[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Aug 27 22:09:55 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f6be3b5d by Moritz Muehlenhoff at 2026-08-27T23:09:42+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -264,11 +264,11 @@ CVE-2026-78002 (A flaw was found in rsyslog. An unauthenticated remote attacker
 CVE-2026-75871 (GitLab has remediated a vulnerability in the GitLab AI Gateway compone ...)
 	TODO: check
 CVE-2026-75573 (In MongoDB Connector for BI, mongodrdl may write a TLS private-key pas ...)
-	TODO: check
+	NOT-FOR-US: MongoDB Connector for BI
 CVE-2026-75357 (An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to exec ...)
 	NOT-FOR-US: Bilibili Desktop
 CVE-2026-75159 (An unauthenticated client that can reach a MongoDB Connector for BI de ...)
-	TODO: check
+	NOT-FOR-US: MongoDB Connector for BI
 CVE-2026-75020 (Improper Neutralization of Special Elements used in an LDAP Query ('LD ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-75005 (Inefficient Algorithmic Complexity vulnerability in Apache APISIX.   A ...)
@@ -276,9 +276,9 @@ CVE-2026-75005 (Inefficient Algorithmic Complexity vulnerability in Apache APISI
 CVE-2026-74848 (Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response S ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-74233 (Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, ...)
-	TODO: check
+	NOT-FOR-US: Zbtlink
 CVE-2026-74232 (Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.110 ...)
-	TODO: check
+	NOT-FOR-US: Zbtlink
 CVE-2026-71402 (An out-of-bounds read was found in the DHCPv4 packet capture code of w ...)
 	TODO: check
 CVE-2026-71401 (An integer underflow was found in the DHCPv4 packet capture code of wi ...)
@@ -4734,10 +4734,10 @@ CVE-2026-12554 (Potential security vulnerabilities have been identified in HP Ea
 	NOT-FOR-US: HP
 CVE-2026-10618 (Hugo's default fenced-code-block renderer writes attribute values take ...)
 	- hugo <unfixed>
-	TODO: check details upstream
+	NOTE: https://github.com/gohugoio/hugo/issues/15247
 CVE-2026-10582 (Hugo's security.http.urls allowlist is the only control on outbound fe ...)
 	- hugo <unfixed>
-	TODO: check details upstream
+	NOTE: https://github.com/gohugoio/hugo/issues/15247
 CVE-2025-68833 (HCL Hive Keycloak IAM Instance is affected by insufficient granularity ...)
 	NOT-FOR-US: HCL
 CVE-2025-68825 (HCL Hive is affected by incorrect default permissions which could allo ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f6be3b5dcbecc3b39fbc8ef5847add6e5b8a6abe

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f6be3b5dcbecc3b39fbc8ef5847add6e5b8a6abe
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260827/1191a9d2/attachment.htm>


More information about the debian-security-tracker-commits mailing list