[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 21 22:07:18 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a90cba16 by Salvatore Bonaccorso at 2026-08-21T23:06:30+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -128,57 +128,57 @@ CVE-2026-76017 (Use after free in Chromoting in Google Chrome prior to 151.0.792
 CVE-2026-75946 (A potential security vulnerability has been identified in the OMEN Gam ...)
 	NOT-FOR-US: HP
 CVE-2026-75933 (Jet Admin allows an authenticated attacker to inject JavaScript via th ...)
-	TODO: check
+	NOT-FOR-US: Jet Admin
 CVE-2026-75932 (Jet Admin allows an attacker to create a malicious app and connect it  ...)
-	TODO: check
+	NOT-FOR-US: Jet Admin
 CVE-2026-75928 (The Brushfire platform's video content streaming application (https:// ...)
-	TODO: check
+	NOT-FOR-US: Brushfire
 CVE-2026-75910 (Incorrect privilege assignment in the ClickHouse connector deployment  ...)
 	NOT-FOR-US: Amazon
 CVE-2026-75796 (The AI Engine  WordPress plugin before 3.6.1 does not verify that the  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-75501 (A vulnerability in the Calix EXOS firmware for the GS7 XGS (GS5239XG)  ...)
-	TODO: check
+	NOT-FOR-US: Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router
 CVE-2026-75484 (Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerabi ...)
-	TODO: check
+	NOT-FOR-US: Bandit (mtrudel/bandit, not the same as src:bandit)
 CVE-2026-75115 (Joomla Extension - yootheme.com - Authenticated, privileged arbitrary  ...)
 	NOT-FOR-US: Joomla
 CVE-2026-74866 (@fastify/busboy is a multipart form-data parser for Node.js. Its multi ...)
-	TODO: check
+	NOT-FOR-US: fastify/busboy
 CVE-2026-74836 (Allocation of Resources Without Limits or Throttling vulnerability in  ...)
-	TODO: check
+	NOT-FOR-US: Bandit (mtrudel/bandit, not the same as src:bandit)
 CVE-2026-73537 (Cross-site scripting vulnerability exists in Miraikan Assist App. If t ...)
-	TODO: check
+	NOT-FOR-US: Miraikan Assist App
 CVE-2026-73267 (A flaw was found in the clusterclaims-controller component of multiclu ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Multicluster Engine for Kubernetes
 CVE-2026-73137 (A flaw was found in the multicloud-operators-subscription component of ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Advanced Cluster Management (RHACM)
 CVE-2026-73040 (Dockge validates a stack name only on the write path. In backend/stack ...)
-	TODO: check
+	NOT-FOR-US: Dockge
 CVE-2026-72861 (The github-issue-bot templates in appwrite/templates verify the GitHub ...)
-	TODO: check
+	NOT-FOR-US: appwrite/templates
 CVE-2026-72860 (The POST /api/provider-nodes/validate route in 9router takes a caller- ...)
-	TODO: check
+	NOT-FOR-US: 9router
 CVE-2026-72858
 	REJECTED
 CVE-2026-72848 (SitemapLoader.parse_sitemap in langchain_community/document_loaders/si ...)
-	TODO: check
+	NOT-FOR-US: langchain
 CVE-2026-72846 (Lightdash stores the webhook URL supplied with a scheduled delivery an ...)
-	TODO: check
+	NOT-FOR-US: Lightdash
 CVE-2026-72843 (The customer update route in EverShop is declared with "access": "publ ...)
-	TODO: check
+	NOT-FOR-US: EverShop
 CVE-2026-72818 (The URLS regular expression in nltk/tokenize/casual.py, compiled into  ...)
 	TODO: check
 CVE-2026-71862 (Checkmate is an open-source, self-hosted tool designed to track and mo ...)
-	TODO: check
+	NOT-FOR-US: Checkmate
 CVE-2026-71494 (Infracost provides cloud cost intelligence for engineers, AI coding ag ...)
-	TODO: check
+	NOT-FOR-US: Infracost
 CVE-2026-71493 (Infracost provides cloud cost intelligence for engineers, AI coding ag ...)
-	TODO: check
+	NOT-FOR-US: Infracost
 CVE-2026-71485 (Centrifugo is an open-source scalable real-time messaging server. Prio ...)
-	TODO: check
+	NOT-FOR-US: Centrifugo
 CVE-2026-70656 (Checkmate is an open-source, self-hosted tool designed to track and mo ...)
-	TODO: check
+	NOT-FOR-US: Checkmate
 CVE-2026-70654 (libvips is a fast image processing library with low memory needs. Prio ...)
