[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 28 10:03:48 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e3e41376 by Salvatore Bonaccorso at 2026-08-28T09:56:36+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -712,41 +712,41 @@ CVE-2026-80590 [inet: frags: strip GSO state from fragments before reassembly]
- linux <unfixed>
NOTE: https://git.kernel.org/linus/d5dc1e69fd7258ea605c9952e5d5947539159ae3
CVE-2026-82090 (Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects ex ...)
- TODO: check
+ NOT-FOR-US: Pocket
CVE-2026-82089 (The wallabag (aka fr.gaulupeau.apps.InThePoche) application through 2. ...)
- TODO: check
+ NOT-FOR-US: wallabag (aka fr.gaulupeau.apps.InThePoche) application
CVE-2026-82082 (NUMail developed by Green-Computing has an OS Command Injection vulner ...)
- TODO: check
+ NOT-FOR-US: NUMail
CVE-2026-82081 (wallabag 2 through 2.6.14 allows SSRF because a crafted title or conte ...)
- TODO: check
+ NOT-FOR-US: wallabag
CVE-2026-82072 (Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allow ...)
TODO: check
CVE-2026-81934 (Redis contains a use-after-free vulnerability in the 'tlsProcessPendin ...)
TODO: check
CVE-2026-81931 (Unrestricted Upload of File with Dangerous Type in the product photo u ...)
- TODO: check
+ NOT-FOR-US: Roskus Prospero Flow CRM
CVE-2026-81851 (A heap-based buffer overflow vulnerability in Fireware OS's iked proce ...)
NOT-FOR-US: WatchGuard
CVE-2026-81848 (A vulnerability was determined in cyberchitta scrapling-fetch-mcp up t ...)
- TODO: check
+ NOT-FOR-US: cyberchitta scrapling-fetch-mcp
CVE-2026-81847 (A vulnerability was found in MAA-AI MaaMCP up to 1.1.1.dev6+g2e4a41287 ...)
- TODO: check
+ NOT-FOR-US: MAA-AI MaaMCP
CVE-2026-81845 (A vulnerability has been found in arben-adm mcp-sequential-thinking up ...)
- TODO: check
+ NOT-FOR-US: arben-adm mcp-sequential-thinking
CVE-2026-81838 (A relative path traversal issue in the zip extraction functionality in ...)
NOT-FOR-US: Amazon
CVE-2026-81837 (A flaw has been found in RooCodeInc Roo-Code up to 3.51.1. This issue ...)
- TODO: check
+ NOT-FOR-US: RooCodeInc Roo-Code
CVE-2026-81836 (A vulnerability was detected in RooCodeInc Roo-Code up to 3.51.1. This ...)
- TODO: check
+ NOT-FOR-US: RooCodeInc Roo-Code
CVE-2026-81835 (A security vulnerability has been detected in RooCodeInc Roo-Code up t ...)
- TODO: check
+ NOT-FOR-US: RooCodeInc Roo-Code
CVE-2026-81834 (A weakness has been identified in RooCodeInc Roo-Code up to 3.51.1. Af ...)
- TODO: check
+ NOT-FOR-US: RooCodeInc Roo-Code
CVE-2026-81833 (A security flaw has been discovered in RooCodeInc Roo-Code up to 3.51. ...)
- TODO: check
+ NOT-FOR-US: RooCodeInc Roo-Code
CVE-2026-81731 (Frappe 15.11.0 through 16.32.0 stores and renders the workspace card d ...)
- TODO: check
+ NOT-FOR-US: Frappe
CVE-2026-81730 (Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under th ...)
NOT-FOR-US: Dolibarr
CVE-2026-81729 (Dolibarr before 23.0.4 authorizes REST API document deletion against t ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e3e41376ac9b3345231e3fe45d8d4997a932d8b4
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e3e41376ac9b3345231e3fe45d8d4997a932d8b4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260828/fe28d479/attachment.htm>
More information about the debian-security-tracker-commits
mailing list