[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 21 20:14:57 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8960a777 by security tracker role at 2026-08-21T19:14:50+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -41,7 +41,7 @@ CVE-2026-77751 (A path traversal vulnerability existed in the handling of MISP o
 CVE-2026-77710 (A vulnerability in misp-stix could allow a crafted STIX document to in ...)
 	TODO: check
 CVE-2026-77686 (A weakness has been identified in Dolibarr up to 23.0.4. This affects  ...)
-	TODO: check
+	NOT-FOR-US: Dolibarr
 CVE-2026-77683 (A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affect ...)
 	TODO: check
 CVE-2026-77681 (A vulnerability was identified in CodeAstro Online Job Portal 1.0. Aff ...)
@@ -59,19 +59,19 @@ CVE-2026-77645 (A critical remote code execution (RCE) vulnerability has been re
 CVE-2026-77644 (A critical bypass access control vulnerability has been reported in PT ...)
 	TODO: check
 CVE-2026-77392 (A weakness has been identified in SourceCodester Dynamic Input Field G ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-77391 (A security flaw has been discovered in SourceCodester Dynamic Input Fi ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-77264 (The Automation Web Platform \u2013 Notifications and OTP for WooCommer ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-77237 (Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS- ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-77236 (Missing minimum size validation in secure context allocation in FreeRT ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-77235 (Missing privilege verification in the secure context cleanup handler i ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-77234 (Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-77151 (A security flaw has been discovered in lin-snow Ech0 up to 5.4.1. Affe ...)
 	TODO: check
 CVE-2026-77113 (Path traversal in apport-unpack in Canonical Apport before2.36.0,2.34. ...)
@@ -79,17 +79,17 @@ CVE-2026-77113 (Path traversal in apport-unpack in Canonical Apport before2.36.0
 CVE-2026-77087 (Paperclip before 0.3.1 in default local_trusted mode fails to validate ...)
 	TODO: check
 CVE-2026-77086 (SiYuan before v3.7.4 fails to validate the packageName parameter in Ba ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-77029 (Joomla Extension - yootheme.com - Missing CSRF tokens on front-end sta ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-77028 (Joomla Extension - yootheme.com - Reflected XSS and open redirect via  ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-76613 (Joomla Extension - yootheme.com - Authenticated, privileged SQL inject ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-76612 (Joomla Extension - yootheme.com - Unauthenticated stored XSS via user- ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-76611 (Joomla Extension - yootheme.com - Unauthenticated arbitrary directory  ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-76158 (External Control of File Name or Path in the upload API endpoint of Da ...)
 	TODO: check
 CVE-2026-76157 (Missing authentication for a critical function in the upload API endpo ...)
@@ -117,7 +117,7 @@ CVE-2026-76018 (Privilege elevation in Import in Google Chrome prior to 151.0.79
 CVE-2026-76017 (Use after free in Chromoting in Google Chrome prior to 151.0.7922.173  ...)
 	TODO: check
 CVE-2026-75946 (A potential security vulnerability has been identified in the OMEN Gam ...)
-	TODO: check
+	NOT-FOR-US: HP
 CVE-2026-75933 (Jet Admin allows an authenticated attacker to inject JavaScript via th ...)
 	TODO: check
 CVE-2026-75932 (Jet Admin allows an attacker to create a malicious app and connect it  ...)
@@ -125,15 +125,15 @@ CVE-2026-75932 (Jet Admin allows an attacker to create a malicious app and conne
 CVE-2026-75928 (The Brushfire platform's video content streaming application (https:// ...)
 	TODO: check
 CVE-2026-75910 (Incorrect privilege assignment in the ClickHouse connector deployment  ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-75796 (The AI Engine  WordPress plugin before 3.6.1 does not verify that the  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-75501 (A vulnerability in the Calix EXOS firmware for the GS7 XGS (GS5239XG)  ...)
 	TODO: check
 CVE-2026-75484 (Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerabi ...)
 	TODO: check
 CVE-2026-75115 (Joomla Extension - yootheme.com - Authenticated, privileged arbitrary  ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-74866 (@fastify/busboy is a multipart form-data parser for Node.js. Its multi ...)
 	TODO: check
 CVE-2026-74836 (Allocation of Resources Without Limits or Throttling vulnerability in  ...)
