[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 25 20:15:38 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
fa1ac825 by security tracker role at 2026-08-25T19:15:32+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -113,103 +113,103 @@ CVE-2026-78684 (vLLM before 0.27.0 fails to properly classify DeepStream as a GP
 CVE-2026-78581 (Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana c ...)
 	TODO: check
 CVE-2026-78576 (The Readabler plugin for WordPress is vulnerable to SQL Injection in a ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-78572 (The Kalles Addons plugin for WordPress is vulnerable to PHP Object Inj ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-78570 (The Total Donations plugin for WordPress is vulnerable to Privilege Es ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-78568 (The Total Donations plugin for WordPress is vulnerable to SQL Injectio ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-78566 (The Shuffle theme for WordPress is vulnerable to Local File Inclusion  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-78563 (The NotificationX Pro plugin for WordPress is vulnerable to Stored Cro ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-78562 (The Verdure Core plugin for WordPress is vulnerable to Local File Incl ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-78468 (The FluentCRM Pro \u2013 Email Newsletter, Automation, Email Marketing ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-78379 (Improper neutralization of input used for LLM prompting in the python_ ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-78322 (A flaw was found in file-roller. When opening or extracting a maliciou ...)
 	TODO: check
 CVE-2026-77998 (Joomla Extension - miniorange.com - Unauthenticated Authentication Byp ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-77997 (Joomla Extension - yootheme.com - Authenticated, privileged informatio ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-77996 (Joomla Extension - yootheme.com - Authenticated, privileged stored XSS ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-77824 (The Media Sweep \u2013 WordPress Media Cleaner plugin for WordPress is ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-77146 (The extension's invitation controller fails to stop processing after r ...)
-	TODO: check
+	NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-77145 (The permission check for the frontend management update flow verified  ...)
-	TODO: check
+	NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-77144 (The frontend management plugin attributed a newly created event to the ...)
-	TODO: check
+	NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-77143 (The frontend topic editing flow does not verify on the server side tha ...)
-	TODO: check
+	NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-77142 (The frontend company self-service editing feature relies on a template ...)
-	TODO: check
+	NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-77141 (The extension resolves the targeted club record from a user-supplied r ...)
-	TODO: check
+	NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-77140 (The extension validates the HMAC of a frontend employee edit link only ...)
-	TODO: check
+	NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-77139 (The extension fails to validate a client-supplied template element key ...)
-	TODO: check
+	NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-77138 (The extension fails to safely process untrusted client input of an att ...)
-	TODO: check
+	NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-77137 (The extension fails to properly sanitize user input before using it in ...)
-	TODO: check
+	NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-77136 (The extension passes the raw value of a form field configured as "This ...)
-	TODO: check
+	NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-77135 (The extension's user detail view fails to verify that a requested user ...)
-	TODO: check
+	NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-77134 (The extension fails to require the dedicated admin confirmation token  ...)
-	TODO: check
+	NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-77133 (The extension fails to restrict which frontend usergroups a logged-in  ...)
-	TODO: check
+	NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-77131 (When OpenSSL is unavailable on the server, the extension transmits TYP ...)
-	TODO: check
+	NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-77130 (The extension fails to properly validate the expiration of a client-su ...)
-	TODO: check
+	NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-77129 (The extension passes an editor-configurable email subject string direc ...)
-	TODO: check
+	NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-77128 (The extension fails to enforce enable-field restrictions on a reposito ...)
-	TODO: check
+	NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-77127 (The extension fails to restrict a backend AJAX endpoint for inline edi ...)
