[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Aug 29 09:52:30 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
9bc51038 by Salvatore Bonaccorso at 2026-08-29T10:48:34+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -135,11 +135,11 @@ CVE-2026-77008 (The HEL Online Classroom: AI-powered Online Classrooms WordPress
CVE-2026-77007 (The HEL Online Classroom: AI-powered Online Classrooms WordPress plugi ...)
NOT-FOR-US: WordPress plugin
CVE-2026-76798 (The MongoSQL Transition Readiness Tool writes query text and user name ...)
- TODO: check
+ NOT-FOR-US: MongoSQL Transition Readiness Tool
CVE-2026-76797 (The MongoSQL Transition Readiness Tool writes database and collection ...)
- TODO: check
+ NOT-FOR-US: MongoSQL Transition Readiness Tool
CVE-2026-76794 (MongoSQL Transition Readiness Tool does not sufficiently encode databa ...)
- TODO: check
+ NOT-FOR-US: MongoSQL Transition Readiness Tool
CVE-2026-76651 (A buffer overflow vulnerability exists in the embedded HTTP servicein ...)
NOT-FOR-US: TPLink
CVE-2026-76650 (A NULL pointer dereference vulnerability exists inTL-WR841N v14inthe U ...)
@@ -155,19 +155,19 @@ CVE-2026-76547 (The User Profile Builder WordPress plugin before 4.0.1 does not
CVE-2026-76546 (The User Profile Builder WordPress plugin before 4.0.1 does not escap ...)
NOT-FOR-US: WordPress plugin
CVE-2026-75486 (Synk Sweater Comb before 3.8.8 contains a command injection vulnerabil ...)
- TODO: check
+ NOT-FOR-US: Synk Sweater Comb
CVE-2026-75126 (PLANET GS-4210-16P2S firmware before 3.441b260626 contains multiple au ...)
- TODO: check
+ NOT-FOR-US: PLANET
CVE-2026-75125 (PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenti ...)
- TODO: check
+ NOT-FOR-US: PLANET
CVE-2026-75124 (PLANET GS-4210-16P2S firmware before 3.441b260626 contains a pre-authe ...)
- TODO: check
+ NOT-FOR-US: PLANET
CVE-2026-75123 (PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenti ...)
- TODO: check
+ NOT-FOR-US: PLANET
CVE-2026-75122 (PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenti ...)
- TODO: check
+ NOT-FOR-US: PLANET
CVE-2026-75121 (PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenti ...)
- TODO: check
+ NOT-FOR-US: PLANET
CVE-2026-75118 (A pre-authentication stack-based buffer overflow vulnerability exists ...)
NOT-FOR-US: TPLink
CVE-2026-72984 (Access of resource using incompatible type ('type confusion') in Micro ...)
@@ -185,115 +185,115 @@ CVE-2026-62904 (Incorrect authorization in Microsoft Edge (Chromium-based) allow
CVE-2026-58616 (Concurrent execution using shared resource with improper synchronizati ...)
NOT-FOR-US: Microsoft
CVE-2026-56100 (SpringBlade versions 2.7.3 through 3.5.0 contain a privilege escalatio ...)
- TODO: check
+ NOT-FOR-US: SpringBlade
CVE-2026-55891 (PrivateBin is an online pastebin where the server has zero knowledge o ...)
- TODO: check
+ NOT-FOR-US: PrivateBin
CVE-2026-55867 (Graylog is a free and open log management platform. From 6.2.0 until 6 ...)
TODO: check
CVE-2026-55860 (MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client imp ...)
- TODO: check
+ NOT-FOR-US: MariaDB Connector/R2DBC
CVE-2026-55859 (MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client imp ...)
- TODO: check
+ NOT-FOR-US: MariaDB Connector/R2DBC
CVE-2026-55858 (MariaDB Connector/J is used to connect applications developed in Java ...)
- TODO: check
+ NOT-FOR-US: MariaDB Connector/J
CVE-2026-55857 (MariaDB Connector/J is used to connect applications developed in Java ...)
