[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 28 12:18:34 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
20dbdd20 by Salvatore Bonaccorso at 2026-08-28T10:55:58+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -756,15 +756,15 @@ CVE-2026-81729 (Dolibarr before 23.0.4 authorizes REST API document deletion aga
CVE-2026-81728 (Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX im ...)
NOT-FOR-US: Dolibarr
CVE-2026-81530 (A weakness in the client-side encryption configuration surface of the ...)
- TODO: check
+ NOT-FOR-US: MongoDB C# Driver
CVE-2026-81529 (Improper neutralization of delimiters in connection-URL construction a ...)
- TODO: check
+ NOT-FOR-US: MongoDB C# Driver
CVE-2026-81528 (A MongoDB C# driver document-replacement code path omits the element-n ...)
- TODO: check
+ NOT-FOR-US: MongoDB C# Driver
CVE-2026-81527 (A NoSQL/expression injection weakness exists in the LINQ-to-aggregatio ...)
- TODO: check
+ NOT-FOR-US: MongoDB C# Driver
CVE-2026-81526 (The MongoDB Rust Driver does not neutralize special characters in a ca ...)
- TODO: check
+ NOT-FOR-US: MongoDB Rust Driver
CVE-2026-81525 (The MongoDB client library for PHP does not sufficiently sanitize spec ...)
TODO: check
CVE-2026-81524 (A weakness in the MongoDB C Driver allows special elements in caller-s ...)
@@ -772,7 +772,7 @@ CVE-2026-81524 (A weakness in the MongoDB C Driver allows special elements in ca
CVE-2026-81523 (A missing input-validation issue in MongoDB libmongocrypt's automatic- ...)
TODO: check
CVE-2026-81522 (A weakness in the MongoDB C++ Driver's handling of caller-supplied nam ...)
- TODO: check
+ NOT-FOR-US: MongoDB C++ Driver
CVE-2026-81521 (The MongoDB Go Driver's client-level bulk write operation may accept a ...)
TODO: check
CVE-2026-78618 (A business logic flaw in WatchGuard Dimension allows an authenticated ...)
@@ -800,7 +800,7 @@ CVE-2026-78498 (A server-side request forgery (SSRF) vulnerability WatchGuard Di
CVE-2026-78495 (A server-side request forgery (SSRF) vulnerability WatchGuard Dimensio ...)
NOT-FOR-US: WatchGuard
CVE-2026-78239 (Xiiaozet LK100W exposes a critical management function that can be in ...)
- TODO: check
+ NOT-FOR-US: Xiiaozet LK100W
CVE-2026-78195 (A Cross-Site Scripting (XSS) vulnerability in the WatchGuard Dimension ...)
NOT-FOR-US: WatchGuard
CVE-2026-78174 (WatchGuard Dimension records unredacted session identifiers for logged ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/20dbdd2016b8cf9277e817130dfd3de0b71a39e7
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/20dbdd2016b8cf9277e817130dfd3de0b71a39e7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260828/ce92097a/attachment.htm>
More information about the debian-security-tracker-commits
mailing list