-	TODO: check
+	NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-76198 (CAI Content Credentials is affected by an Improper Input Validation vu ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-76197 (Adobe Campaign Classic (ACC) is affected by an Improper Neutralization ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-76195 (Adobe Campaign Classic (ACC) is affected by an Improper Neutralization ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-76193 (Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forg ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-76189 (CAI Content Credentials is affected by an Integer Underflow (Wrap or W ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-76128 (The eCommerce Product Catalog plugin for WordPress is vulnerable to St ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-75971 (The ShopEngine Elementor WooCommerce Builder Addon \u2013 All in One W ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-75908 (The Newsletters plugin for WordPress is vulnerable to authorization by ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-75770 (Substance3D - Painter is affected by an out-of-bounds write vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75769 (Substance3D - Painter is affected by a Heap-based Buffer Overflow vuln ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75768 (Substance3D - Painter is affected by an Untrusted Search Path vulnerab ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75767 (Substance3D - Painter is affected by a Heap-based Buffer Overflow vuln ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75766 (Substance3D - Painter is affected by a Heap-based Buffer Overflow vuln ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75752 (Substance3D - Painter is affected by an out-of-bounds read vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75750 (Substance3D - Painter is affected by a Heap-based Buffer Overflow vuln ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75749 (Substance3D - Painter is affected by an out-of-bounds write vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75498 (Webkul QloApps does not validate request parameters before a database  ...)
 	TODO: check
 CVE-2026-75497 (Webkul QloApps does not validate request parameters before a database  ...)
@@ -221,21 +221,21 @@ CVE-2026-75038 (UNIX symbolic link (symlink) following vulnerability in ilya-zlo
 CVE-2026-75037 (Polkit Authentication Based on UnixProcessSubject / Peer PID in LACT o ...)
 	TODO: check
 CVE-2026-71564 (Substance3D - Designer is affected by an out-of-bounds write vulnerabi ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-71444 (CAI Content Credentials is affected by an Integer Underflow (Wrap or W ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-71443 (CAI Content Credentials is affected by an Improper Input Validation vu ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-71442 (CAI Content Credentials is affected by an Integer Underflow (Wrap or W ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-71441 (Illustrator is affected by an out-of-bounds read vulnerability that co ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-71399 (Adobe XD is affected by a Buffer Overflow vulnerability that could res ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-71382 (Substance3D - Sampler is affected by an out-of-bounds write vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-71360 (CAI Content Credentials is affected by an Uncontrolled Resource Consum ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-70551 (A user who can read an existing remote VCS repository can replace its  ...)
 	TODO: check
 CVE-2026-70550 (An authorization weakness in JFrog Artifactory Composer repository han ...)
@@ -253,13 +253,13 @@ CVE-2026-65979 (OpenEXR is the reference implementation and specification for th
 CVE-2026-65633 (Improper Authentication vulnerability in team-alembic AshAuthenticatio ...)
 	TODO: check
 CVE-2026-64204 (There is a memory corruption vulnerability recently discovered in NI L ...)
-	TODO: check
+	NOT-FOR-US: National Instruments
 CVE-2026-64203 (There is a memory corruption vulnerability recently discovered in NI L ...)
-	TODO: check
+	NOT-FOR-US: National Instruments
 CVE-2026-64202 (There is a memory corruption vulnerability recently discovered in NI L ...)
-	TODO: check
+	NOT-FOR-US: National Instruments
 CVE-2026-64201 (There is a memory corruption vulnerability recently discovered in NI L ...)
-	TODO: check
+	NOT-FOR-US: National Instruments
 CVE-2026-63587 (The SMS control function of IE-SR-2TX-WL-4G devices can require a pass ...)
 	TODO: check
 CVE-2026-63586 (The web-based management interface uses a modified uhttpd server with  ...)
@@ -289,23 +289,23 @@ CVE-2026-59186 (OpenEXR is the reference implementation and specification for th
 CVE-2026-59184 (OpenEXR is the reference implementation and specification for the EXR  ...)
 	TODO: check
 CVE-2026-57910 (Improper authentication in the WatchGuard Agent allows an unauthentica ...)
-	TODO: check
+	NOT-FOR-US: WatchGuard
 CVE-2026-57909 (A path traversal vulnerability in WatchGuard Agent allows a remote, un ...)