 	- vips 8.18.3-1
 	NOTE: https://github.com/libvips/libvips/security/advisories/GHSA-rjmm-3qch-m9rg
@@ -228,11 +228,10 @@ CVE-2026-69242 (libvips is a fast image processing library with low memory needs
 	NOTE: https://github.com/libvips/libvips/security/advisories/GHSA-9rwc-f68v-4482
 	NOTE: https://github.com/libvips/libvips/pull/5012
 	NOTE: Fixed by: https://github.com/libvips/libvips/commit/c72f50927413cd2451837d9813f954bc5d88f548 (v8.18.3-rc1)
-	TODO: check
 CVE-2026-69099
 	REJECTED
 CVE-2026-68921 (DiceBear is an avatar library for designers and developers. Prior to 9 ...)
-	TODO: check
+	NOT-FOR-US: DiceBear
 CVE-2026-68789 (Improper neutralization of special elements used in an sql command ('s ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-68782 (Improper neutralization of special elements used in an sql command ('s ...)
@@ -240,15 +239,15 @@ CVE-2026-68782 (Improper neutralization of special elements used in an sql comma
 CVE-2026-68745 (Certificate validation failures in SAML authentication in Apache Cloud ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-67567 (A flaw was found in the multicloud-operators-subscription component. T ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
 CVE-2026-67448 (Mailpit is an email testing tool and API for developers. From 1.29.0 u ...)
-	TODO: check
+	NOT-FOR-US: Mailpit
 CVE-2026-67447 (Mailpit is an email testing tool and API for developers. From 1.30.0 u ...)
-	TODO: check
+	NOT-FOR-US: Mailpit
 CVE-2026-67446 (Mailpit is an email testing tool and API for developers. Prior to 1.30 ...)
-	TODO: check
+	NOT-FOR-US: Mailpit
 CVE-2026-67445 (Mailpit is an email testing tool and API for developers. Prior to 1.30 ...)
-	TODO: check
+	NOT-FOR-US: Mailpit
 CVE-2026-66722 (Improper authorization for CRUD operations on Project Roles and Projec ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-66721 (Missing authorization issue for domain admins in CloudStack's host tag ...)
@@ -262,9 +261,9 @@ CVE-2026-65801 (Server-side request forgery (ssrf) in Microsoft Exchange Online
 CVE-2026-65770 (Improper neutralization of argument delimiters in a command ('argument ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-65645 (Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3. ...)
-	TODO: check
+	NOT-FOR-US: Rocket.Chat
 CVE-2026-65644 (Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3. ...)
-	TODO: check
+	NOT-FOR-US: Rocket.Chat
 CVE-2026-65613 (Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-64773 (An attacker that can reach a container's published TCP port may be abl ...)
@@ -276,25 +275,25 @@ CVE-2026-63723
 CVE-2026-63509 (Relative path traversal in Microsoft Fabric allows an authorized attac ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-63466 (Unleash is an open-source feature management platform. Prior to 8.0.3, ...)
-	TODO: check
+	NOT-FOR-US: Unleash
 CVE-2026-63462 (Unleash is an open-source feature management platform. Prior to 7.5.2, ...)
-	TODO: check
+	NOT-FOR-US: Unleash
 CVE-2026-63046 (Improper Neutralization of Argument Delimiters in a Command ('Argument ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-63004 (Unleash is an open-source feature management platform. Prior to 7.5.2, ...)
-	TODO: check
+	NOT-FOR-US: Unleash
 CVE-2026-62945 (TREK is a collaborative travel planner. Prior to 3.1.3, TREK file uplo ...)
-	TODO: check
+	NOT-FOR-US: TREK
 CVE-2026-62834 (Improper verification of cryptographic signature in Azure Data Factory ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-62677 (Omnigent is an open-source AI agent framework and meta-harness for orc ...)
-	TODO: check
+	NOT-FOR-US: Omnigent
 CVE-2026-62676 (Omnigent is an open-source AI agent framework and meta-harness for orc ...)
-	TODO: check
+	NOT-FOR-US: Omnigent
 CVE-2026-62675 (Omnigent is an open-source AI agent framework and meta-harness for orc ...)
-	TODO: check
+	NOT-FOR-US: Omnigent
 CVE-2026-62674 (Omnigent is an open-source AI agent framework and meta-harness for orc ...)
-	TODO: check
+	NOT-FOR-US: Omnigent
 CVE-2026-62440 (Improper Access Control vulnerability in Apache CloudStack's Kubernete ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-61422 (Authenticated pre-validation SSRF vulnerability in Apache CloudStack's ...)
