[Git][security-tracker-team/security-tracker][master] Process some new NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 21 20:48:11 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
c07471f6 by Salvatore Bonaccorso at 2026-08-21T21:47:43+02:00
Process some new NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -7,31 +7,31 @@ CVE-2026-9244
CVE-2026-9012
REJECTED
CVE-2026-77815 (to_abs_path in scripts/iib/tool.py normalised the requested path with ...)
- TODO: check
+ NOT-FOR-US: zanllp infinite-image-browsing
CVE-2026-77814 (is_path_trusted in scripts/iib/api.py compares the requested path agai ...)
- TODO: check
+ NOT-FOR-US: zanllp infinite-image-browsing
CVE-2026-77812 (DJI drones transmit DUML (DJI Universal Markup Language) protocol mess ...)
NOT-FOR-US: DJI
CVE-2026-77795 (A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.6.2. ...)
- TODO: check
+ NOT-FOR-US: Dromara RuoYi-Vue-Plus
CVE-2026-77780 (Authorization Bypass Through User-Controlled Key in the transaction sa ...)
- TODO: check
+ NOT-FOR-US: Roskus Prospero Flow CRM
CVE-2026-77776 (Headroom's LLM proxy derives the memory owner from the x-headroom-user ...)
- TODO: check
+ NOT-FOR-US: Headroom's LLM proxy
CVE-2026-77775 (Headroom's LLM proxy lets a client choose the upstream destination wit ...)
- TODO: check
+ NOT-FOR-US: Headroom's LLM proxy
CVE-2026-77769 (The report.list procedure in packages/trpc/src/routers/report.ts accep ...)
- TODO: check
+ NOT-FOR-US: OpenPanel
CVE-2026-77768 (The report.get procedure in packages/trpc/src/routers/report.ts accept ...)
- TODO: check
+ NOT-FOR-US: OpenPanel
CVE-2026-77767 (Reconmap's API applies a fallback authorization policy in apps/api/app ...)
- TODO: check
+ NOT-FOR-US: Reconmap
CVE-2026-77763 (The filestore backend in pkg/object/file.go, used for file:// stores a ...)
TODO: check
CVE-2026-77761 (A parser state isolation vulnerability in misp-stix could cause data f ...)
TODO: check
CVE-2026-77759 (Authorization Bypass Through User-Controlled Key in the transaction AP ...)
- TODO: check
+ NOT-FOR-US: Roskus Prospero Flow CRM
CVE-2026-77755 (A denial-of-service vulnerability was identified in misp-stix when pro ...)
TODO: check
CVE-2026-77751 (A path traversal vulnerability existed in the handling of MISP object ...)
@@ -41,9 +41,9 @@ CVE-2026-77710 (A vulnerability in misp-stix could allow a crafted STIX document
CVE-2026-77686 (A weakness has been identified in Dolibarr up to 23.0.4. This affects ...)
NOT-FOR-US: Dolibarr
CVE-2026-77683 (A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affect ...)
- TODO: check
+ NOT-FOR-US: Comfast
CVE-2026-77681 (A vulnerability was identified in CodeAstro Online Job Portal 1.0. Aff ...)
- TODO: check
+ NOT-FOR-US: CodeAstro Online Job Portal
CVE-2026-77651 (The arrayref crate 0.3.10 for Rust can trigger execution of malicious ...)
TODO: check
CVE-2026-77650 (The append-only-vec crate 0.1.9 for Rust can trigger execution of mali ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c07471f615cffb2a2cd4b2692f712c8c706c1463
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c07471f615cffb2a2cd4b2692f712c8c706c1463
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260821/e04c1c74/attachment.htm>
More information about the debian-security-tracker-commits
mailing list