WebExtensions component. This vulnerabilit ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4664,7 +5326,7 @@ CVE-2026-74960 (Site isolation issue in the WebExtensions component. This vulner
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74960
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74960
 CVE-2026-74959 (Mitigation bypass in the Storage: Cache API component. This vulnerabil ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4675,7 +5337,7 @@ CVE-2026-74958 (Information disclosure in the WebRTC component. This vulnerabili
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74958
 CVE-2026-74957 (Mitigation bypass in the Safe Browsing component. This vulnerability w ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4692,7 +5354,7 @@ CVE-2026-74954 (Information disclosure due to side-channel in the Storage: Cache
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74954
 CVE-2026-74953 (Privilege escalation in the Networking: Cookies component. This vulner ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4709,7 +5371,7 @@ CVE-2026-74950 (Privilege escalation in the Downloads API component. This vulner
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74950
 CVE-2026-74949 (Privilege escalation due to use-after-free in the Graphics: Canvas2D c ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4717,7 +5379,7 @@ CVE-2026-74949 (Privilege escalation due to use-after-free in the Graphics: Canv
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74949
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74949
 CVE-2026-74948 (Information disclosure in the Graphics component. This vulnerability w ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4728,7 +5390,7 @@ CVE-2026-74947 (Privilege escalation due to invalid pointer in the Graphics comp
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74947
 CVE-2026-74946 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4736,7 +5398,7 @@ CVE-2026-74946 (Privilege escalation due to incorrect boundary conditions in the
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74946
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74946
 CVE-2026-74945 (Information disclosure in the Graphics: Text component. This vulnerabi ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4744,7 +5406,7 @@ CVE-2026-74945 (Information disclosure in the Graphics: Text component. This vul
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74945
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74945
 CVE-2026-74944 (Use-after-free in the DOM: Core & HTML component. This vulnerability w ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4752,7 +5414,7 @@ CVE-2026-74944 (Use-after-free in the DOM: Core & HTML component. This vulnerabi
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74944
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74944
 CVE-2026-74943 (Use-after-free in the Graphics: ImageLib component. This vulnerability ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4760,7 +5422,7 @@ CVE-2026-74943 (Use-after-free in the Graphics: ImageLib component. This vulnera
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74943
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74943
 CVE-2026-74942 (Privilege escalation in the Remote Settings Client component. This vul ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4768,7 +5430,7 @@ CVE-2026-74942 (Privilege escalation in the Remote Settings Client component. Th
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74942
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74942
 CVE-2026-74941 (Privilege escalation in the Graphics: CanvasWebGL component. This vuln ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4776,7 +5438,7 @@ CVE-2026-74941 (Privilege escalation in the Graphics: CanvasWebGL component. Thi
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74941
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74941
 CVE-2026-74940 (Use-after-free in the Graphics: Text component. This vulnerability was ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4784,7 +5446,7 @@ CVE-2026-74940 (Use-after-free in the Graphics: Text component. This vulnerabili
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74940
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74940
 CVE-2026-74939 (Privilege escalation in the DOM: Navigation component. This vulnerabil ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4798,7 +5460,7 @@ CVE-2026-74937 (Use-after-free in the JavaScript: GC component. This vulnerabili
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74937
 CVE-2026-74936 (Use-after-free in the JavaScript: WebAssembly component. This vulnerab ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4806,7 +5468,7 @@ CVE-2026-74936 (Use-after-free in the JavaScript: WebAssembly component. This vu
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74936
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74936
 CVE-2026-74935 (Privilege escalation in the DOM: Networking component. This vulnerabil ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -4814,7 +5476,7 @@ CVE-2026-74935 (Privilege escalation in the DOM: Networking component. This vuln
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74935
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74935
 CVE-2026-74934 (Site isolation issue in the Graphics: CanvasWebGL component. This vuln ...)
-	{DSA-6451-1}
+	{DSA-6451-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -6329,11 +6991,11 @@ CVE-2026-13700 (The WooMS WordPress plugin through 9.14 does not validate a user
 	NOT-FOR-US: WordPress plugin
 CVE-2026-66801
 	NOT-FOR-US: Red Hat cluster-backup-operator
-CVE-2026-66800
+CVE-2026-66800 (Server-side request forgery (ssrf) in Azure Data Factory allows an una ...)
 	NOT-FOR-US: Red Hat cluster-backup-operator
 CVE-2026-66798
 	NOT-FOR-US: Red Hat cluster-backup-operator
-CVE-2026-66797
+CVE-2026-66797 (Improper access control in CloudStack's annotation functionality allow ...)
