[Git][security-tracker-team/security-tracker][master] auto-nfu: Update gitlab rule
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Aug 27 22:18:26 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
5e2b22dc by Moritz Muehlenhoff at 2026-08-27T23:18:04+02:00
auto-nfu: Update gitlab rule
- - - - -
2 changed files:
- data/CVE/list
- data/packages/nfu.yaml
Changes:
=====================================
data/CVE/list
=====================================
@@ -262,7 +262,7 @@ CVE-2026-78002 (A flaw was found in rsyslog. An unauthenticated remote attacker
[trixie] - rsyslog <no-dsa> (Minor issue)
NOTE: https://github.com/rsyslog/rsyslog/security/advisories/GHSA-g72f-gc6v-f2w3
CVE-2026-75871 (GitLab has remediated a vulnerability in the GitLab AI Gateway compone ...)
- TODO: check
+ NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-75573 (In MongoDB Connector for BI, mongodrdl may write a TLS private-key pas ...)
NOT-FOR-US: MongoDB Connector for BI
CVE-2026-75357 (An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to exec ...)
@@ -376,7 +376,7 @@ CVE-2026-26453 (ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null p
CVE-2026-26452 (ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 lcontains a vulnerabili ...)
TODO: check
CVE-2026-19889 (GitLab has remediated a vulnerability in the GitLab AI Gateway compone ...)
- TODO: check
+ NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-19854 (When the ClickHouse plugin uses Native protocol (the default) with PDC ...)
TODO: check
CVE-2026-17562 (Authorization bypass through User-Controlled key vulnerability in Summ ...)
=====================================
data/packages/nfu.yaml
=====================================
@@ -529,6 +529,7 @@
- cna: GitLab
- anyOf:
- product: GitLab
+ - product: GitLab AI Gateway
- reason: Google products not packaged in Debian
allOf:
- cna: Google
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5e2b22dc0e80a976b5bd4d933cbee54b84708cde
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5e2b22dc0e80a976b5bd4d933cbee54b84708cde
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260827/504d0602/attachment.htm>
More information about the debian-security-tracker-commits
mailing list