[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 25 20:38:11 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
adbe8dac by Salvatore Bonaccorso at 2026-08-25T21:36:57+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,19 +1,19 @@
 CVE-2026-80051 (github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 does not  ...)
-	TODO: check
+	NOT-FOR-US: github.com/graphql-go/graphql (GraphQL for Go)
 CVE-2026-80050 (ContiNew Admin fails to apply file-upload permission checks or file-ty ...)
-	TODO: check
+	NOT-FOR-US: ContiNew Admin
 CVE-2026-80049 (Airbyte Platform resolves the workspace used for its authorization dec ...)
-	TODO: check
+	NOT-FOR-US: Airbyte Platform
 CVE-2026-79788 (In Dradis Community Edition, the ProvidersController and AgentsControl ...)
-	TODO: check
+	NOT-FOR-US: Dradis Community Edition
 CVE-2026-79787 (Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signat ...)
-	TODO: check
+	NOT-FOR-US: Alluxio
 CVE-2026-79786 (Coroot's unauthenticated MCP OAuth dynamic client registration endpoin ...)
-	TODO: check
+	NOT-FOR-US: Coroot
 CVE-2026-79785 (X-AnyLabeling's model downloader disabled TLS certificate verification ...)
-	TODO: check
+	NOT-FOR-US: X-AnyLabeling
 CVE-2026-79784 (Vocos instantiates a class named by a configuration file without restr ...)
-	TODO: check
+	NOT-FOR-US: Vocos
 CVE-2026-79783 (rclone before 1.74.4 fails to mask special permission bits when applyi ...)
 	TODO: check
 CVE-2026-79782 (rclone before 1.74.4 fails to strip the X-Amz-Security-Token header wh ...)
@@ -33,9 +33,9 @@ CVE-2026-79776 (rclone before 1.75.0 mounts the pprof debug handler as its own r
 CVE-2026-79775 (rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) contain m ...)
 	TODO: check
 CVE-2026-79774 (Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig ...)
-	TODO: check
+	NOT-FOR-US: Winter CMS
 CVE-2026-79773 (Winter CMS before 1.2.13 contains a local file inclusion vulnerability ...)
-	TODO: check
+	NOT-FOR-US: Winter CMS
 CVE-2026-79772 (Nokogiri versions before 1.19.1 fail to check the return value from xm ...)
 	TODO: check
 CVE-2026-79771 (Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Styl ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/adbe8dac1ec1e3941f3857cdd84c20cd6a80133b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/adbe8dac1ec1e3941f3857cdd84c20cd6a80133b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260825/14276ee8/attachment.htm>


More information about the debian-security-tracker-commits mailing list