-	TODO: check
+	NOT-FOR-US: WatchGuard
 CVE-2026-57863 (Crater Invoice through 6.0.6 contains a path traversal vulnerability i ...)
 	TODO: check
 CVE-2026-56096 (The extension passes the user-supplied search query parameter to Apach ...)
-	TODO: check
+	NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-56095 (The extension's indexer passed every field value returned by content o ...)
-	TODO: check
+	NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-56094 (The extension allows a request-provided additionalFilters parameter to ...)
-	TODO: check
+	NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-56093 (The extension's frontend detail-view document lookup does not apply th ...)
-	TODO: check
+	NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-56092 (The extension forces empty frontend-group and subpage-inheritance rest ...)
-	TODO: check
+	NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-55976 (Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-55663 (mediasoup is a WebRTC video conferencing system. From version 3.20.0 u ...)
 	TODO: check
 CVE-2026-55640 (Nextcloud MCP Server is a production-ready MCP server that connects AI ...)
@@ -377,55 +377,55 @@ CVE-2026-55525 (PraisonAI is a multi-agent teams system. Prior to praisonaiagent
 CVE-2026-55419 (Reachy Mini is an SDK for controlling Reachy Mini robots. Prior to 1.8 ...)
 	TODO: check
 CVE-2026-53561 (An improper authentication vulnerability in HiveServer2 SAML bearer-to ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-49845 (SQL injection in Hive Metastore direct SQL partition-name resolution i ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-48433 (Substance3D - Designer is affected by a Heap-based Buffer Overflow vul ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-48432 (Substance3D - Designer is affected by a Heap-based Buffer Overflow vul ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-48431 (Substance3D - Designer is affected by a Heap-based Buffer Overflow vul ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-48430 (Substance3D - Designer is affected by a Heap-based Buffer Overflow vul ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-48429 (Substance3D - Designer is affected by a NULL Pointer Dereference vulne ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-48428 (Substance3D - Designer is affected by a Heap-based Buffer Overflow vul ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-48427 (Substance3D - Designer is affected by an out-of-bounds write vulnerabi ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-48426 (Substance3D - Designer is affected by an out-of-bounds write vulnerabi ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-48425 (Substance3D - Sampler is affected by a Heap-based Buffer Overflow vuln ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-48424 (Substance3D - Sampler is affected by a Heap-based Buffer Overflow vuln ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-48423 (Substance3D - Sampler is affected by a Heap-based Buffer Overflow vuln ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-48422 (Substance3D - Sampler is affected by a Heap-based Buffer Overflow vuln ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-48421 (Substance3D - Sampler is affected by an out-of-bounds write vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-48420 (Substance3D - Sampler is affected by an out-of-bounds write vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-48419 (Substance3D - Sampler is affected by an out-of-bounds write vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-48418 (Substance3D - Sampler is affected by an out-of-bounds write vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-48417 (Substance3D - Sampler is affected by a Stack-based Buffer Overflow vul ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-47626 (NVIDIA DGX Spark contains a vulnerability in the system firmware, wher ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-47624 (NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-26211 (Ekushey Project Manager CRM stores the administrator-configured system ...)
 	TODO: check
 CVE-2026-24263 (NVIDIA DGX Spark contains a vulnerability in the system firmware, wher ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-24262 (NVIDIA DGX Spark contains a vulnerability in the system firmware, wher ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-24225 (NVIDIA DGX Spark contains a vulnerability in the standalone MM firmwar ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-24170 (NVIDIA UFM Enterprise contains a vulnerability in the web interface au ...)
 	TODO: check
 CVE-2026-24169 (NVIDIA UFM Enterprise contains a vulnerability in the plugin managemen ...)
