[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Aug 29 08:58:31 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
dade0147 by Salvatore Bonaccorso at 2026-08-29T09:44:27+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3,65 +3,65 @@ CVE-2026-82343 (A flaw was found in the file-psd plugin in GIMP. When processing
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16587
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/6b6a3e6d8ccdf2a7d6488d0df28ec033a9801a38
 CVE-2026-82333 (multer is a middleware for handling multipart/form-data in Node.js. A  ...)
-	TODO: check
+	NOT-FOR-US: Node multer
 CVE-2026-82329 (JFrog Artifactory contains an authentication weakness that, under defa ...)
-	TODO: check
+	NOT-FOR-US: JFrog Artifactory
 CVE-2026-82306 (StarRocks through 4.0.13 contains an information disclosure vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: StarRocks
 CVE-2026-82291 (HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS r ...)
-	TODO: check
+	NOT-FOR-US: HeyForm
 CVE-2026-82290 (Chainlit through 2.12.0 fails to validate ownership of feedback record ...)
-	TODO: check
+	NOT-FOR-US: Chainlit
 CVE-2026-82289 (Gitingest through 0.3.1 fails to properly validate hostnames in _valid ...)
-	TODO: check
+	NOT-FOR-US: Gitingest
 CVE-2026-82288 (Stable Diffusion WebUI through 1.10.1 contains a credential disclosure ...)
-	TODO: check
+	NOT-FOR-US: Stable Diffusion WebUI
 CVE-2026-82287 (Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability tha ...)
-	TODO: check
+	NOT-FOR-US: Rybbit
 CVE-2026-82286 (gpt-crawler through 1.5.1 fails to validate the outputFileName paramet ...)
-	TODO: check
+	NOT-FOR-US: gpt-crawler
 CVE-2026-82285 (bisheng through 2.6.0-fix2 contains a server-side request forgery vuln ...)
-	TODO: check
+	NOT-FOR-US: bisheng
 CVE-2026-82284 (Quivr versions through 0.0.322 fail to validate chat ownership in the  ...)
-	TODO: check
+	NOT-FOR-US: Quivr
 CVE-2026-82283 (VoltAgent through 2.1.20 fails to validate conversation ownership in m ...)
-	TODO: check
+	NOT-FOR-US: VoltAgent
 CVE-2026-82282 (Atlantis through 0.47.1 fails to authenticate the /github-app/setup en ...)
-	TODO: check
+	NOT-FOR-US: Atlantis
 CVE-2026-82281 (Kotaemon through 0.12.0 fails to properly validate conversation owners ...)
-	TODO: check
+	NOT-FOR-US: Kotaemon
 CVE-2026-82280 (Quivr through 0.0.322 fails to validate ownership in prompt endpoints, ...)
-	TODO: check
+	NOT-FOR-US: Quivr
 CVE-2026-82279 (HyperDX through 1.10.1 fails to enforce role-based access controls in  ...)
-	TODO: check
+	NOT-FOR-US: HyperDX
 CVE-2026-82278 (BISHENG before 2.6.0 contains a remote code execution vulnerability in ...)
-	TODO: check
+	NOT-FOR-US: BISHENG
 CVE-2026-82277 (Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exp ...)
-	TODO: check
+	NOT-FOR-US: Argo Rollouts
 CVE-2026-82276 (StarRocks through 4.0.13 contains an authentication bypass vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: StarRocks
 CVE-2026-82275 (Qwen-Agent through 0.0.34 contains a path traversal vulnerability in t ...)
-	TODO: check
+	NOT-FOR-US: Qwen-Agent
 CVE-2026-82274 (Twenty through 2.35.0 contains an open redirect vulnerability in the O ...)
-	TODO: check
+	NOT-FOR-US: Twenty
 CVE-2026-82273 (Mastra through 1.63.0 contains an authentication bypass vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: Mastra
 CVE-2026-82272 (Immich through 3.1.0 fails to properly enforce locked asset visibility ...)
-	TODO: check
+	NOT-FOR-US: Immich
 CVE-2026-82271 (R2R through 3.6.5 fails to properly validate user ownership in convers ...)
-	TODO: check
+	NOT-FOR-US: R2R
 CVE-2026-82270 (Portkey AI Gateway through 1.15.2 contains a server-side request forge ...)
-	TODO: check
+	NOT-FOR-US: Portkey AI Gateway
 CVE-2026-82269 (Gophish through 0.12.1 fails to enforce account lockout and password c ...)
-	TODO: check
+	NOT-FOR-US: Gophish
 CVE-2026-82268 (Qwen-Agent through 0.0.34 contains a server-side request forgery vulne ...)
-	TODO: check
+	NOT-FOR-US: Qwen-Agent
 CVE-2026-82267 (Komodo through 2.3.2 discloses internal resource identifiers and write ...)
-	TODO: check
+	NOT-FOR-US: Komodo
 CVE-2026-82266 (Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin ...)
-	TODO: check
+	NOT-FOR-US: Redpanda
 CVE-2026-82265 (Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tra ...)
-	TODO: check
+	NOT-FOR-US: Zipkin
 CVE-2026-82264 (Duplicacy through 3.2.5 contains a path traversal vulnerability in the ...)
 	TODO: check
 CVE-2026-82263 (Logto through 1.42.0 contains a server-side request forgery vulnerabil ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dade0147dd8e110213b0f9167a60c69fe0ee420c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dade0147dd8e110213b0f9167a60c69fe0ee420c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260829/fbece25e/attachment.htm>


More information about the debian-security-tracker-commits mailing list