@@ -340,15 +339,15 @@ CVE-2026-55893 (Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier
 CVE-2026-55850 (Element Web is a Matrix web client built using the Matrix React SDK. P ...)
 	TODO: check
 CVE-2026-55769 (CloudNativePG is a platform designed to manage PostgreSQL databases wi ...)
-	TODO: check
+	NOT-FOR-US: CloudNativePG
 CVE-2026-55765 (CloudNativePG is a platform designed to manage PostgreSQL databases wi ...)
-	TODO: check
+	NOT-FOR-US: CloudNativePG
 CVE-2026-55491 (BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, Bi ...)
-	TODO: check
+	NOT-FOR-US: BigBlueButton
 CVE-2026-55489 (BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, Bi ...)
-	TODO: check
+	NOT-FOR-US: BigBlueButton
 CVE-2026-55241 (Checkmate is an open-source, self-hosted tool designed to track and mo ...)
-	TODO: check
+	NOT-FOR-US: Checkmate
 CVE-2026-55015 (Uncontrolled search path element in Windows Remote Help allows an auth ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-55013 (Uncontrolled search path element in Windows Remote Help Defense allows ...)
@@ -356,23 +355,23 @@ CVE-2026-55013 (Uncontrolled search path element in Windows Remote Help Defense
 CVE-2026-54789 (mod_auth_openidc is an OpenID Certified authentication and authorizati ...)
 	TODO: check
 CVE-2026-54682 (DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2 ...)
-	TODO: check
+	NOT-FOR-US: DiscordChatExporter
 CVE-2026-54681 (DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2 ...)
-	TODO: check
+	NOT-FOR-US: DiscordChatExporter
 CVE-2026-54509 (TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GE ...)
-	TODO: check
+	NOT-FOR-US: TREK
 CVE-2026-54508 (TREK is a collaborative travel planner. Prior to 3.1.0, TREK validates ...)
-	TODO: check
+	NOT-FOR-US: TREK
 CVE-2026-54505 (TREK is a collaborative travel planner. Prior to 3.1.0, when the Journ ...)
-	TODO: check
+	NOT-FOR-US: TREK
 CVE-2026-54389 (Ghidra before 12.1.3 contains an uncontrolled resource consumption vul ...)
 	TODO: check
 CVE-2026-54134 (OctoPrint provides a web interface for controlling consumer 3D printer ...)
 	TODO: check
 CVE-2026-54073 (VeraCrypt provides disk encryption with strong security based on TrueC ...)
-	TODO: check
+	NOT-FOR-US: VeraCrypt
 CVE-2026-54071 (BabelDOC is a document translation tool. Prior to 0.6.3, BabelDOC's ve ...)
-	TODO: check
+	NOT-FOR-US: BabelDOC
 CVE-2026-53991
 	REJECTED
 CVE-2026-53974
@@ -380,37 +379,37 @@ CVE-2026-53974
 CVE-2026-53804 (OTRS Community Edition contains an authenticated OS command injection  ...)
 	TODO: check
 CVE-2026-53762 (VeraCrypt provides disk encryption with strong security based on TrueC ...)
-	TODO: check
+	NOT-FOR-US: VeraCrypt
 CVE-2026-52021 (An issue in code100xDevs 100xdevs CMS v.1.0 (2026-04-30) allows a remo ...)
-	TODO: check
+	NOT-FOR-US: code100xDevs 100xdevs CMS
 CVE-2026-50278 (iccDEV provides a set of libraries and tools for working with ICC colo ...)
-	TODO: check
+	NOT-FOR-US: iccDEV
 CVE-2026-50222 (Missing Authorization, Exposure of Sensitive Information to an Unautho ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-50192 (Kerberos Agent is an open source video (surveillance) management agent ...)
-	TODO: check
+	NOT-FOR-US: Kerberos Agent
 CVE-2026-50112 (SSRF via Metalink Mirror URL Resolution:  An authenticated tenant can  ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-49436 (LinkAce is a self-hosted archive to collect website links. Prior to ve ...)
-	TODO: check
+	NOT-FOR-US: LinkAce
 CVE-2026-49245 (SFTPGo is an open source, event-driven file transfer solution. From 2. ...)
 	TODO: check
 CVE-2026-49244 (SFTPGo is an open source, event-driven file transfer solution. From 2. ...)
 	TODO: check
 CVE-2026-49217 (Mailu is a mail server as a set of Docker images. Prior to version 202 ...)
-	TODO: check
+	NOT-FOR-US: Mailu
 CVE-2026-49114 (In ONNX before 1.21.0, the 'save_external_data' function builds the ex ...)
