[Git][security-tracker-team/security-tracker][master] auto-nfu: Update gitlab rule

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Aug 27 22:18:26 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5e2b22dc by Moritz Muehlenhoff at 2026-08-27T23:18:04+02:00
auto-nfu: Update gitlab rule

- - - - -


2 changed files:

- data/CVE/list
- data/packages/nfu.yaml


Changes:

=====================================
data/CVE/list
=====================================
@@ -262,7 +262,7 @@ CVE-2026-78002 (A flaw was found in rsyslog. An unauthenticated remote attacker
 	[trixie] - rsyslog <no-dsa> (Minor issue)
 	NOTE: https://github.com/rsyslog/rsyslog/security/advisories/GHSA-g72f-gc6v-f2w3
 CVE-2026-75871 (GitLab has remediated a vulnerability in the GitLab AI Gateway compone ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-75573 (In MongoDB Connector for BI, mongodrdl may write a TLS private-key pas ...)
 	NOT-FOR-US: MongoDB Connector for BI
 CVE-2026-75357 (An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to exec ...)
@@ -376,7 +376,7 @@ CVE-2026-26453 (ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null p
 CVE-2026-26452 (ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 lcontains a vulnerabili ...)
 	TODO: check
 CVE-2026-19889 (GitLab has remediated a vulnerability in the GitLab AI Gateway compone ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-19854 (When the ClickHouse plugin uses Native protocol (the default) with PDC ...)
 	TODO: check
 CVE-2026-17562 (Authorization bypass through User-Controlled key vulnerability in Summ ...)


=====================================
data/packages/nfu.yaml
=====================================
@@ -529,6 +529,7 @@
     - cna: GitLab
     - anyOf:
       - product: GitLab
+      - product: GitLab AI Gateway
 - reason: Google products not packaged in Debian
   allOf:
     - cna: Google



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5e2b22dc0e80a976b5bd4d933cbee54b84708cde

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5e2b22dc0e80a976b5bd4d933cbee54b84708cde
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260827/504d0602/attachment.htm>


More information about the debian-security-tracker-commits mailing list