[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 26 07:59:42 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
03f0d4d0 by Salvatore Bonaccorso at 2026-08-26T08:57:33+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -262,13 +262,13 @@ CVE-2026-71382 (Substance3D - Sampler is affected by an out-of-bounds write vuln
 CVE-2026-71360 (CAI Content Credentials is affected by an Uncontrolled Resource Consum ...)
 	NOT-FOR-US: Adobe
 CVE-2026-70551 (A user who can read an existing remote VCS repository can replace its  ...)
-	TODO: check
+	NOT-FOR-US: JFrog Artifactory
 CVE-2026-70550 (An authorization weakness in JFrog Artifactory Composer repository han ...)
 	NOT-FOR-US: JFrog Artifactory
 CVE-2026-70548 (Under specific circumstances, low-level user can run request to remote ...)
 	NOT-FOR-US: JFrog Artifactory
 CVE-2026-69104 (An authenticated user may initiate repository migration operations wit ...)
-	TODO: check
+	NOT-FOR-US: JFrog Artifactory
 CVE-2026-67578 (FA-50 all versions miss authentication for some configuration. An atta ...)
 	NOT-FOR-US: FA-50
 CVE-2026-66882 (Improper Neutralization of Input During Web Page Generation (XSS) vuln ...)
@@ -339,7 +339,7 @@ CVE-2026-59982 (OpenEXR is the reference implementation and specification for th
 CVE-2026-59769 (FA-50 all versions contain hard-coded credentials. An attacker, who kn ...)
 	NOT-FOR-US: FA-50
 CVE-2026-59335 (Improper handling of case sensitivity (CWE-178) in the identity zone a ...)
-	TODO: check
+	NOT-FOR-US: Cloud Foundry
 CVE-2026-59189 (OpenEXR is the reference implementation and specification for the EXR  ...)
 	- openexr 3.4.14-0.1
 	NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-hwmv-39v6-739m
@@ -398,7 +398,7 @@ CVE-2026-55619 (eml_parser serves as a python module for parsing eml files and r
 CVE-2026-55618 (eml_parser serves as a python module for parsing eml files and returni ...)
 	NOT-FOR-US: eml_parser Python module
 CVE-2026-55609 (sublinear-time-solver is a Rust and WebAssembly library for solving as ...)
-	TODO: check
+	NOT-FOR-US: sublinear-time-solver
 CVE-2026-55585 (QWED is open-source AI verification infrastructure for deterministic v ...)
 	NOT-FOR-US: QWED
 CVE-2026-55582 (mcp-shell is an MCP server for running shell commands securely, audita ...)
@@ -408,11 +408,11 @@ CVE-2026-55581 (mcp-shell is an MCP server for running shell commands securely,
 CVE-2026-55580 (mcp-shell is an MCP server for running shell commands securely, audita ...)
 	NOT-FOR-US: mcp-shell
 CVE-2026-55571 (djust provides Phoenix LiveView-style reactive server-side rendering f ...)
-	TODO: check
+	NOT-FOR-US: djust
 CVE-2026-55557 (browse-mcp is a Playwright-based headless-browser MCP server for MCP-c ...)
-	TODO: check
+	NOT-FOR-US: browse-mcp
 CVE-2026-55553 (urllib is an HTTP client for Node.js that supports authentication, red ...)
-	TODO: check
+	NOT-FOR-US: urllib Node.js module
 CVE-2026-55546 (QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2 ...)
 	NOT-FOR-US: QWED-MCP
 CVE-2026-55541 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, pr ...)
@@ -797,9 +797,9 @@ CVE-2026-75575 (Rocket.Chat exposes the sendForgotPasswordEmail Meteor method wi
 CVE-2026-75574 (The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders ...)
 	NOT-FOR-US: Grav plugin
 CVE-2026-75554 (Insufficient Session Expiration vulnerability in the OAuth token refre ...)
-	TODO: check
+	NOT-FOR-US: hexpm (server side)
 CVE-2026-75542 (Incorrect Authorization vulnerability in the OAuth token endpoint in h ...)
-	TODO: check
+	NOT-FOR-US: hexpm (server side)
 CVE-2026-75509 (joserfc is a Python library that provides an implementation of several ...)
 	- joserfc 1.7.3-1
 	NOTE: https://github.com/authlib/joserfc/security/advisories/GHSA-r74j-q665-7rpj



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/03f0d4d051deea86c1f544d577927e08e1932582

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/03f0d4d051deea86c1f544d577927e08e1932582
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260826/7afd0ded/attachment.htm>


More information about the debian-security-tracker-commits mailing list