 	NOT-FOR-US: Red Hat cluster-backup-operator
 CVE-2026-18725
 	- open-iscsi <unfixed> (bug #1144935)
@@ -14137,7 +14799,7 @@ CVE-2026-XXXX [OSSN-0106: API ramdisk endpoints require network-level access con
 	NOTE: https://wiki.openstack.org/wiki/OSSN/OSSN-0106
 	NOTE: https://bugs.launchpad.net/ironic/+bug/2162821
 	NOTE: https://bugs.launchpad.net/ironic/+bug/2162818
-CVE-2026-77648 [OSSN-0105: OpenStack Glance legacy Tasks import bypasses image import URI filtering]
+CVE-2026-77648 (In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=imp ...)
 	- glance 2:32.0.0-3 (bug #1144212)
 	[trixie] - glance <no-dsa> (Minor issue)
 	NOTE: https://wiki.openstack.org/wiki/OSSN/OSSN-0105
@@ -15281,7 +15943,7 @@ CVE-2026-65797 (Numeric truncation error in Windows DNS allows an authorized att
 	NOT-FOR-US: Microsoft
 CVE-2026-65796 (Heap-based buffer overflow in Windows iSCSI Target Service allows an u ...)
 	NOT-FOR-US: Microsoft
-CVE-2026-65795 (No cwe for this issue in Windows DNS allows an authorized attacker to  ...)
+CVE-2026-65795 (Relative path traversal in Windows DNS allows an authorized attacker t ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-65794 (Buffer over-read in Windows SMB Client allows an unauthorized attacker ...)
 	NOT-FOR-US: Microsoft
@@ -17214,7 +17876,8 @@ CVE-2026-XXXX [RCE fixed in 4.4.21]
 	- spip 4.4.21+dfsg-1
 	[trixie] - spip 4.4.21+dfsg-0+deb13u1
 	NOTE: https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-21.html
-CVE-2026-77647 [RCE fixed in 4.4.20]
+CVE-2026-77647 (SPIP before 4.4.20 allows unauthenticated remote attackers to execute  ...)
+	{DSA-6448-1}
 	- spip 4.4.20+dfsg-1
 	NOTE: https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-20.html
 CVE-2026-66738 (SPIP before 4.4.18 contains a code injection vulnerability in SQLite-b ...)
@@ -25091,12 +25754,12 @@ CVE-2026-XXXX [GHSA-p2v3-6wvc-cv3p: Arbitrary file write on host via image finge
 	[trixie] - incus 6.0.4-2+deb13u9
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-p2v3-6wvc-cv3p
 	NOTE: https://github.com/lxc/incus/pull/3750
-CVE-2026-63343 [Arbitrary file read+write on host via metadata.yaml symlink in crafted image]
+CVE-2026-63343 (Incus is a system container and virtual machine manager. Prior to vers ...)
 	{DSA-6407-1}
 	- incus 7.0.1-2
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-fmjx-5j3g-997p
 	NOTE: https://github.com/lxc/incus/pull/3750
-CVE-2026-63125 [Arbitrary file write on host via backup.yaml symlink in crafted image]
+CVE-2026-63125 (Incus is a system container and virtual machine manager. Prior to vers ...)
 	{DSA-6407-1}
 	- incus 7.0.1-2
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-6rqx-22hc-qm36
@@ -25106,22 +25769,22 @@ CVE-2026-XXXX [GHSA-m3j6-p3v3-qmjv: Container configuration newline injection th
 	[trixie] - incus 6.0.4-2+deb13u9
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-m3j6-p3v3-qmjv
 	NOTE: https://github.com/lxc/incus/pull/3750
-CVE-2026-62941 [Project restriction bypass via cross-project instance copy]
+CVE-2026-62941 (Incus is a system container and virtual machine manager. Prior to vers ...)
 	{DSA-6407-1}
 	- incus 7.0.1-2
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-mq9x-prm8-3vpw
 	NOTE: https://github.com/lxc/incus/pull/3750
-CVE-2026-62940 [Project restriction bypass via instance migration config override]
+CVE-2026-62940 (Incus is a system container and virtual machine manager. Prior to vers ...)
 	{DSA-6407-1}
 	- incus 7.0.1-2
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-qw5c-v953-38gw
 	NOTE: https://github.com/lxc/incus/pull/3750
-CVE-2026-62867 [Argument injection through storage volume block.create_options]
+CVE-2026-62867 (Incus is a system container and virtual machine manager. Prior to vers ...)
 	{DSA-6407-1}
 	- incus 7.0.1-2
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-q7xw-r4w2-2wcm
 	NOTE: https://github.com/lxc/incus/pull/3750
-CVE-2026-62313 [Project isolation restriction bypass by omitting security.idmap.isolated]
+CVE-2026-62313 (Incus is a system container and virtual machine manager. Prior to vers ...)
