[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Aug 24 22:23:01 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
471dd91c by Moritz Muehlenhoff at 2026-08-24T23:16:57+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -386,17 +386,17 @@ CVE-2026-71504 (Dolibarr before 24.0.0 contains an improper authorization vulner
 CVE-2026-71503 (Dolibarr before 24.0.0 contains a reflected cross-site scripting vulne ...)
 	NOT-FOR-US: Dolibarr
 CVE-2026-71366 (A server-side request forgery (SSRF) vulnerability was found in multip ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2026-71364 (A path traversal vulnerability was found in AWX's project archive extr ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2026-71300 (Improper input validation vulnerability in Apache Camel Atmosphere Web ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-6017 (Firmware in KAON PG5298A and PG5298B routers allow an unauthenticated  ...)
-	TODO: check
+	NOT-FOR-US: KAON
 CVE-2026-67602 (phpIPAM before 1.8.2 contains an authentication bypass vulnerability i ...)
-	TODO: check
+	- phpipam <itp> (bug #731713)
 CVE-2026-67204 (BookStack before 26.05.4 contains a broken access control vulnerabilit ...)
-	TODO: check
+	NOT-FOR-US: BookStack
 CVE-2026-66908 (Improper Authentication vulnerability in Apache Camel Platform HTTP Ma ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-66907 (Relative path traversal vulnerability in Apache Camel Google Storage c ...)
@@ -442,19 +442,19 @@ CVE-2026-59565 (A remotely exploitable buffer overflow bug can cause a local and
 CVE-2026-59564 (An authentication bypass issue exists in communications between affect ...)
 	NOT-FOR-US: Zscaler
 CVE-2026-59561 (Sakura Editor provided by Sakura Editor Development Community contains ...)
-	TODO: check
+	NOT-FOR-US: Sakura Editor
 CVE-2026-59295 (Micrometer-instrumented Apache HttpAsyncClient (4.x or 5.x) usage via  ...)
-	TODO: check
+	NOT-FOR-US: io.micrometer:micrometer-core
 CVE-2026-59230 (Improper input validation vulnerability in Apache Camel.    This issue ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-40877 (Combodo iTop is a web-based IT service management tool. Prior to 3.2.3 ...)
-	TODO: check
+	NOT-FOR-US: Combodo iTop
 CVE-2026-39975 (Combodo iTop is a web-based IT service management tool. Prior to 3.2.3 ...)
-	TODO: check
+	NOT-FOR-US: Combodo iTop
 CVE-2026-39915 (TIM Flow before 26.0.6 contains a CRLF injection vulnerability that al ...)
-	TODO: check
+	NOT-FOR-US: TIM Flow
 CVE-2026-39914 (TIM Flow before 26.0.6 contains an improper authorization vulnerabilit ...)
-	TODO: check
+	NOT-FOR-US: TIM Flow
 CVE-2026-34491 (Improper neutralization of input during web page generation ('cross-si ...)
 	NOT-FOR-US: Johnson Controls
 CVE-2026-32558 (Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Prog ...)
@@ -470,9 +470,9 @@ CVE-2026-32476 (Unauthenticated Cross Site Scripting (XSS) in Brave Conversion E
 CVE-2026-32471 (Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions.)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-30864 (Combodo iTop is a web-based IT service management tool. Prior to 3.2.3 ...)
-	TODO: check
+	NOT-FOR-US: Combodo iTop
 CVE-2026-30512 (A local privilege escalation vulnerability exists in the Restricted Ac ...)
-	TODO: check
+	NOT-FOR-US: entervo HMI
 CVE-2026-28190 (Subscriber Broken Access Control in ProLancer Element <= 1.4.8 version ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28171 (Unauthenticated Arbitrary File Deletion in WooCommerce File Approval < ...)
@@ -502,11 +502,11 @@ CVE-2026-21752 (HCL Hive is affected by a use of vulnerable third-party componen
 CVE-2026-21751 (HCL Hive is affected by a cryptographic primitive with a risky impleme ...)
 	NOT-FOR-US: HCL
 CVE-2026-19874 (A heap-based buffer overflow vulnerability exists in Konami's Metal Ge ...)
-	TODO: check
+	NOT-FOR-US: Konami
 CVE-2026-19853 (NewSiteServer (NSS) developed by CyberTutor has a Missing Authenticati ...)
-	TODO: check
+	NOT-FOR-US: NewSiteServer
 CVE-2026-19852 (NewSiteServer (NSS) developed by CyberTutor has an Arbitrary File Uplo ...)
-	TODO: check
+	NOT-FOR-US: NewSiteServer
 CVE-2026-19200 (The Velociraptor verify() VQL function allows a user to verify an arti ...)
 	NOT-FOR-US: Rapid7
 CVE-2026-18349 (Improper protection against voltage and clock glitches vulnerability i ...)
@@ -544,7 +544,7 @@ CVE-2025-68833 (HCL Hive Keycloak IAM Instance is affected by insufficient granu
 CVE-2025-68825 (HCL Hive is affected by incorrect default permissions which could allo ...)
 	NOT-FOR-US: HCL
 CVE-2025-63080 (Firmware in KAON PG5298A and PG5298B routers allow an authenticated us ...)
-	TODO: check
+	NOT-FOR-US: KAON
 CVE-2025-36940 (Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), ...)
 	NOT-FOR-US: Google devices
 CVE-2025-36939 (Multiple vulnerabilities exist in OpenThread's handling of MLE packets ...)
@@ -1997,13 +1997,13 @@ CVE-2026-59655 (Exposure of Sensitive Information to an Unauthorized Actor vulne
 CVE-2026-59654 (Missing Release of Resource after Effective Lifetime vulnerability in  ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-59323 (An application using Micrometer Tracing with W3C baggage propagation i ...)
-	TODO: check
+	NOT-FOR-US: Spring Micrometer Tracing
 CVE-2026-59318 (In Spring AI's tool calling support, the per-request tool list is adve ...)
 	NOT-FOR-US: VMware
 CVE-2026-59308 (In Spring AI's Semantic Cache support, the context hash used to isolat ...)
 	NOT-FOR-US: VMware
 CVE-2026-59296 (Using untrusted, non-normalized input as-is for metrics data (such as  ...)
-	TODO: check
+	NOT-FOR-US: Spring Micrometer Tracing
 CVE-2026-59279 (The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) ...)
 	NOT-FOR-US: VMware
 CVE-2026-59085 (Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack' ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/471dd91cc0660a44b8effd1eb86d1ecf6247991b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/471dd91cc0660a44b8effd1eb86d1ecf6247991b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260824/b18fd132/attachment.htm>


More information about the debian-security-tracker-commits mailing list