[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Aug 22 09:54:06 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1189cea3 by Salvatore Bonaccorso at 2026-08-22T10:53:41+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -126,83 +126,83 @@ CVE-2026-53572 (KEDA is a Kubernetes-based Event Driven Autoscaling component. P
 CVE-2026-53541 (OliveTin gives access to predefined shell commands from a web interfac ...)
 	NOT-FOR-US: OliveTin
 CVE-2026-53531 (RaTeX is a KaTeX-compatible math rendering engine written in Rust. Pri ...)
-	TODO: check
+	NOT-FOR-US: RaTeX
 CVE-2026-53530 (RaTeX is a KaTeX-compatible math rendering engine written in Rust. Pri ...)
-	TODO: check
+	NOT-FOR-US: RaTeX
 CVE-2026-53529 (LeafWiki is a self-hosted wiki. Prior to version 0.10.2, page titles r ...)
-	TODO: check
+	NOT-FOR-US: LeafWiki
 CVE-2026-53528 (LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.0 have a p ...)
-	TODO: check
+	NOT-FOR-US: LeafWiki
 CVE-2026-53527 (LeafWiki is a self-hosted wiki. Versions 0.1.0 through 0.10.0 have a p ...)
-	TODO: check
+	NOT-FOR-US: LeafWiki
 CVE-2026-53509 (CKAN MCP Server is a tool for querying CKAN open data portals. A known ...)
-	TODO: check
+	NOT-FOR-US: CKAN MCP Server
 CVE-2026-53499 (FORT Validator is a Resource Public Key Infrastructure (RPKI) relying- ...)
 	TODO: check
 CVE-2026-53497 (CrossWatch (CW) is a synchronization engine. Prior to version 0.9.21,  ...)
-	TODO: check
+	NOT-FOR-US: CrossWatch
 CVE-2026-53487 (Kite is a Kubernetes dashboard. Prior to version 0.12.3, authenticated ...)
-	TODO: check
+	NOT-FOR-US: Kite Kubernetes dashboard
 CVE-2026-53468 (Typemill is a flat-file, Markdown-based content management system desi ...)
-	TODO: check
+	NOT-FOR-US: Typemill
 CVE-2026-50290 (SpecifyJS is a declarative TypeScript user interface framework. Prior  ...)
-	TODO: check
+	NOT-FOR-US: SpecifyJS
 CVE-2026-50288 (SpecifyJS is a declarative TypeScript user interface framework. Prior  ...)
-	TODO: check
+	NOT-FOR-US: SpecifyJS
 CVE-2026-49849 (xShop is an open-source shop developed in Laravel. An Unrestricted Fil ...)
-	TODO: check
+	NOT-FOR-US: xShop
 CVE-2026-49360 (Recce is a data-validation toolkit for enhanced dbt (data build tool)  ...)
-	TODO: check
+	NOT-FOR-US: Recce
 CVE-2026-48106 (Arc is an open, SQL-native time-series database for telemetry. Prior t ...)
-	TODO: check
+	NOT-FOR-US: Arc
 CVE-2026-48105 (Arc is an open, SQL-native time-series database for telemetry. Prior t ...)
-	TODO: check
+	NOT-FOR-US: Arc
 CVE-2026-48050 (Arc is an open, SQL-native time-series database for telemetry. Version ...)
-	TODO: check
+	NOT-FOR-US: Arc
 CVE-2026-47735 (Arc is an open, SQL-native time-series database for telemetry. Prior t ...)
-	TODO: check
+	NOT-FOR-US: Arc
 CVE-2026-45271 (Picotls is a TLS protocol library that allows users select different c ...)
-	TODO: check
+	NOT-FOR-US: Picotls
 CVE-2026-45099 (Terragrunt is a flexible orchestration tool that allows Infrastructure ...)
-	TODO: check
+	NOT-FOR-US: Terragrunt
 CVE-2026-43980 (Malla is a web analyzer for Meshtastic networks based on MQTT data. Pr ...)
-	TODO: check
+	NOT-FOR-US: Malla
 CVE-2026-34949 (Combodo iTop is a web based IT service management tool.Prior to 3.2.3, ...)
-	TODO: check
+	NOT-FOR-US: Combodo iTop
 CVE-2026-34948 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
-	TODO: check
+	NOT-FOR-US: Combodo iTop
 CVE-2026-34836 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
-	TODO: check
+	NOT-FOR-US: Combodo iTop
 CVE-2026-34741 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
-	TODO: check
+	NOT-FOR-US: Combodo iTop
 CVE-2026-33333 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
-	TODO: check
+	NOT-FOR-US: Combodo iTop
 CVE-2026-33240 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
-	TODO: check
+	NOT-FOR-US: Combodo iTop
 CVE-2026-33047 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
-	TODO: check
+	NOT-FOR-US: Combodo iTop
 CVE-2026-31936 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
-	TODO: check
+	NOT-FOR-US: Combodo iTop
 CVE-2026-31880 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
-	TODO: check
+	NOT-FOR-US: Combodo iTop
 CVE-2026-31803 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
-	TODO: check
+	NOT-FOR-US: Combodo iTop
 CVE-2026-30890 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
-	TODO: check
+	NOT-FOR-US: Combodo iTop
 CVE-2026-30866 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
-	TODO: check
+	NOT-FOR-US: Combodo iTop
 CVE-2026-30865 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
-	TODO: check
+	NOT-FOR-US: Combodo iTop
 CVE-2026-30826 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
-	TODO: check
+	NOT-FOR-US: Combodo iTop
 CVE-2026-30819 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
-	TODO: check
+	NOT-FOR-US: Combodo iTop
 CVE-2026-27490 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
-	TODO: check
+	NOT-FOR-US: Combodo iTop
 CVE-2026-27463 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
-	TODO: check
+	NOT-FOR-US: Combodo iTop
 CVE-2026-27462 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
-	TODO: check
+	NOT-FOR-US: Combodo iTop
 CVE-2026-19883 (The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to u ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-19222 (The Forminator Forms  WordPress plugin before 1.57.0.7 does not consis ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1189cea346efffdfe90683b2c9a2610c6ba6849c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1189cea346efffdfe90683b2c9a2610c6ba6849c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260822/0d462287/attachment.htm>


More information about the debian-security-tracker-commits mailing list