@@ -179,29 +179,29 @@ CVE-2026-70652 (libvips is a fast image processing library with low memory needs
 CVE-2026-70651 (libvips is a fast image processing library with low memory needs. Prio ...)
 	TODO: check
 CVE-2026-70105 (Improper input validation in Microsoft Office Word allows an unauthori ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-69855 (Server-side request forgery (ssrf) in Microsoft Copilot in Azure allow ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-69851 (Server-side request forgery (ssrf) in Azure Active Directory allows an ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-69836 (Deserialization of untrusted data in Microsoft Entra ID allows an unau ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-69701
 	REJECTED
 CVE-2026-69558 (Authorization bypass through user-controlled key in Microsoft Partner  ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-69555 (Incorrect authorization in Azure Arc allows an unauthorized attacker t ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-69543 (Server-side request forgery (ssrf) in Azure Virtual Machines allows an ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-69519 (Observable response discrepancy in Azure Stack HCI allows an unauthori ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-69502 (Server-side request forgery (ssrf) in Azure SQL Database allows an una ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-69419 (Integer overflow or wraparound in Azure Data Manager for Energy allows ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-69400 (Improper limitation of a pathname to a restricted directory ('path tra ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-69242 (libvips is a fast image processing library with low memory needs. Prio ...)
 	TODO: check
 CVE-2026-69099
@@ -209,11 +209,11 @@ CVE-2026-69099
 CVE-2026-68921 (DiceBear is an avatar library for designers and developers. Prior to 9 ...)
 	TODO: check
 CVE-2026-68789 (Improper neutralization of special elements used in an sql command ('s ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-68782 (Improper neutralization of special elements used in an sql command ('s ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-68745 (Certificate validation failures in SAML authentication in Apache Cloud ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-67567 (A flaw was found in the multicloud-operators-subscription component. T ...)
 	TODO: check
 CVE-2026-67448 (Mailpit is an email testing tool and API for developers. From 1.29.0 u ...)
@@ -225,43 +225,43 @@ CVE-2026-67446 (Mailpit is an email testing tool and API for developers. Prior t
 CVE-2026-67445 (Mailpit is an email testing tool and API for developers. Prior to 1.30 ...)
 	TODO: check
 CVE-2026-66722 (Improper authorization for CRUD operations on Project Roles and Projec ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-66721 (Missing authorization issue for domain admins in CloudStack's host tag ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-66309 (Improper access control in Azure SQL Database allows an authorized att ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-65816 (Use of incorrectly-resolved name or reference in Azure Arc allows an u ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-65801 (Server-side request forgery (ssrf) in Microsoft Exchange Online allows ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-65770 (Improper neutralization of argument delimiters in a command ('argument ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-65645 (Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3. ...)
 	TODO: check
 CVE-2026-65644 (Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3. ...)
 	TODO: check
 CVE-2026-65613 (Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-64773 (An attacker that can reach a container's published TCP port may be abl ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-63726
 	REJECTED
 CVE-2026-63723
 	REJECTED
 CVE-2026-63509 (Relative path traversal in Microsoft Fabric allows an authorized attac ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-63466 (Unleash is an open-source feature management platform. Prior to 8.0.3, ...)
 	TODO: check
 CVE-2026-63462 (Unleash is an open-source feature management platform. Prior to 7.5.2, ...)
 	TODO: check
 CVE-2026-63046 (Improper Neutralization of Argument Delimiters in a Command ('Argument ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-63004 (Unleash is an open-source feature management platform. Prior to 7.5.2, ...)
 	TODO: check
 CVE-2026-62945 (TREK is a collaborative travel planner. Prior to 3.1.3, TREK file uplo ...)
 	TODO: check
 CVE-2026-62834 (Improper verification of cryptographic signature in Azure Data Factory ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-62677 (Omnigent is an open-source AI agent framework and meta-harness for orc ...)
 	TODO: check
 CVE-2026-62676 (Omnigent is an open-source AI agent framework and meta-harness for orc ...)
@@ -271,39 +271,39 @@ CVE-2026-62675 (Omnigent is an open-source AI agent framework and meta-harness f
 CVE-2026-62674 (Omnigent is an open-source AI agent framework and meta-harness for orc ...)
