[Git][security-tracker-team/security-tracker][master] Process some new NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 21 20:48:11 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c07471f6 by Salvatore Bonaccorso at 2026-08-21T21:47:43+02:00
Process some new NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -7,31 +7,31 @@ CVE-2026-9244
 CVE-2026-9012
 	REJECTED
 CVE-2026-77815 (to_abs_path in scripts/iib/tool.py normalised the requested path with  ...)
-	TODO: check
+	NOT-FOR-US: zanllp infinite-image-browsing
 CVE-2026-77814 (is_path_trusted in scripts/iib/api.py compares the requested path agai ...)
-	TODO: check
+	NOT-FOR-US: zanllp infinite-image-browsing
 CVE-2026-77812 (DJI drones transmit DUML (DJI Universal Markup Language) protocol mess ...)
 	NOT-FOR-US: DJI
 CVE-2026-77795 (A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.6.2.  ...)
-	TODO: check
+	NOT-FOR-US: Dromara RuoYi-Vue-Plus
 CVE-2026-77780 (Authorization Bypass Through User-Controlled Key in the transaction sa ...)
-	TODO: check
+	NOT-FOR-US: Roskus Prospero Flow CRM
 CVE-2026-77776 (Headroom's LLM proxy derives the memory owner from the x-headroom-user ...)
-	TODO: check
+	NOT-FOR-US: Headroom's LLM proxy
 CVE-2026-77775 (Headroom's LLM proxy lets a client choose the upstream destination wit ...)
-	TODO: check
+	NOT-FOR-US: Headroom's LLM proxy
 CVE-2026-77769 (The report.list procedure in packages/trpc/src/routers/report.ts accep ...)
-	TODO: check
+	NOT-FOR-US: OpenPanel
 CVE-2026-77768 (The report.get procedure in packages/trpc/src/routers/report.ts accept ...)
-	TODO: check
+	NOT-FOR-US: OpenPanel
 CVE-2026-77767 (Reconmap's API applies a fallback authorization policy in apps/api/app ...)
-	TODO: check
+	NOT-FOR-US: Reconmap
 CVE-2026-77763 (The filestore backend in pkg/object/file.go, used for file:// stores a ...)
 	TODO: check
 CVE-2026-77761 (A parser state isolation vulnerability in misp-stix could cause data f ...)
 	TODO: check
 CVE-2026-77759 (Authorization Bypass Through User-Controlled Key in the transaction AP ...)
-	TODO: check
+	NOT-FOR-US: Roskus Prospero Flow CRM
 CVE-2026-77755 (A denial-of-service vulnerability was identified in misp-stix when pro ...)
 	TODO: check
 CVE-2026-77751 (A path traversal vulnerability existed in the handling of MISP object  ...)
@@ -41,9 +41,9 @@ CVE-2026-77710 (A vulnerability in misp-stix could allow a crafted STIX document
 CVE-2026-77686 (A weakness has been identified in Dolibarr up to 23.0.4. This affects  ...)
 	NOT-FOR-US: Dolibarr
 CVE-2026-77683 (A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affect ...)
-	TODO: check
+	NOT-FOR-US: Comfast
 CVE-2026-77681 (A vulnerability was identified in CodeAstro Online Job Portal 1.0. Aff ...)
-	TODO: check
+	NOT-FOR-US: CodeAstro Online Job Portal
 CVE-2026-77651 (The arrayref crate 0.3.10 for Rust can trigger execution of malicious  ...)
 	TODO: check
 CVE-2026-77650 (The append-only-vec crate 0.1.9 for Rust can trigger execution of mali ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c07471f615cffb2a2cd4b2692f712c8c706c1463

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c07471f615cffb2a2cd4b2692f712c8c706c1463
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260821/e04c1c74/attachment.htm>


More information about the debian-security-tracker-commits mailing list