 	TODO: check
 CVE-2026-48590 (XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module ...)
-	TODO: check
+	NOT-FOR-US: joshnuss xml_builder
 CVE-2026-47827 (Command Injection in BOSH CLI tool on windows in Cloud Foundry allows  ...)
-	TODO: check
+	NOT-FOR-US: BOSH CLI tool
 CVE-2026-47359 (Improper Neutralization of Special Elements used in an OS Command ('OS ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-47080 (XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module ...)
-	TODO: check
+	NOT-FOR-US: joshnuss xml_builder
 CVE-2026-47079 (Inappropriate Encoding for Output Context vulnerability in joshnuss xm ...)
-	TODO: check
+	NOT-FOR-US: joshnuss xml_builder
 CVE-2026-46682 (BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, Bi ...)
 	TODO: check
 CVE-2026-46355 (BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, Bi ...)
@@ -1121,7 +1120,7 @@ CVE-2026-61663 (django CMS is an easy-to-use and developer-friendly enterprise c
 CVE-2026-61625 (VictoriaMetrics is a scalable solution for monitoring and managing tim ...)
 	NOT-FOR-US: VictoriaMetrics
 CVE-2026-55642 (dbx is a cross-platform database client for databases. Prior to 0.5.51 ...)
-	TODO: check
+	NOT-FOR-US: dbx
 CVE-2026-55586 (SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, ...)
 	NOT-FOR-US: SumatraPDF
 CVE-2026-55558 (aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior  ...)
@@ -1157,7 +1156,7 @@ CVE-2026-53425 (Insufficient Verification of Data Authenticity vulnerability in
 CVE-2026-53424 (Authentication Bypass by Capture-replay vulnerability in dropbox samly ...)
 	TODO: check
 CVE-2026-49996 (SecureDrop Client is a desktop app for journalists to securely communi ...)
-	TODO: check
+	NOT-FOR-US: SecureDrop Client
 CVE-2026-49825 (lxml is a library for processing XML and HTML in the Python language.  ...)
 	TODO: check
 CVE-2026-46537
@@ -2580,19 +2579,19 @@ CVE-2026-52889 (Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27
 CVE-2026-52834 (jxl-oxide is a pure Rust implementation of a JPEG XL decoder. Prior to ...)
 	TODO: check
 CVE-2026-52792 (Algernon is a small self-contained pure-Go web server. Prior to 1.17.9 ...)
-	TODO: check
+	NOT-FOR-US: github.com/xyproto/algernon
 CVE-2026-51367 (An issue in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote  ...)
-	TODO: check
+	NOT-FOR-US: Bottinelli Informatica Vedo Suite
 CVE-2026-51366 (SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2 ...)
-	TODO: check
+	NOT-FOR-US: Bottinelli Informatica Vedo Suite
 CVE-2026-50720 (The Ingenic T31 SoC boot ROM flash-boot verification path compares onl ...)
-	TODO: check
+	NOT-FOR-US: Ingenic
 CVE-2026-50719 (The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs pars ...)
-	TODO: check
+	NOT-FOR-US: Ingenic
 CVE-2026-50550 (Snipe-IT is an IT asset/license management system. Prior to 8.5.0, a u ...)
 	TODO: check
 CVE-2026-50173 (Flow-Like is a platform for building end-to-end use cases. Prior to ve ...)
-	TODO: check
+	NOT-FOR-US: Flow-Like
 CVE-2026-49976 (Snipe-IT is an IT asset/license management system. Prior to 8.6.1, a u ...)
 	TODO: check
 CVE-2026-49870 (Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POS ...)
@@ -2602,25 +2601,25 @@ CVE-2026-49817 (Dell Command Update (DCU), versions prior to 5.7.1, contain a De
 CVE-2026-49816 (Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserial ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-49441 (Wazuh is a free and open source platform used for threat prevention, d ...)
-	TODO: check
+	NOT-FOR-US: Wazuh
 CVE-2026-49425 (The compat32 kevent() handler translates a 64-bit kevent struct into a ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-49424 (The Linux waitid() implementation translates a FreeBSD siginfo_t struc ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-49392 (Wazuh is a free and open source platform used for threat prevention, d ...)
-	TODO: check
+	NOT-FOR-US: Wazuh
 CVE-2026-49289 (The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related fun ...)
 	TODO: check
 CVE-2026-49283 (The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related fun ...)
 	TODO: check
 CVE-2026-49255 (electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VN ...)
-	TODO: check
+	NOT-FOR-US: electerm
 CVE-2026-49253 (electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VN ...)
