[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 25 14:36:36 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
52fa3837 by Salvatore Bonaccorso at 2026-08-25T15:36:08+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -96,9 +96,9 @@ CVE-2026-77310 (jackson-databind contains the general-purpose data-binding funct
 	NOTE: https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-vvgp-rfg2-7rr6
 	NOTE: https://github.com/FasterXML/jackson-databind/commit/2fc7bd9057dd051d7dea0e5fcad89822d0fa5ebd (jackson-databind-2.18.9)
 CVE-2026-76846 (Grav before 2.0.16 contains an incomplete default denylist in the Twig ...)
-	TODO: check
+	NOT-FOR-US: Grav CMS
 CVE-2026-76839 (Grav before 2.0.16 allows sandboxed Twig templates to access sensitive ...)
-	TODO: check
+	NOT-FOR-US: Grav CMS
 CVE-2026-76816 (Netty is an asynchronous, event-driven network application framework.  ...)
 	TODO: check
 CVE-2026-76098 (Mistune is a Python Markdown parser with renderers and plugins. Versio ...)
@@ -110,9 +110,9 @@ CVE-2026-75982 (The LearnPress plugin for WordPress is vulnerable to unauthorize
 CVE-2026-75930 (The FundEngine \u2013 Donation and Crowdfunding Platform plugin for Wo ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-75575 (Rocket.Chat exposes the sendForgotPasswordEmail Meteor method without  ...)
-	TODO: check
+	NOT-FOR-US: Rocket.Chat
 CVE-2026-75574 (The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders ...)
-	TODO: check
+	NOT-FOR-US: Grav plugin
 CVE-2026-75554 (Insufficient Session Expiration vulnerability in the OAuth token refre ...)
 	TODO: check
 CVE-2026-75542 (Incorrect Authorization vulnerability in the OAuth token endpoint in h ...)
@@ -120,11 +120,11 @@ CVE-2026-75542 (Incorrect Authorization vulnerability in the OAuth token endpoin
 CVE-2026-75509 (joserfc is a Python library that provides an implementation of several ...)
 	TODO: check
 CVE-2026-75464 (OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnera ...)
-	TODO: check
+	NOT-FOR-US: OneNav
 CVE-2026-75369 (An out-of-bounds read vulnerability in the CAN::Application::parsePerf ...)
-	TODO: check
+	NOT-FOR-US: SpaceDot AcubeSAT OBC software
 CVE-2026-75368 (A stack overflow in the loadRawData function of SpaceDot AcubeSAT OBC  ...)
-	TODO: check
+	NOT-FOR-US: SpaceDot AcubeSAT OBC software
 CVE-2026-75019 (The Cozy Blocks \u2013 Page Builder for Gutenberg Editor & FSE with 70 ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-72714 (Rocq Prover does not restore the universe graph's copy of the universe ...)
@@ -501,9 +501,9 @@ CVE-2026-77914 (rConfig before 8.2.13 contains a path traversal vulnerability th
 CVE-2026-76848 (TypeORM's SelectQueryBuilder.distinctOn accepts an array of strings an ...)
 	NOT-FOR-US: TypeORM
 CVE-2026-76847 (act starts an HTTP Artifacts V4 backend whenever a workflow uses actio ...)
-	TODO: check
+	NOT-FOR-US: nektos act
 CVE-2026-76845 (adm-zip 0.5.9 through 0.6.0 follows symbolic links at the extraction d ...)
-	TODO: check
+	NOT-FOR-US: adm-zip
 CVE-2026-76844 (webpack-dev-middleware resolves a request to a local file in getFilena ...)
 	TODO: check
 CVE-2026-76843 (The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/mo ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/52fa3837c85e0a3f231c2e76fa8a90989bbf8f77

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/52fa3837c85e0a3f231c2e76fa8a90989bbf8f77
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260825/318c66a4/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list