[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Aug 25 21:36:31 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
ea0b5fb7 by Salvatore Bonaccorso at 2026-08-25T22:36:03+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -69,37 +69,37 @@ CVE-2026-79674 (NLTK versions before 3.10.3 contain a path sandbox bypass vulner
- nltk 3.10.3-1
NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-3gq4-3j92-5w49
CVE-2026-79673 (Ech0 before 4.4.3 protects the PUT /user endpoint with the profile:rea ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79672 (Ech0 before 4.4.3 fails to enforce scope-based authorization on nine c ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79671 (Ech0 through 4.2.1 contains a server-side request forgery vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79670 (Ech0 before 4.4.3 contains a stored cross-site scripting vulnerability ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79669 (Ech0 before 4.4.3 lacks authorization checks on system log endpoints a ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79668 (Ech0 before 4.7.3 contains an authentication bypass vulnerability in t ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79667 (Ech0 version 4.3.4 and earlier fails to reliably enforce scoped access ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79666 (Ech0 before 4.4.3 fails to enforce administrator authorization on dash ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79665 (Ech0 before 4.5.1 contains an authorization bypass vulnerability where ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79664 (Ech0 before 4.7.3 fails to properly revoke access tokens created with ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79663 (Ech0 before 4.7.3 contains a stored cross-site scripting vulnerability ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79662 (Ech0 through 4.5.6 contains an OAuth redirect URI validation vulnerabi ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79661 (Ech0 through 4.5.6 registers the PUT /api/echo/like/:id endpoint on th ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79660 (Ech0 versions before 4.7.3 expose guest commenter email addresses thro ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79659 (Ech0 before 4.7.3 contains a server-side request forgery vulnerability ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79658 (Ech0 before 5.0.1 does not impose any size or shape limit on the Accep ...)
- TODO: check
+ NOT-FOR-US: Ech0
CVE-2026-79657 (NLTK versions before 3.10.3 contain a remote code execution vulnerabil ...)
- nltk 3.10.3-1
NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-x99w-6fgc-pmfw
@@ -369,39 +369,39 @@ CVE-2026-55553 (urllib is an HTTP client for Node.js that supports authenticatio
CVE-2026-55546 (QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2 ...)
TODO: check
CVE-2026-55541 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, pr ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55540 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, is ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55539 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, th ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55538 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, pr ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55537 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Jo ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55536 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Br ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55535 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, th ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55534 (PraisonAI is a multi-agent teams system. From praisonai 4.6.34 until 4 ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55533 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, cr ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55532 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, MC ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55531 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, th ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55530 (PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6. ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55529 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, th ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55528 (PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6. ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55527 (PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6. ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55526 (PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6. ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55525 (PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6. ...)
- TODO: check
+ NOT-FOR-US: PraisonAI
CVE-2026-55419 (Reachy Mini is an SDK for controlling Reachy Mini robots. Prior to 1.8 ...)
TODO: check
CVE-2026-53561 (An improper authentication vulnerability in HiveServer2 SAML bearer-to ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ea0b5fb7f7d0a5190d6e86938cecb1dcde0087e0
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ea0b5fb7f7d0a5190d6e86938cecb1dcde0087e0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260825/3988976c/attachment.htm>
More information about the debian-security-tracker-commits
mailing list