[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 28 12:18:34 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
20dbdd20 by Salvatore Bonaccorso at 2026-08-28T10:55:58+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -756,15 +756,15 @@ CVE-2026-81729 (Dolibarr before 23.0.4 authorizes REST API document deletion aga
 CVE-2026-81728 (Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX im ...)
 	NOT-FOR-US: Dolibarr
 CVE-2026-81530 (A weakness in the client-side encryption configuration surface of the  ...)
-	TODO: check
+	NOT-FOR-US: MongoDB C# Driver
 CVE-2026-81529 (Improper neutralization of delimiters in connection-URL construction a ...)
-	TODO: check
+	NOT-FOR-US: MongoDB C# Driver
 CVE-2026-81528 (A MongoDB C# driver document-replacement code path omits the element-n ...)
-	TODO: check
+	NOT-FOR-US: MongoDB C# Driver
 CVE-2026-81527 (A NoSQL/expression injection weakness exists in the LINQ-to-aggregatio ...)
-	TODO: check
+	NOT-FOR-US: MongoDB C# Driver
 CVE-2026-81526 (The MongoDB Rust Driver does not neutralize special characters in a ca ...)
-	TODO: check
+	NOT-FOR-US: MongoDB Rust Driver
 CVE-2026-81525 (The MongoDB client library for PHP does not sufficiently sanitize spec ...)
 	TODO: check
 CVE-2026-81524 (A weakness in the MongoDB C Driver allows special elements in caller-s ...)
@@ -772,7 +772,7 @@ CVE-2026-81524 (A weakness in the MongoDB C Driver allows special elements in ca
 CVE-2026-81523 (A missing input-validation issue in MongoDB libmongocrypt's automatic- ...)
 	TODO: check
 CVE-2026-81522 (A weakness in the MongoDB C++ Driver's handling of caller-supplied nam ...)
-	TODO: check
+	NOT-FOR-US: MongoDB C++ Driver
 CVE-2026-81521 (The MongoDB Go Driver's client-level bulk write operation may accept a ...)
 	TODO: check
 CVE-2026-78618 (A business logic flaw in WatchGuard Dimension allows an authenticated  ...)
@@ -800,7 +800,7 @@ CVE-2026-78498 (A server-side request forgery (SSRF) vulnerability WatchGuard Di
 CVE-2026-78495 (A server-side request forgery (SSRF) vulnerability WatchGuard Dimensio ...)
 	NOT-FOR-US: WatchGuard
 CVE-2026-78239 (Xiiaozet LK100W exposes a critical management function that can be  in ...)
-	TODO: check
+	NOT-FOR-US: Xiiaozet LK100W
 CVE-2026-78195 (A Cross-Site Scripting (XSS) vulnerability in the WatchGuard Dimension ...)
 	NOT-FOR-US: WatchGuard
 CVE-2026-78174 (WatchGuard Dimension records unredacted session identifiers for logged ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/20dbdd2016b8cf9277e817130dfd3de0b71a39e7

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/20dbdd2016b8cf9277e817130dfd3de0b71a39e7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260828/ce92097a/attachment.htm>


More information about the debian-security-tracker-commits mailing list