 	TODO: check
 CVE-2026-62440 (Improper Access Control vulnerability in Apache CloudStack's Kubernete ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-61422 (Authenticated pre-validation SSRF vulnerability in Apache CloudStack's ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-61400 (Improper Neutralization of Special Elements used in a Command ('Comman ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-61399 (Improper Encoding or Escaping of Output vulnerability in Apache CloudS ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-61398 (Improper Encoding or Escaping of Output vulnerability in Apache CloudS ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-61397 (Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-59799 (Improper Privilege Management vulnerability in Apache CloudStack's Two ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-59780 (Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-59657 (Cleartext Storage of Sensitive Information vulnerability in Apache Clo ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-59655 (Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-59654 (Missing Release of Resource after Effective Lifetime vulnerability in  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-59323 (An application using Micrometer Tracing with W3C baggage propagation i ...)
 	TODO: check
 CVE-2026-59318 (In Spring AI's tool calling support, the per-request tool list is adve ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-59308 (In Spring AI's Semantic Cache support, the context hash used to isolat ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-59296 (Using untrusted, non-normalized input as-is for metrics data (such as  ...)
 	TODO: check
 CVE-2026-59279 (The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-59085 (Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack' ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-57835
 	REJECTED
 CVE-2026-56875
@@ -325,9 +325,9 @@ CVE-2026-55489 (BigBlueButton is an open-source virtual classroom. Prior to 3.0.
 CVE-2026-55241 (Checkmate is an open-source, self-hosted tool designed to track and mo ...)
 	TODO: check
 CVE-2026-55015 (Uncontrolled search path element in Windows Remote Help allows an auth ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-55013 (Uncontrolled search path element in Windows Remote Help Defense allows ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-54789 (mod_auth_openidc is an OpenID Certified authentication and authorizati ...)
 	TODO: check
 CVE-2026-54682 (DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2 ...)
@@ -361,11 +361,11 @@ CVE-2026-52021 (An issue in code100xDevs 100xdevs CMS v.1.0 (2026-04-30) allows
 CVE-2026-50278 (iccDEV provides a set of libraries and tools for working with ICC colo ...)
 	TODO: check
 CVE-2026-50222 (Missing Authorization, Exposure of Sensitive Information to an Unautho ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-50192 (Kerberos Agent is an open source video (surveillance) management agent ...)
 	TODO: check
 CVE-2026-50112 (SSRF via Metalink Mirror URL Resolution:  An authenticated tenant can  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-49436 (LinkAce is a self-hosted archive to collect website links. Prior to ve ...)
 	TODO: check
 CVE-2026-49245 (SFTPGo is an open source, event-driven file transfer solution. From 2. ...)
@@ -381,7 +381,7 @@ CVE-2026-48590 (XML Injection vulnerability in joshnuss xml_builder (XmlBuilder
 CVE-2026-47827 (Command Injection in BOSH CLI tool on windows in Cloud Foundry allows  ...)
 	TODO: check
 CVE-2026-47359 (Improper Neutralization of Special Elements used in an OS Command ('OS ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-47080 (XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module ...)
 	TODO: check
 CVE-2026-47079 (Inappropriate Encoding for Output Context vulnerability in joshnuss xm ...)
@@ -391,15 +391,15 @@ CVE-2026-46682 (BigBlueButton is an open-source virtual classroom. Prior to 3.0.
 CVE-2026-46355 (BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, Bi ...)
 	TODO: check
 CVE-2026-45202 (Software installed and run as a non-privileged user may conduct GPU sy ...)
-	TODO: check
+	NOT-FOR-US: Imagination Technologies
 CVE-2026-45201 (Software installed and run as a non-privileged user may conduct improp ...)
-	TODO: check
+	NOT-FOR-US: Imagination Technologies
 CVE-2026-45199 (Kernel software installed and running inside a Guest VM may post impro ...)
-	TODO: check
+	NOT-FOR-US: Imagination Technologies
 CVE-2026-43798 (A single crafted SSH message gives an unauthenticated network attacker ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-43679 (This issue was addressed with improved permissions checking. This issu ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-41451 (UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a  ...)
 	TODO: check
 CVE-2026-41450 (UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a  ...)
@@ -411,183 +411,183 @@ CVE-2026-39909 (llama.cpp before b8585 contains a use-after-free vulnerability i
 CVE-2026-35163 (OctoPrint provides a web interface for controlling consumer 3D printer ...)
 	TODO: check
 CVE-2026-27875 (Cleartext Storage of Sensitive Information in Memory vulnerability in  ...)