@@ -437,59 +437,59 @@ CVE-2026-24167 (NVIDIA UFM Enterprise contains a vulnerability in the user manag
 CVE-2026-24166 (NVIDIA UFM Enterprise contains a vulnerability in the session manageme ...)
 	TODO: check
 CVE-2026-21758 (HCL Hive is affected by an information disclosure vulnerability, which ...)
-	TODO: check
+	NOT-FOR-US: HCL
 CVE-2026-21754 (HCL Hive is affected by multiple infrastructure and network configurat ...)
-	TODO: check
+	NOT-FOR-US: HCL
 CVE-2026-21753 (HCL Hive is affected by weak software supply chain governance, which c ...)
-	TODO: check
+	NOT-FOR-US: HCL
 CVE-2026-19949 (The All-in-One WP Migration and Backup plugin for WordPress is vulnera ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-19913 (The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file di ...)
 	TODO: check
 CVE-2026-19912 (The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthentica ...)
 	TODO: check
 CVE-2026-19851 (A Use of Default Password vulnerability affecting Tuleap Enterprise Ed ...)
-	TODO: check
+	NOT-FOR-US: Dassault Systemes
 CVE-2026-18547 (The Ultimate Member \u2013 User Profile, Registration, Login, Member D ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18512 (The TranslatePress \u2013 Translate Multilingual sites with AI Transla ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18445 (There is an integer overflow vulnerability resulting in an out-of-boun ...)
-	TODO: check
+	NOT-FOR-US: National Instruments
 CVE-2026-18444 (There is an integer conversion vulnerability resulting in an out-of-bo ...)
-	TODO: check
+	NOT-FOR-US: National Instruments
 CVE-2026-18328 (The Forminator Forms \u2013 Contact Form, Payment Form & Custom Form B ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18323 (The Forminator Forms \u2013 Contact Form, Payment Form & Custom Form B ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18100 (The MetForm \u2013 Contact Form, Survey, Quiz, & Custom Form Builder f ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-17587 (The My Agile Privacy\xae \u2013 CMP, Cookie Consent & Privacy Tools pl ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-17548 (Missing authorization in Checkmk <2.5.0p12, <2.4.0p36, <2.3.0p50 and a ...)
 	TODO: check
 CVE-2026-16601 (The CM Map Locations \u2013 Visualize and share your locations in a fe ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16599 (GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY auth ...)
 	TODO: check
 CVE-2026-16286 (Unrestricted upload of file with dangerous type vulnerability in TRtek ...)
 	TODO: check
 CVE-2026-16234 (There is a memory corruption vulnerability recently discovered in NI L ...)
-	TODO: check
+	NOT-FOR-US: National Instruments
 CVE-2026-16233 (There is a memory corruption vulnerability recently discovered in NI L ...)
-	TODO: check
+	NOT-FOR-US: National Instruments
 CVE-2026-16231 (hbs is an Express view engine that wraps Handlebars. Its registerAsync ...)
 	TODO: check
 CVE-2026-15310 (When decompressing crafted zip files using the bzip/LZMA/Zstandard   c ...)
 	TODO: check
 CVE-2026-13478 (The Zephyr ext2 filesystem driver validates the on-disk block bitmap i ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-13217 (The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp.c reconstructs a sessi ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-13216 (The virtio PCI driver (drivers/virtio/virtio_pci.c) parses a device's  ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-12878 (In affected versions of the Codefresh platform an authenticated user c ...)
-	TODO: check
+	NOT-FOR-US: Octopus Deploy
 CVE-2026-12600 (Denial-of-service (DoS) vulnerability in the internal JPEG2000 (JPX) d ...)
 	TODO: check
 CVE-2025-71407 (Nokogiri before 1.18.3 contains a stack buffer overflow vulnerability  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fa1ac82553126e2d450b2f15237392659bebfb7d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fa1ac82553126e2d450b2f15237392659bebfb7d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260825/44bc0e86/attachment.htm>


More information about the debian-security-tracker-commits mailing list