[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 28 19:59:30 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
283c6b7c by Salvatore Bonaccorso at 2026-08-28T20:58:50+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1012,7 +1012,7 @@ CVE-2026-53578 (Trilium is an open-source hierarchical note-taking application.
 CVE-2026-48996 (Trilium is an open-source hierarchical note-taking application. In ver ...)
 	NOT-FOR-US: Trilium Notes
 CVE-2026-47727 (Trilium is an open-source hierarchical note-taking application. In ver ...)
-	TODO: check
+	NOT-FOR-US: Trilium Notes
 CVE-2026-44629 (Improper access control to the Synergis Softwire installation folder.  ...)
 	NOT-FOR-US: Genetec
 CVE-2026-3129 (The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross ...)
@@ -2050,19 +2050,19 @@ CVE-2026-47842 (Applications using AesBytesEncryptor with the two-argument const
 CVE-2026-47834 (Spring Data JPA's Sort validation can be bypassed when parameters cont ...)
 	TODO: check
 CVE-2026-47666 (Penpot is an open-source design and prototyping platform. In versions  ...)
-	TODO: check
+	NOT-FOR-US: Penpot
 CVE-2026-47665 (Penpot is an open-source design and prototyping platform. In versions  ...)
-	TODO: check
+	NOT-FOR-US: Penpot
 CVE-2026-46371 (Fleet is an open-source device management platform built on osquery. I ...)
-	TODO: check
+	NOT-FOR-US: Fleet
 CVE-2026-46370 (Fleet is an open-source device management platform built on osquery. I ...)
-	TODO: check
+	NOT-FOR-US: Fleet
 CVE-2026-46369 (Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol ba ...)
-	TODO: check
+	NOT-FOR-US: Nimiq
 CVE-2026-45694 (LibreNMS is a network monitoring system. In versions up to and includi ...)
-	TODO: check
+	NOT-FOR-US: LibreNMS
 CVE-2026-43621 (Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, co ...)
-	TODO: check
+	NOT-FOR-US: Simple Machines Forum (SMF)
 CVE-2026-39275 (Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before  ...)
 	TODO: check
 CVE-2026-26449 (In Stomper 5e2741e when a client sends a SEND frame missing the destin ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/283c6b7cd0c342fb22d81dbf4e784c2cc313230f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/283c6b7cd0c342fb22d81dbf4e784c2cc313230f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260828/8fca768f/attachment.htm>


More information about the debian-security-tracker-commits mailing list