[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 26 08:26:40 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b0fee2c4 by Salvatore Bonaccorso at 2026-08-26T09:26:02+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -9,33 +9,33 @@ CVE-2026-9146
 CVE-2026-80216
 	REJECTED
 CVE-2026-80214 (LibreNMS\u2019s Virtualization Discovery module is vulnerable to comma ...)
-	TODO: check
+	NOT-FOR-US: LibreNMS
 CVE-2026-80202 (Kimai before 2.56.0 does not enforce team-membership checks in Timeshe ...)
-	TODO: check
+	NOT-FOR-US: Kimai
 CVE-2026-80201 (Kimai before 2.53.0 fails to block sensitive User methods in the Twig  ...)
-	TODO: check
+	NOT-FOR-US: Kimai
 CVE-2026-80200 (Kimai before 2.53.0 contains an open redirect vulnerability in the SAM ...)
-	TODO: check
+	NOT-FOR-US: Kimai
 CVE-2026-80199 (Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAut ...)
-	TODO: check
+	NOT-FOR-US: Kimai
 CVE-2026-80198 (Kimai versions before 2.56.0 fail to restrict the config() Twig functi ...)
-	TODO: check
+	NOT-FOR-US: Kimai
 CVE-2026-80197 (Kimai before 2.57.0 contains an improper authorization vulnerability i ...)
-	TODO: check
+	NOT-FOR-US: Kimai
 CVE-2026-80196 (Kimai before 2.58.0 contains an authentication bypass vulnerability wh ...)
-	TODO: check
+	NOT-FOR-US: Kimai
 CVE-2026-80195 (Kimai before 2.63.0 contains a business logic / improper authorization ...)
-	TODO: check
+	NOT-FOR-US: Kimai
 CVE-2026-80194 (Kimai before 2.64.0 contains a missing authorization vulnerability in  ...)
-	TODO: check
+	NOT-FOR-US: Kimai
 CVE-2026-80193 (Kimai before 2.62.0 fails to validate create_other_timesheet permissio ...)
-	TODO: check
+	NOT-FOR-US: Kimai
 CVE-2026-80192 (@better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x line and ...)
-	TODO: check
+	NOT-FOR-US: better-auth/sso
 CVE-2026-80191 (GROWI applies its page-viewer permission check to attachment requests  ...)
-	TODO: check
+	NOT-FOR-US: GROWI
 CVE-2026-80189 (LeafWiki extracts an uploaded ZIP archive without limiting how much da ...)
-	TODO: check
+	NOT-FOR-US: LeafWiki
 CVE-2026-80186 [Stack Overflow in name2utf8 causes DoS and potential code execution]
 	- bluez <unfixed>
 	NOTE: https://github.com/bluez/bluez/security/advisories/GHSA-68h6-5qgp-3975
@@ -45,9 +45,9 @@ CVE-2026-80185 [unprivileged-local and adjacent-LE-peer leads to arbitrary code
 	NOTE: https://github.com/bluez/bluez/security/advisories/GHSA-7mmr-gwqx-vc34
 	NOTE: Fixed by: https://github.com/bluez/bluez/commit/985e643d78b09afc81d606bc0a08581fc05b1b15
 CVE-2026-80138 (ClipBucket V5's web installer fails to properly validate or escape the ...)
-	TODO: check
+	NOT-FOR-US: ClipBucket
 CVE-2026-80104 (DB-GPT builds the destination path for an uploaded skill from the mult ...)
-	TODO: check
+	NOT-FOR-US: DB-GPT
 CVE-2026-80101 (A flaw was found in the file-xwd plugin in GIMP. When processing a spe ...)
 	TODO: check
 CVE-2026-79912 (A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. ...)
@@ -719,9 +719,9 @@ CVE-2026-78892 (Incorrect authorization in Chromoting in Google Chrome on on Win
 CVE-2026-78891 (Buffer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allo ...)
 	TODO: check
 CVE-2026-78655 (Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-fact ...)
-	TODO: check
+	NOT-FOR-US: Punk::Plugin::TOTP Perl module
 CVE-2026-78619 (Punk::Plugin::TOTP versions before 0.05 for Perl accept another accoun ...)
-	TODO: check
+	NOT-FOR-US: Punk::Plugin::TOTP Perl module
 CVE-2026-78146 (The Simple Newsletter Plugin  WordPress plugin before 4.3.3 does not v ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-77790 (The RegistrationMagic  WordPress plugin before 6.0.9.4 does not saniti ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b0fee2c46e5deda09b882edec16d965632505a80

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b0fee2c46e5deda09b882edec16d965632505a80
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260826/06dee469/attachment.htm>


More information about the debian-security-tracker-commits mailing list