-	TODO: check
+	NOT-FOR-US: Johnson Controls
 CVE-2026-22681 (OpenViking before 0.3.4contains a server-side request forgery vulnerab ...)
 	TODO: check
 CVE-2026-20679 (The issue was addressed with improved checks. This issue is fixed in m ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-19848 (The ProfilePress WordPress plugin before 4.17.1 does not strip shortco ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-19783 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-19755 (NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw di ...)
 	TODO: check
 CVE-2026-19449 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in c ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-19448 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruptio ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-19446 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthen ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-19442 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-19441 (Missing authentication for critical function vulnerability in IKAS Tec ...)
 	TODO: check
 CVE-2026-19437 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-19435 (The Duplicate Post WordPress plugin before 1.5.6 does not check the us ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-19085 (The Duplicate Post WordPress plugin before 1.5.6 does not check that a ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18842 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18840 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18835 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote aut ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18832 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18828 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18824 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote aut ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18822 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18781 (The Drag and Drop Multiple File Upload for Contact Form 7 WordPress pl ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18716 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote aut ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18670 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18420 (Improper input validation in the Time Series Visual Builder (TSVB) plu ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-18409 (The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Sit ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18356 (The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does n ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-17559 (The Passster WordPress plugin before 4.3.9 does not correctly match it ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-17436 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17425 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17424 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17423 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17422 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17252 (A stack-based out-of-bounds write vulnerability exists in the login re ...)
-	TODO: check
+	NOT-FOR-US: TPLink
 CVE-2026-17251 (A NULL pointer dereference vulnerability exists in the HTTP request pa ...)
-	TODO: check
+	NOT-FOR-US: TPLink
 CVE-2026-17250 (A stack-based buffer overflow vulnerability exists in the firmware upd ...)
-	TODO: check
+	NOT-FOR-US: TPLink
 CVE-2026-17195 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17171 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17170 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17168 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote aut ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17165 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17163 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17160 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17159 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17157 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17152 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17145 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17142 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17141 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17138 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17136 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17124 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17122 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17121 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17120 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17118 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17060 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17040 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17024 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17009 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17007 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17006 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17003 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17000 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16997 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16996 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16991 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16989 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16980 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16973 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16972 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16964 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16962 (The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16959 (The Media Library Assistant WordPress plugin before 3.40 does not vali ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16958 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16952 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16951 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local auth ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16946 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16945 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16944 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16943 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16937 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16936 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16935 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16934 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16650 (The Charitable WordPress plugin before 1.8.12 does not verify the auth ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16577 (The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution  Wo ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16576 (The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution  Wo ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16575 (The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution  Wo ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16520 (Improper input validation and Exposure of sensitive information throug ...)
 	TODO: check
 CVE-2026-16323 (Execution after redirect (EAR) vulnerability in FuyaWeb Internet and I ...)
@@ -597,19 +597,19 @@ CVE-2026-15580 (vault token disclosure via unvalidated postMessage vulnerability
 CVE-2026-15576 (Improper authentication in the agent receiver of Checkmk <2.5.0p10 all ...)
 	TODO: check
 CVE-2026-15150 (The myCred WordPress plugin before 3.2.5 does not verify that the rece ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15046 (The LitExtension WordPress plugin through 1.2.5 does not verify a nonc ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14601 (The Link Whisper Free WordPress plugin before 0.9.7 does not properly  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14325 (The Drag and Drop Multiple File Upload for Contact Form 7 WordPress pl ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14208 (Remote Utilities Host <=7.7.3.0 sets insecure ACLs on all DLL files in ...)
 	TODO: check
 CVE-2026-13736 (The NewPath WildApricotPress Add-on  WordPress plugin through 1.0.0 do ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13176 (The Eventin WordPress plugin before 4.1.21 does not validate a user-su ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-11938
 	REJECTED
 CVE-2026-11902
@@ -625,7 +625,7 @@ CVE-2025-3127
 CVE-2025-2795
 	REJECTED
 CVE-2025-15671 (The Welcart e-Commerce WordPress plugin before 2.12.1 does not regener ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2023-7344
 	REJECTED
 CVE-2023-7336



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8960a777bf80c9b86daacd71728f5bcc59cf47c8

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8960a777bf80c9b86daacd71728f5bcc59cf47c8
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260821/6e6939c2/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list