[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Aug 26 07:59:42 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
03f0d4d0 by Salvatore Bonaccorso at 2026-08-26T08:57:33+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -262,13 +262,13 @@ CVE-2026-71382 (Substance3D - Sampler is affected by an out-of-bounds write vuln
CVE-2026-71360 (CAI Content Credentials is affected by an Uncontrolled Resource Consum ...)
NOT-FOR-US: Adobe
CVE-2026-70551 (A user who can read an existing remote VCS repository can replace its ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-70550 (An authorization weakness in JFrog Artifactory Composer repository han ...)
NOT-FOR-US: JFrog Artifactory
CVE-2026-70548 (Under specific circumstances, low-level user can run request to remote ...)
NOT-FOR-US: JFrog Artifactory
CVE-2026-69104 (An authenticated user may initiate repository migration operations wit ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-67578 (FA-50 all versions miss authentication for some configuration. An atta ...)
NOT-FOR-US: FA-50
CVE-2026-66882 (Improper Neutralization of Input During Web Page Generation (XSS) vuln ...)
@@ -339,7 +339,7 @@ CVE-2026-59982 (OpenEXR is the reference implementation and specification for th
CVE-2026-59769 (FA-50 all versions contain hard-coded credentials. An attacker, who kn ...)
NOT-FOR-US: FA-50
CVE-2026-59335 (Improper handling of case sensitivity (CWE-178) in the identity zone a ...)
- TODO: check
+ NOT-FOR-US: Cloud Foundry
CVE-2026-59189 (OpenEXR is the reference implementation and specification for the EXR ...)
- openexr 3.4.14-0.1
NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-hwmv-39v6-739m
@@ -398,7 +398,7 @@ CVE-2026-55619 (eml_parser serves as a python module for parsing eml files and r
CVE-2026-55618 (eml_parser serves as a python module for parsing eml files and returni ...)
NOT-FOR-US: eml_parser Python module
CVE-2026-55609 (sublinear-time-solver is a Rust and WebAssembly library for solving as ...)
- TODO: check
+ NOT-FOR-US: sublinear-time-solver
CVE-2026-55585 (QWED is open-source AI verification infrastructure for deterministic v ...)
NOT-FOR-US: QWED
CVE-2026-55582 (mcp-shell is an MCP server for running shell commands securely, audita ...)
@@ -408,11 +408,11 @@ CVE-2026-55581 (mcp-shell is an MCP server for running shell commands securely,
CVE-2026-55580 (mcp-shell is an MCP server for running shell commands securely, audita ...)
NOT-FOR-US: mcp-shell
CVE-2026-55571 (djust provides Phoenix LiveView-style reactive server-side rendering f ...)
- TODO: check
+ NOT-FOR-US: djust
CVE-2026-55557 (browse-mcp is a Playwright-based headless-browser MCP server for MCP-c ...)
- TODO: check
+ NOT-FOR-US: browse-mcp
CVE-2026-55553 (urllib is an HTTP client for Node.js that supports authentication, red ...)
- TODO: check
+ NOT-FOR-US: urllib Node.js module
CVE-2026-55546 (QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2 ...)
NOT-FOR-US: QWED-MCP
CVE-2026-55541 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, pr ...)
@@ -797,9 +797,9 @@ CVE-2026-75575 (Rocket.Chat exposes the sendForgotPasswordEmail Meteor method wi
CVE-2026-75574 (The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders ...)
NOT-FOR-US: Grav plugin
CVE-2026-75554 (Insufficient Session Expiration vulnerability in the OAuth token refre ...)
- TODO: check
+ NOT-FOR-US: hexpm (server side)
CVE-2026-75542 (Incorrect Authorization vulnerability in the OAuth token endpoint in h ...)
- TODO: check
+ NOT-FOR-US: hexpm (server side)
CVE-2026-75509 (joserfc is a Python library that provides an implementation of several ...)
- joserfc 1.7.3-1
NOTE: https://github.com/authlib/joserfc/security/advisories/GHSA-r74j-q665-7rpj
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/03f0d4d051deea86c1f544d577927e08e1932582
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/03f0d4d051deea86c1f544d577927e08e1932582
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260826/7afd0ded/attachment.htm>
More information about the debian-security-tracker-commits
mailing list