-	TODO: check
+	NOT-FOR-US: electerm
 CVE-2026-48162 (Wazuh is a free and open source platform used for threat prevention, d ...)
-	TODO: check
+	NOT-FOR-US: Wazuh
 CVE-2026-48024 (Wazuh is a free and open source platform used for threat prevention, d ...)
-	TODO: check
+	NOT-FOR-US: Wazuh
 CVE-2026-46343 (Wazuh is a free and open source platform used for threat prevention, d ...)
 	TODO: check
 CVE-2026-45798 (Wazuh is a free and open source platform used for threat prevention, d ...)
@@ -4802,13 +4801,13 @@ CVE-2026-50186 (4gaBoards is a boards system for realtime project management. Pr
 CVE-2026-49500 (Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, con ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-49431 (The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly validated  ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-49430 (The ZFS_IOC_RECV_NEW ioctl, in the heal receive path, similarly trunca ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-49429 (The ZFS_IOC_USERSPACE_MANY ioctl, used by zfs-userspace(8), truncated  ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-49428 (Certain system calls, such open(2) with the O_TRUNC flag set, and fspa ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-49427 (Pages belonging to largepage shared memory objects were not explicitly ...)
 	NOT-FOR-US: FreeBSD
 CVE-2026-49426 (When auditing a system call executed via ptrace(PT_SC_REMOTE), the ker ...)
@@ -4818,23 +4817,23 @@ CVE-2026-49423 (When building the iovec array for a received TLS 1.2 CBC record,
 CVE-2026-49422 (The RACK setsockopt(2) handler drops the connection lock in order to c ...)
 	NOT-FOR-US: FreeBSD
 CVE-2026-49421 (The kernel function that implements unlinkat(2) and funlinkat(2) valid ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-49420 (The RTSP handler in libalias rewrote outgoing packets into a fixed-len ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-49419 (When the JAIL_AT_DESC flag is specified, kern_jail_set() and kern_jail ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-49418 (When msync(MS_INVALIDATE) is called on a mapping of an unmanaged devic ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-49415 (During execve(2) of a SUID binary, the new virtual address space is in ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-48796 (CefSharp provides .NET bindings for the Chromium Embedded Framework fo ...)
-	TODO: check
+	NOT-FOR-US: CefSharp
 CVE-2026-47721 (FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ...)
-	TODO: check
+	NOT-FOR-US: FUXA
 CVE-2026-47720 (FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ...)
-	TODO: check
+	NOT-FOR-US: FUXA
 CVE-2026-47719 (FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ...)
-	TODO: check
+	NOT-FOR-US: FUXA
 CVE-2026-47699 (Confidential Containers Guest Components provides guest tools and comp ...)
 	TODO: check
 CVE-2026-41921 (Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored cross-s ...)
@@ -5928,15 +5927,15 @@ CVE-2026-50575 (BetterDesk is a remote desktop management solution. BetterDesk v
 CVE-2026-50187 (Oh My Zsh is a community-driven framework for managing Zsh configurati ...)
 	TODO: check
 CVE-2026-50167 (Kurrier is a modern, self-hosted workspace for email, calendar, contac ...)
-	TODO: check
+	NOT-FOR-US: Kurrier
 CVE-2026-50161 (libre is a generic library for real-time communications with asynchron ...)
 	TODO: check
 CVE-2026-50143 (The Apify MCP server enables AI agents to extract data from websites u ...)
 	NOT-FOR-US: Apify MCP server
 CVE-2026-50139 (goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `Sh ...)
-	TODO: check
+	NOT-FOR-US: goshs
 CVE-2026-50138 (goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, whe ...)
-	TODO: check
+	NOT-FOR-US: goshs
 CVE-2026-50126 (Adaguc-server is an open source geographical information system to vis ...)
 	NOT-FOR-US: Vvveb
 CVE-2026-49228 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
@@ -6441,7 +6440,7 @@ CVE-2026-54336 (JumpServer is an open source bastion host and an operation and m
 CVE-2026-52886 (Notepad++ is a free and open-source source code editor. Prior to 8.9.7 ...)
 	NOT-FOR-US: Notepad++
 CVE-2026-51977 (An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Ve ...)
-	TODO: check
+	NOT-FOR-US: Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera
 CVE-2026-47698 (vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bri ...)
 	NOT-FOR-US: Node.js vm2
 CVE-2026-47686 (vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleE ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a90cba167ba3695236b8ca46cab10bc0a767c878

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a90cba167ba3695236b8ca46cab10bc0a767c878
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260821/7fad71ea/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list