[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Aug 29 09:03:25 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
993c867a by Salvatore Bonaccorso at 2026-08-29T09:55:54+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -63,33 +63,33 @@ CVE-2026-82266 (Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with
 CVE-2026-82265 (Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tra ...)
 	NOT-FOR-US: Zipkin
 CVE-2026-82264 (Duplicacy through 3.2.5 contains a path traversal vulnerability in the ...)
-	TODO: check
+	NOT-FOR-US: Duplicacy
 CVE-2026-82263 (Logto through 1.42.0 contains a server-side request forgery vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: Logto
 CVE-2026-82262 (Logto through 1.42.0 contains a server-side request forgery vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: Logto
 CVE-2026-82021 (Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: Hermes Agent
 CVE-2026-82020 (Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restrict ...)
-	TODO: check
+	NOT-FOR-US: Hermes Agent
 CVE-2026-82018 (IGEL OS 12 before 12.9.0, 12.8.3 LTS and IGEL OS 11 before 11.11.150 c ...)
-	TODO: check
+	NOT-FOR-US: IGEL
 CVE-2026-82017 (IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boo ...)
-	TODO: check
+	NOT-FOR-US: IGEL
 CVE-2026-81849 (Improper limitation of a pathname to a restricted directory in the aws ...)
 	NOT-FOR-US: Amazon
 CVE-2026-81533 (An application using the MongoDB BI Connector ODBC Driver may encounte ...)
-	TODO: check
+	NOT-FOR-US: MongoDB BI Connector ODBC Driver
 CVE-2026-81532 (A user able to submit SQL through an application using the MongoDB Con ...)
-	TODO: check
+	NOT-FOR-US: MongoDB BI Connector ODBC Driver
 CVE-2026-81520 (A network-reachable client that has not yet authenticated can hold a M ...)
-	TODO: check
+	NOT-FOR-US: MongoDB BI Connector ODBC Driver
 CVE-2026-81518 (When mongosqld is configured with a client certificate authority file, ...)
-	TODO: check
+	NOT-FOR-US: MongoDB BI Connector
 CVE-2026-81517 (An unauthenticated party able to reach the port of a MongoDB Connector ...)
-	TODO: check
+	NOT-FOR-US: MongoDB BI Connector
 CVE-2026-81490 (A database user able to create a view in a namespace that MongoDB Conn ...)
-	TODO: check
+	NOT-FOR-US: MongoDB BI Connector
 CVE-2026-81346 (The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-81342 (The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.43 d ...)
@@ -105,25 +105,25 @@ CVE-2026-80488 (The WP Ultimate CSV Importer  WordPress plugin before 9.0 does n
 CVE-2026-80311 (The Stripe Payment Forms by WP Full Pay  WordPress plugin before 8.5.5 ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-77939 (Flextype CMS through v1.0.0-dev contains an expression language inject ...)
-	TODO: check
+	NOT-FOR-US: Flextype CMS
 CVE-2026-77786 (The Rank Math SEO  WordPress plugin before 1.0.277 does not check that ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-77704 (The Booking for Appointments and Events Calendar  WordPress plugin bef ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-77586 (In MongoDB Connector for BI, MongoDB object names such as collection,  ...)
-	TODO: check
+	NOT-FOR-US: MongoDB BI Connector
 CVE-2026-77218 (PLANET GS-4210-16P2S firmware before 3.441b260626 contains authenticat ...)
-	TODO: check
+	NOT-FOR-US: PLANET
 CVE-2026-77217 (PLANET GS-4210-16P2S firmware before 3.441b260626 contains authenticat ...)
-	TODO: check
+	NOT-FOR-US: PLANET
 CVE-2026-77184 (In MongoDB Connector for BI, the description text of a collection's JS ...)
-	TODO: check
+	NOT-FOR-US: MongoDB BI Connector
 CVE-2026-77078 (multer is a middleware for handling multipart/form-data in Node.js. A  ...)
-	TODO: check
+	NOT-FOR-US: Node multer
 CVE-2026-77063 (multer is a middleware for handling multipart/form-data in Node.js. Wh ...)
-	TODO: check
+	NOT-FOR-US: Node multer
 CVE-2026-77037 (multer is a middleware for handling multipart/form-data in Node.js. In ...)
-	TODO: check
+	NOT-FOR-US: Node multer
 CVE-2026-77012 (The \u7231\u91c7\u96c6\u6570\u636e\u91c7\u96c6\u548c\u53d1\u5e03\u63d2 ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-77010 (The HEL Online Classroom: AI-powered Online Classrooms WordPress plugi ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/993c867a5685c3df3cad6db502e7d0539fdf74ac

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/993c867a5685c3df3cad6db502e7d0539fdf74ac
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260829/2bec7ec2/attachment.htm>


More information about the debian-security-tracker-commits mailing list