 	{DSA-6407-1}
 	- incus 7.0.1-2
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-53cg-qvg7-m8vg
@@ -55592,31 +56255,38 @@ CVE-2026-XXXX [TROVE-2026-015]
 	[bookworm] - tor 0.4.9.11-0+deb12u1
 	[bullseye] - tor <end-of-life> (see DSA 5562)
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41261
-CVE-2026-77642 [TROVE-2026-019]
+CVE-2026-77642 (tor before 0.4.9.9 was prone to anout-of-bounds write when parsing a c ...)
+	{DSA-6372-1}
 	- tor 0.4.9.9-1
 	[bullseye] - tor <end-of-life> (see DSA 5562)
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41267
-CVE-2026-77641 [TROVE-2026-017]
+CVE-2026-77641 (tor before 0.4.9.9 was prone to aNULL write after free when sending a  ...)
+	{DSA-6372-1}
 	- tor 0.4.9.9-1
 	[bullseye] - tor <end-of-life> (see DSA 5562)
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41263
-CVE-2026-77639 [TROVE-2026-022]
+CVE-2026-77639 (Tor before 0.4.9.9 was prone to acompression bomb bypass where an atta ...)
+	{DSA-6372-1}
 	- tor 0.4.9.9-1
 	[bullseye] - tor <end-of-life> (see DSA 5562)
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41275
-CVE-2026-77640 [TROVE-2026-021]
+CVE-2026-77640 (tor before 0.4.9.9 was prone to an infinite loop when decompressing a  ...)
+	{DSA-6372-1}
 	- tor 0.4.9.9-1
 	[bullseye] - tor <end-of-life> (see DSA 5562)
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41274
-CVE-2026-77584 [TROVE-2026-025]
+CVE-2026-77584 (Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on ...)
+	{DSA-6372-1}
 	- tor 0.4.9.11-1
 	[bullseye] - tor <end-of-life> (see DSA 5562)
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41258 (private ATM)
-CVE-2026-77587 [TROVE-2026-026]
+CVE-2026-77587 (Tor before 0.4.9.11 is prone to a use-after-free (and potential double ...)
+	{DSA-6372-1}
 	- tor 0.4.9.11-1
 	[bullseye] - tor <end-of-life> (see DSA 5562)
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41306
-CVE-2026-77638
+CVE-2026-77638 (Tor before 0.4.9.11 is prone to a race condition where in just the rig ...)
+	{DSA-6372-1}
 	- tor 0.4.9.11-1
 	[bullseye] - tor <end-of-life> (see DSA 5562)
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41297
@@ -56903,21 +57573,21 @@ CVE-2021-47986 (Parse Server before 4.10.0 contains a supply chain vulnerability
 	NOT-FOR-US: Parse Server
 CVE-2020-37256 (Grav before 1.6.30 contains a cross-site scripting vulnerability in th ...)
 	NOT-FOR-US: Grav CMS
-CVE-2026-48750
+CVE-2026-48750 (Incus is a system container and virtual machine manager. Prior to vers ...)
 	{DSA-6373-1 DSA-6370-1}
 	- incus 7.0.0-5
 	- lxd <removed>
 	[bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-73hr-m85f-64v9
 	NOTE: https://github.com/canonical/lxd/pull/18590
-CVE-2026-48751
+CVE-2026-48751 (Incus is a system container and virtual machine manager. Prior to vers ...)
 	{DSA-6373-1 DSA-6370-1}
 	- incus 7.0.0-5
 	- lxd <removed>
 	[bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-48q5-w887-33wv
 	NOTE: https://github.com/canonical/lxd/pull/18604
-CVE-2026-48752
+CVE-2026-48752 (Incus is a system container and virtual machine manager. Prior to vers ...)
 	{DSA-6373-1 DSA-6370-1}
 	- incus 7.0.0-5
 	- lxd <removed>
@@ -56925,7 +57595,7 @@ CVE-2026-48752
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-vxp5-584q-c479
 	NOTE: https://github.com/lxc/incus/commit/cbefa31ae0da8fd96361178aed3a3c631e098fef (v7.2.0)
 	NOTE: https://github.com/canonical/lxd/pull/18590
-CVE-2026-48755
+CVE-2026-48755 (Incus is a system container and virtual machine manager. Prior to vers ...)
 	{DSA-6373-1 DSA-6370-1}
 	- incus 7.0.0-5
 	- lxd <removed>
@@ -56933,7 +57603,7 @@ CVE-2026-48755
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-v6mj-8pf4-hhw4
 	NOTE: https://github.com/lxc/incus/commit/873a032a461df6b09b7586435b592873863a4e88 (v7.2.0)
 	NOTE: https://github.com/canonical/lxd/pull/18597
-CVE-2026-48769
+CVE-2026-48769 (Incus is a system container and virtual machine manager. Prior to vers ...)
