[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Aug 25 15:17:44 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
c0d67181 by Salvatore Bonaccorso at 2026-08-25T16:16:31+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -138,65 +138,65 @@ CVE-2026-75368 (A stack overflow in the loadRawData function of SpaceDot AcubeSA
CVE-2026-75019 (The Cozy Blocks \u2013 Page Builder for Gutenberg Editor & FSE with 70 ...)
NOT-FOR-US: WordPress plugin
CVE-2026-72714 (Rocq Prover does not restore the universe graph's copy of the universe ...)
- TODO: check
+ NOT-FOR-US: Rocq Prover
CVE-2026-72711 (The Lean 4 kernel does not check that the body of an opaque declaratio ...)
- TODO: check
+ NOT-FOR-US: Lean 4 kernel
CVE-2026-72705 (The guard checker in Rocq Prover does not follow recursive calls made ...)
- TODO: check
+ NOT-FOR-US: Rocq Prover
CVE-2026-72704 (The guard checker in Rocq Prover does not recheck the recursive tree r ...)
- TODO: check
+ NOT-FOR-US: Rocq Prover
CVE-2026-72703 (The guard checker in Rocq Prover treats a parameter of a nested mutual ...)
- TODO: check
+ NOT-FOR-US: Rocq Prover
CVE-2026-72702 (Grav CMS before 2.0.16 contains an origin validation bypass in the Uri ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-72701 (Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verif ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-72700 (The getgrav/grav-plugin-login Composer plugin before 3.9.1 (used by Gr ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-72699 (The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vuln ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-72698 (Grav CMS before 2.0.16 fails to filter system, site, and theme configu ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-72697 (Grav CMS before 2.0.16 contains a path traversal vulnerability in the ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-72696 (Grav CMS before 2.0.16 contains a symlink following vulnerability in S ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-72695 (Grav before 2.0.16 contains a path traversal vulnerability in MediaUpl ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-71511 (Dolibarr before 24.0.0 contains a sensitive data exposure vulnerabilit ...)
NOT-FOR-US: Dolibarr
CVE-2026-71510 (Dolibarr before 24.0.0 contains a SQL injection vulnerability in the u ...)
NOT-FOR-US: Dolibarr
CVE-2026-69665 (SKYSEA Client View and SKYMEC IT Manager contain an issue with incorre ...)
- TODO: check
+ NOT-FOR-US: SKYSEA Client View and SKYMEC IT Manager
CVE-2026-68960 (A stack-based buffer overflow vulnerability exists in SKYSEA Client Vi ...)
- TODO: check
+ NOT-FOR-US: SKYSEA Client View and SKYMEC IT Manager
CVE-2026-68959 (SKYSEA Client View and SKYMEC IT Manager contain a path traversal vuln ...)
- TODO: check
+ NOT-FOR-US: SKYSEA Client View and SKYMEC IT Manager
CVE-2026-68516 (OpenEXR is the reference implementation and specification for the EXR ...)
TODO: check
CVE-2026-68062 (SKYSEA Client View and SKYMEC IT Manager contain a path traversal vuln ...)
- TODO: check
+ NOT-FOR-US: SKYSEA Client View and SKYMEC IT Manager
CVE-2026-66766 (SAP S/4HANA (Private Cloud) uses a third-party component that contains ...)
NOT-FOR-US: SAP
CVE-2026-66109 (A missing authorization vulnerability exists in SKYSEA Client View and ...)
- TODO: check
+ NOT-FOR-US: SKYSEA Client View and SKYMEC IT Manager
CVE-2026-63693 (Dell Client BIOS contains an Improper Link Resolution Before File Acce ...)
NOT-FOR-US: Dell / EMC
CVE-2026-61419 (Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Ac ...)
NOT-FOR-US: Dell / EMC
CVE-2026-5006 (A vulnerability was identified in HashiCorp Vault and Vault Enterprise ...)
- TODO: check
+ NOT-FOR-US: HashiCorp
CVE-2026-59183 (OpenEXR is the reference implementation and specification for the EXR ...)
TODO: check
CVE-2026-56710 (Grav Login plugin versions before 1.0.16 fail to validate the target a ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-56709 (Grav before 3.9.2 fails to validate untrusted Host headers in the send ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-56708 (Grav API plugin before 1.0.16 contains a server-side request forgery v ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-56707 (Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an autho ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-56706 (Adminer before 5.4.3 uses a CSRF token scheme that transmits both the ...)
TODO: check
CVE-2026-56705 (Adminer before 5.4.3 fails to sanitize the server field before constru ...)
@@ -208,7 +208,7 @@ CVE-2026-56703 (Adminer before 5.4.3 contains a remote code execution vulnerabil
CVE-2026-56702 (Adminer versions before 5.4.3 contain an unrestricted file upload vuln ...)
TODO: check
CVE-2026-55468 (Wagtail is an open source content management system built on Django. P ...)
- TODO: check
+ NOT-FOR-US: Wagtail
CVE-2026-55373 (OpenEXR is the reference implementation and specification for the EXR ...)
TODO: check
CVE-2026-55371 (OpenEXR is the reference implementation and specification for the EXR ...)
@@ -515,7 +515,7 @@ CVE-2026-76847 (act starts an HTTP Artifacts V4 backend whenever a workflow uses
CVE-2026-76845 (adm-zip 0.5.9 through 0.6.0 follows symbolic links at the extraction d ...)
NOT-FOR-US: adm-zip
CVE-2026-76844 (webpack-dev-middleware resolves a request to a local file in getFilena ...)
- TODO: check
+ NOT-FOR-US: Node webpack-dev-middleware
CVE-2026-76843 (The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/mo ...)
TODO: check
CVE-2026-76842 (The Mercado Pago Node.js SDK interpolates caller-supplied identifiers ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c0d671816c498aed5d58807b1ab8251366eba784
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c0d671816c498aed5d58807b1ab8251366eba784
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260825/fb9a3e56/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list