[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Aug 25 20:38:11 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
adbe8dac by Salvatore Bonaccorso at 2026-08-25T21:36:57+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,19 +1,19 @@
CVE-2026-80051 (github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 does not ...)
- TODO: check
+ NOT-FOR-US: github.com/graphql-go/graphql (GraphQL for Go)
CVE-2026-80050 (ContiNew Admin fails to apply file-upload permission checks or file-ty ...)
- TODO: check
+ NOT-FOR-US: ContiNew Admin
CVE-2026-80049 (Airbyte Platform resolves the workspace used for its authorization dec ...)
- TODO: check
+ NOT-FOR-US: Airbyte Platform
CVE-2026-79788 (In Dradis Community Edition, the ProvidersController and AgentsControl ...)
- TODO: check
+ NOT-FOR-US: Dradis Community Edition
CVE-2026-79787 (Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signat ...)
- TODO: check
+ NOT-FOR-US: Alluxio
CVE-2026-79786 (Coroot's unauthenticated MCP OAuth dynamic client registration endpoin ...)
- TODO: check
+ NOT-FOR-US: Coroot
CVE-2026-79785 (X-AnyLabeling's model downloader disabled TLS certificate verification ...)
- TODO: check
+ NOT-FOR-US: X-AnyLabeling
CVE-2026-79784 (Vocos instantiates a class named by a configuration file without restr ...)
- TODO: check
+ NOT-FOR-US: Vocos
CVE-2026-79783 (rclone before 1.74.4 fails to mask special permission bits when applyi ...)
TODO: check
CVE-2026-79782 (rclone before 1.74.4 fails to strip the X-Amz-Security-Token header wh ...)
@@ -33,9 +33,9 @@ CVE-2026-79776 (rclone before 1.75.0 mounts the pprof debug handler as its own r
CVE-2026-79775 (rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) contain m ...)
TODO: check
CVE-2026-79774 (Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig ...)
- TODO: check
+ NOT-FOR-US: Winter CMS
CVE-2026-79773 (Winter CMS before 1.2.13 contains a local file inclusion vulnerability ...)
- TODO: check
+ NOT-FOR-US: Winter CMS
CVE-2026-79772 (Nokogiri versions before 1.19.1 fail to check the return value from xm ...)
TODO: check
CVE-2026-79771 (Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Styl ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/adbe8dac1ec1e3941f3857cdd84c20cd6a80133b
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/adbe8dac1ec1e3941f3857cdd84c20cd6a80133b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260825/14276ee8/attachment.htm>
More information about the debian-security-tracker-commits
mailing list