 	{DSA-6373-1 DSA-6370-1}
 	- incus 7.0.0-5
 	- lxd <removed>
@@ -56941,7 +57611,7 @@ CVE-2026-48769
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-f6m5-xw2g-xc4x
 	NOTE: https://github.com/lxc/incus/commit/46d6ef232186df5535c49ca9f3597cab381f9b86 (v7.2.0)
 	NOTE: https://github.com/canonical/lxd/pull/18594
-CVE-2026-55621
+CVE-2026-55621 (Incus is a system container and virtual machine manager. Prior to vers ...)
 	{DSA-6373-1 DSA-6370-1}
 	- incus 7.0.0-5
 	- lxd <removed>
@@ -56949,7 +57619,7 @@ CVE-2026-55621
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-64f3-v33m-w89f
 	NOTE: https://github.com/lxc/incus/commit/2e01078366e2653712719dec82318e51c6d21b28 (v7.2.0)
 	NOTE: https://github.com/canonical/lxd/pull/18603
-CVE-2026-55622
+CVE-2026-55622 (Incus is a system container and virtual machine manager. Prior to vers ...)
 	{DSA-6373-1 DSA-6370-1}
 	- incus 7.0.0-5
 	- lxd <removed>
@@ -56957,14 +57627,14 @@ CVE-2026-55622
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-c9f5-j9c3-mhrg
 	NOTE: https://github.com/lxc/incus/commit/1e3ffc53a10950e55de62ac1e0d612be597b84eb (v7.2.0)
 	NOTE: https://github.com/canonical/lxd/pull/18603
-CVE-2026-48749
+CVE-2026-48749 (Incus is a system container and virtual machine manager. Prior to vers ...)
 	{DSA-6373-1 DSA-6370-1}
 	- incus 7.0.0-5
 	- lxd <removed>
 	[bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-2q3f-q5pq-g8wv
 	NOTE: https://github.com/canonical/lxd/pull/18590
-CVE-2026-77506 [ZSA-2026-12]
+CVE-2026-77506 (Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS.)
 	- znuny 6.5.22-1
 	[trixie] - znuny <no-dsa> (Non-free not supported)
 	[bookworm] - znuny <no-dsa> (Non-free not supported)
@@ -77618,22 +78288,22 @@ CVE-2025-14042 (The Automotive Car Dealership Business WordPress Theme for WordP
 	NOT-FOR-US: WordPress plugin
 CVE-2025-11993 (The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPre ...)
 	NOT-FOR-US: WordPress plugin
-CVE-2026-48756
+CVE-2026-48756 (Incus is a system container and virtual machine manager. Prior to vers ...)
 	{DSA-6370-1}
 	- incus 7.0.0-2
 	NOTE: https://github.com/lxc/incus/pull/3425
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-xhqx-mgh3-3h7q
-CVE-2026-48754
+CVE-2026-48754 (Incus is a system container and virtual machine manager. Prior to vers ...)
 	- incus 7.0.0-2
 	[trixie] - incus <not-affected> (Vulnerable code not present)
 	NOTE: https://github.com/lxc/incus/pull/3425
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-4xg6-52mh-fpw8
-CVE-2026-48753
+CVE-2026-48753 (Incus is a system container and virtual machine manager. Prior to vers ...)
 	- incus 7.0.0-2
 	[trixie] - incus <not-affected> (Vulnerable code not present)
 	NOTE: https://github.com/lxc/incus/pull/3425
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-ccjc-4qc3-jxqc
-CVE-2026-47753
+CVE-2026-47753 (Incus is a system container and virtual machine manager. Prior to vers ...)
 	- incus 7.0.0-2
 	[trixie] - incus <not-affected> (Vulnerable code not present)
 	NOTE: https://github.com/lxc/incus/pull/3425
@@ -792467,7 +793137,7 @@ CVE-2018-0500 (Curl_smtp_escape_eob in lib/smtp.c in curl 7.54.1 to and includin
 	[stretch] - curl <not-affected> (Only affects 7.54.1 to 7.60.0)
 	[jessie] - curl <not-affected> (Only affects 7.54.1 to 7.60.0)
 	NOTE: https://curl.haxx.se/docs/adv_2018-70a2.html
-CVE-2026-77643 [missing corner-case of CVE-2018-0499]
+CVE-2026-77643 (A cross-site scripting vulnerability in  queryparser/termgenerator_int ...)
 	- xapian-core 1.4.32-1 (bug #1144490)
 	[trixie] - xapian-core <no-dsa> (Minor issue)
 	NOTE: https://lists.xapian.org/pipermail/xapian-devel/2026-August/003429.html



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dce3666d65e30af868986916156973275c05ce01

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dce3666d65e30af868986916156973275c05ce01
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260821/8ea39110/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list