- TODO: check
+ NOT-FOR-US: MariaDB Connector/J
CVE-2026-55856 (MariaDB Connector/J is used to connect applications developed in Java ...)
- TODO: check
+ NOT-FOR-US: MariaDB Connector/J
CVE-2026-55855 (MariaDB Connector/Node.js is used to connect applications developed on ...)
- TODO: check
+ NOT-FOR-US: MariaDB Connector/Node.js
CVE-2026-55854 (MariaDB Connector/Node.js is used to connect applications developed on ...)
- TODO: check
+ NOT-FOR-US: MariaDB Connector/Node.js
CVE-2026-55848 (mapfish-print is a component of MapFish for printing templated cartogr ...)
- TODO: check
+ NOT-FOR-US: MapFish
CVE-2026-55841 (Graylog is a free and open log management platform. Prior to Graylog S ...)
TODO: check
CVE-2026-55834 (Pocket ID is an OIDC provider that allows users to authenticate with t ...)
- TODO: check
+ NOT-FOR-US: Pocket ID OIDC provider
CVE-2026-55785 (free5GC is an open-source implementation of the 5G core network. Prior ...)
NOT-FOR-US: Free5GC
CVE-2026-55784 (free5GC is an open-source implementation of the 5G core network. In ve ...)
NOT-FOR-US: Free5GC
CVE-2026-55779 (Silverstripe Versioned provides versioning for Silverstripe models. Pr ...)
- TODO: check
+ NOT-FOR-US: Silverstripe
CVE-2026-55764 (Klever-Go is the Go implementation of the Klever blockchain protocol. ...)
- TODO: check
+ NOT-FOR-US: Klever-Go
CVE-2026-55763 (Klever-Go is the Go implementation of the Klever blockchain protocol. ...)
- TODO: check
+ NOT-FOR-US: Klever-Go
CVE-2026-55696 (PrivateBin is an online pastebin where the server has zero knowledge o ...)
- TODO: check
+ NOT-FOR-US: PrivateBin
CVE-2026-55678 (Arc is an open, SQL-native time-series database for telemetry. From 26 ...)
- TODO: check
+ NOT-FOR-US: Arc
CVE-2026-55673 (PowSyBl (Power System Blocks) is a framework to build power system ori ...)
- TODO: check
+ NOT-FOR-US: PowSyBl (Power System Blocks)
CVE-2026-55634 (Pimcore is an Open Source Data & Experience Management Platform. Prior ...)
- TODO: check
+ NOT-FOR-US: Pimcore
CVE-2026-55584 (phpSysInfo is a customizable PHP script that displays system informati ...)
TODO: check
CVE-2026-55569 (aqua is a declarative command-line version manager written in Go. Prio ...)
- TODO: check
+ NOT-FOR-US: aqua
CVE-2026-55566 (Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamc ...)
- TODO: check
+ NOT-FOR-US: Yamcs
CVE-2026-55565 (Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamc ...)
- TODO: check
+ NOT-FOR-US: Yamcs
CVE-2026-55559 (Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamc ...)
- TODO: check
+ NOT-FOR-US: Yamcs
CVE-2026-55552 (Yamcs is a mission control framework. Prior to 5.11.13, Yamcs StaticFi ...)
- TODO: check
+ NOT-FOR-US: Yamcs
CVE-2026-55549 (Yamcs is a mission control framework. Prior to 5.9.4, Yamcs reflects a ...)
- TODO: check
+ NOT-FOR-US: Yamcs
CVE-2026-55547 (Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamc ...)
- TODO: check
+ NOT-FOR-US: Yamcs
CVE-2026-55545 (Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamc ...)
- TODO: check
+ NOT-FOR-US: Yamcs
CVE-2026-55521 (Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamc ...)
- TODO: check
+ NOT-FOR-US: Yamcs
CVE-2026-55511 (Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamc ...)
- TODO: check
+ NOT-FOR-US: Yamcs
CVE-2026-55509 (WsgiDAV is a generic and extendable WebDAV server based on WSGI. Prior ...)
- TODO: check
+ NOT-FOR-US: WsgiDAV
CVE-2026-55485 (Piccolo Admin is an admin interface and content management system for ...)
