[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Aug 27 22:24:01 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
3518c9cf by Moritz Muehlenhoff at 2026-08-27T23:23:28+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -280,19 +280,19 @@ CVE-2026-74233 (Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE8
 CVE-2026-74232 (Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.110 ...)
 	NOT-FOR-US: Zbtlink
 CVE-2026-71402 (An out-of-bounds read was found in the DHCPv4 packet capture code of w ...)
-	TODO: check
+	NOT-FOR-US: SuSE
 CVE-2026-71401 (An integer underflow was found in the DHCPv4 packet capture code of wi ...)
-	TODO: check
+	NOT-FOR-US: SuSE
 CVE-2026-66155 (A vulnerability has been identified in Element maps-ng V47 (All versio ...)
 	NOT-FOR-US: Siemens
 CVE-2026-64896 (Debug and Test Interface With Improper Access Control vulnerability in ...)
 	NOT-FOR-US: Johnson Controls
 CVE-2026-5738 (Improper neutralization of input during web page generation ('cross-si ...)
-	TODO: check
+	NOT-FOR-US: DoXBASE
 CVE-2026-5680 (A flaw was found in Undertow. A remote attacker could exploit this vul ...)
 	TODO: check
 CVE-2026-5218 (Improper neutralization of Script-Related HTML tags in a web page (bas ...)
-	TODO: check
+	NOT-FOR-US: E-Commerce Pack
 CVE-2026-59355 (In versions of Spring Authorization Server 1.5.0 through 1.5.7, the au ...)
 	TODO: check
 CVE-2026-59354 (In versions of Spring Security's OAuth2 Authorization Server module 7. ...)
@@ -302,13 +302,13 @@ CVE-2026-59280 (Applications using Spring Framework's FreeMarker integration may
 CVE-2026-59272 (Any application shipping logs to RabbitMQ over TLS via the Log4j2 appe ...)
 	NOT-FOR-US: VMware
 CVE-2026-57499 (Liman is open source server management software. Prior to 2.2.2 - 1103 ...)
-	TODO: check
+	NOT-FOR-US: Liman
 CVE-2026-56652 (Dool in versions up to 1.3.8 is vulnerable to a CSV injection vulnerab ...)
-	TODO: check
+	- dool <itp> (bug #1032875)
 CVE-2026-56651 (Dool in versions up to 1.3.8 is vulnerable tosymlink following when th ...)
-	TODO: check
+	- dool <itp> (bug #1032875)
 CVE-2026-40526 (Volmarg Personal Management System contains a path traversal vulnerabi ...)
-	TODO: check
+	NOT-FOR-US: Volmarg Personal Management System
 CVE-2026-34674 (Substance3D - Sampler versions 5.1.3 and earlier are affected by a Hea ...)
 	NOT-FOR-US: Adobe
 CVE-2026-32566 (Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types ...)
@@ -354,39 +354,39 @@ CVE-2026-30051 (An issue in the CreateUEContextProcedure function (/v1/ue-contex
 CVE-2026-30050 (An issue in the ModifyAMFEventSubscriptionProcedure function (processo ...)
 	NOT-FOR-US: Free5GC
 CVE-2026-30047 (A reachable assertion vulnerability in the /nsmf-pdusession/v1/sm-cont ...)
-	TODO: check
+	- open5gs <itp> (bug #1094791)
 CVE-2026-30046 (A reachable assertion vulnerability in the NUDM-UECM interface of Open ...)
-	TODO: check
+	- open5gs <itp> (bug #1094791)
 CVE-2026-30045 (An integer overflow in the /nnrf-disc/v1/nf-instances component of ope ...)
-	TODO: check
+	- open5gs <itp> (bug #1094791)
 CVE-2026-27330 (Unauthenticated Broken Access Control in Mobile App for WooCommerce <= ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-26899 (An issue was discovered in luci-app-https-dns-proxy on OpenWrt PR #15  ...)
-	TODO: check
+	NOT-FOR-US: OpenWrt
 CVE-2026-26897 (An issue in EcoOnline EHS (com.airsweb.v10) application for Android, v ...)
-	TODO: check
+	NOT-FOR-US: EcoOnline EHS
 CVE-2026-26459 (ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a vulnerabilit ...)
-	TODO: check
+	NOT-FOR-US: ccoap
 CVE-2026-26457 (ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer ...)
-	TODO: check
+	NOT-FOR-US: ccoap
 CVE-2026-26456 (A null pointer dereference vulnerability exists in the server-side ses ...)
-	TODO: check
+	NOT-FOR-US: ccoap
 CVE-2026-26453 (ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer ...)
-	TODO: check
+	NOT-FOR-US: ccoap
 CVE-2026-26452 (ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 lcontains a vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: ccoap
 CVE-2026-19889 (GitLab has remediated a vulnerability in the GitLab AI Gateway compone ...)
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-19854 (When the ClickHouse plugin uses Native protocol (the default) with PDC ...)
-	TODO: check
+	NOT-FOR-US: Clickhouse Datasource for Grafana
 CVE-2026-17562 (Authorization bypass through User-Controlled key vulnerability in Summ ...)
-	TODO: check
+	NOT-FOR-US: AdisyonPro
 CVE-2026-16279 (An Improper Authorization vulnerability affecting 3DPassport in 3DSwym ...)
 	NOT-FOR-US: Dassault Systemes
 CVE-2026-11754 (Observable discrepancy vulnerability in Seres Software syWEB allows Ac ...)
-	TODO: check
+	NOT-FOR-US: Seres Software syWEB
 CVE-2026-11747 (Improper neutralization of input during web page generation ('cross-si ...)
-	TODO: check
+	NOT-FOR-US: Seres Software syWEB
 CVE-2025-62343 (HCL IntelliOps Event Management (IEM) is affected by an Admin Session  ...)
 	NOT-FOR-US: HCL
 CVE-2025-62342 (HCL IntelliOps Event Management (IEM) is affected by a Session Deletio ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3518c9cf2a4b17ad0f504987568585d28f1c757f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3518c9cf2a4b17ad0f504987568585d28f1c757f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260827/d2f2be50/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list