[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 26 20:14:47 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f8227f0a by security tracker role at 2026-08-26T19:14:40+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,5 +1,5 @@
 CVE-2026-9668 (With legitimate user credentials in hand, attackers can construct mali ...)
-	TODO: check
+	NOT-FOR-US: ZTE
 CVE-2026-81036 (Stalwart Mail Server does not compare an OAuth redirect target against ...)
 	TODO: check
 CVE-2026-81035 (Midday allows any member of a team to delete it. The delete procedure  ...)
@@ -199,9 +199,9 @@ CVE-2026-80203 (The getgrav/grav-plugin-api plugin before 1.0.18 does not enforc
 CVE-2026-80153
 	REJECTED
 CVE-2026-7487 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-79940 (Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions pr ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-79902 (A flaw was found in the Seattle FilmWorks plugin in GIMP. When process ...)
 	TODO: check
 CVE-2026-79619 (On Linux, several OpenZFS ioctl authorization checks accept a capabili ...)
@@ -211,7 +211,7 @@ CVE-2026-78237 (Insufficient input validation in ABR allows a low-privileged use
 CVE-2026-78236 (An insecure PIN derivation mechanism in ABR allows a low-privileged us ...)
 	TODO: check
 CVE-2026-77801 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-77658 (A stack-based buffer overflow vulnerability exists in the Dia diagram  ...)
 	TODO: check
 CVE-2026-77557 (A malicious actor with access to the network could exploit an Improper ...)
@@ -261,9 +261,9 @@ CVE-2026-77533 (A malicious actor with access to the network and low privileges
 CVE-2026-77532 (A malicious actor with access to an adjacent network could exploit a B ...)
 	TODO: check
 CVE-2026-76784 (Multiple TP-Link Kasa smart home devices contain insufficient cryptogr ...)
-	TODO: check
+	NOT-FOR-US: TPLink
 CVE-2026-75977 (The Mang Board WP plugin for WordPress is vulnerable to Missing Author ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-75960 (Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insuf ...)
 	TODO: check
 CVE-2026-75896 (Use of Hard-coded Credentials vulnerability in T\xdcB\u0130TAK B\u0130 ...)
@@ -321,17 +321,17 @@ CVE-2026-73108 (RustDesk versions before 1.4.7 contain an uncontrolled speculati
 CVE-2026-73102 (RustDesk versions 1.3.9 through 1.4.9 contain a path traversal vulnera ...)
 	TODO: check
 CVE-2026-71171 (Dell Cloud Disaster Recovery, versions20.2 and prior,containan Imprope ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-70419 (Dell Cloud Disaster Recovery, versions 20.2 and prior,containan Improp ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-6178 (The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scr ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-63179 (Winter CMS is a content management system built on the Laravel PHP fra ...)
 	TODO: check
 CVE-2026-63041 (Reliance on Untrusted Inputs in a Security Decision vulnerability in A ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-5092 (The Greenshift \u2013 animation and page builder blocks plugin for Wor ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-59683 (The OpenRGB network protocol allows to write attacker controlled strin ...)
 	TODO: check
 CVE-2026-59682 (Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB.This issu ...)
@@ -367,15 +367,15 @@ CVE-2026-48548 (Nagios Core before 4.5.12 contains a cross-site request forgery
 CVE-2026-47841 (An application using Spring Security's WebAuthn support may be vulnera ...)
 	TODO: check
 CVE-2026-47837 (Missing Authentication for Critical Function vulnerability in Spring S ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-47836 (The base directory (spring.cloud.config.server.svn.basedir) used by th ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-41262 (Fleet is an open-source device management platform built on osquery. I ...)
 	TODO: check
 CVE-2026-3235 (The WP Data Access plugin for WordPress is vulnerable to Insecure Dire ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-3035 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-36851 (Path traversal vulnerability in UnPoller 2.33.0 password field allows  ...)
 	TODO: check
 CVE-2026-35445 (Winter CMS is a content management system built on the Laravel PHP fra ...)
@@ -389,7 +389,7 @@ CVE-2026-32258 (Winter is a free, open-source content management system (CMS) ba
 CVE-2026-32257 (Winter is a free, open-source content management system (CMS) based on ...)
 	TODO: check
 CVE-2026-2388 (The Reviews and Rating \u2013 Google Reviews plugin for WordPress is v ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-19538 (The BLOCKED access control list items that are evaluated to deny acces ...)
 	TODO: check
 CVE-2026-19485 (A Predictable Resource Name vulnerability in BigQuery Import Staging i ...)
@@ -401,33 +401,33 @@ CVE-2026-19271 (Improper Neutralization of Special Elements used in an LDAP Quer
 CVE-2026-19197 (A user with organization administrator permissions can delete dashboar ...)
 	TODO: check
 CVE-2026-19042 (A command injection vulnerability in TeamViewer Full Client and Host f ...)
-	TODO: check
+	NOT-FOR-US: TeamViewer
 CVE-2026-18916 (Any remote client can crash a NSD serve child, by throttling the TCP r ...)
 	TODO: check
 CVE-2026-18884 (The WooCommerce Lottery plugin for WordPress is vulnerable to Time-Bas ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18794 (The OpenRGB network protocol allows attackers to cause memory exhausti ...)
 	TODO: check
 CVE-2026-18664 (When ranges are used for access control (i.e. of the form 1.2.3.4-1.2. ...)
 	TODO: check
 CVE-2026-18252 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-18080 (The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plu ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16444 (Improper neutralization of path traversal sequences in TeamViewer Desk ...)
-	TODO: check
+	NOT-FOR-US: TeamViewer
 CVE-2026-15990 (The Formidable Charts plugin for WordPress is vulnerable to Directory  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15985 (The Classified Listing - Mobile Number Verification plugin for WordPre ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15387 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-13481 (The IEEE 1588 PTP management-message parser in subsys/net/lib/ptp/tlv. ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-13480 (The LoRaWAN TS004 Fragmented Data Block Transport handler frag_transpo ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-13479 (The LoRaWAN application-layer clock-synchronization service parses dow ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-12717 (An Improper Input Validation vulnerability in CData JDBC driver integr ...)
 	TODO: check
 CVE-2026-12587 (The vulnerability allows the unauthorised generation of physical acces ...)
@@ -445,7 +445,7 @@ CVE-2025-56798 (Cross-Site Request Forgery (CSRF) vulnerability in Lime Technolo
 CVE-2025-29419 (CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle att ...)
 	TODO: check
 CVE-2025-10903 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2023-42179 (Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect A ...)
 	TODO: check
 CVE-2026-XXXX [GHSA-pxhw-h44j-8pfx: sandbox escape via symlink traversal during setup]



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f8227f0a01bb678b656269a703a71c96bcabafab

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f8227f0a01bb678b656269a703a71c96bcabafab
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260826/679eb49b/attachment.htm>


More information about the debian-security-tracker-commits mailing list