- TODO: check
+ NOT-FOR-US: Piccolo Admin
CVE-2026-55484 (ALOS HTTP is a Linux-first Go web framework and application server bui ...)
- TODO: check
+ NOT-FOR-US: ALOS HTTP
CVE-2026-55425 (Graylog is a free and open log management platform. From 7.1.0 until 7 ...)
TODO: check
CVE-2026-55378 (JS Recon is a JavaScript enumeration and SAST tool. From 1.2.1-beta.1 ...)
- TODO: check
+ NOT-FOR-US: JS Recon
CVE-2026-55248 (plone.app.portlets provides portlets and a Plone-specific user interfa ...)
- TODO: check
+ NOT-FOR-US: plone.app.portlets
CVE-2026-55247 (plone.app.event provides the event content type for Plone. Prior to ve ...)
- TODO: check
+ NOT-FOR-US: plone.app.event for Plone
CVE-2026-55245 (Bifrost is an enterprise AI gateway for routing requests to model prov ...)
- TODO: check
+ NOT-FOR-US: Bifrost
CVE-2026-55220 (Pimcore is an Open Source Data & Experience Management Platform. Prior ...)
- TODO: check
+ NOT-FOR-US: Pimcore
CVE-2026-55215 (MariaDB Connector/Node.js is used to connect applications developed on ...)
- TODO: check
+ NOT-FOR-US: MariaDB Connector/Node.js
CVE-2026-55108 (KubeVela is an open source application delivery platform. Prior to 1.9 ...)
- TODO: check
+ NOT-FOR-US: KubeVela
CVE-2026-55068 (free5GC is an open-source implementation of the 5G core network. In 4. ...)
NOT-FOR-US: Free5GC
CVE-2026-55067 (Vikunja is an open-source self-hosted task management platform. Prior ...)
- TODO: check
+ NOT-FOR-US: Vikunja
CVE-2026-55066 (Vikunja is an open-source self-hosted task management platform. Prior ...)
- TODO: check
+ NOT-FOR-US: Vikunja
CVE-2026-55065 (Vikunja is an open-source self-hosted task management platform. From 0 ...)
- TODO: check
+ NOT-FOR-US: Vikunja
CVE-2026-55064 (Vikunja is an open-source self-hosted task management platform. From 2 ...)
- TODO: check
+ NOT-FOR-US: Vikunja
CVE-2026-54788 (dd-trace-rs provides Datadog application performance monitoring for Ru ...)
- TODO: check
+ NOT-FOR-US: dd-trace-rs
CVE-2026-54766 (Vikunja is an open-source self-hosted task management platform. From 0 ...)
- TODO: check
+ NOT-FOR-US: Vikunja
CVE-2026-54755 (Klever-Go is the Go implementation of the Klever blockchain protocol. ...)
- TODO: check
+ NOT-FOR-US: Klever-Go
CVE-2026-54754 (Klever-Go is the Go implementation of the Klever blockchain protocol. ...)
- TODO: check
+ NOT-FOR-US: Klever-Go
CVE-2026-54746 (Hatchet is a platform for orchestrating background tasks, AI agents, a ...)
- TODO: check
+ NOT-FOR-US: Hatchet
CVE-2026-54745 (Kubeflow Pipelines enables users to build and deploy portable, scalabl ...)
- TODO: check
+ NOT-FOR-US: Kubeflow Pipelines
CVE-2026-51665 (Incorrect access control in the getTracerouteCfg function of TOTOLINK ...)
NOT-FOR-US: TOTOLINK
CVE-2026-51664 (Incorrect access control in the getTelnetCfg function of TOTOLINK T6 4 ...)
@@ -405,19 +405,19 @@ CVE-2026-51611 (Incorrect access control in the startSlaveReboot function of TOT
CVE-2026-51610 (Incorrect access control in the RebootSystem function of TOTOLINK T6 4 ...)
NOT-FOR-US: TOTOLINK
CVE-2026-51376 (An issue in BitChat for iOS v1.15.0 allows a remote attacker to cause ...)
- TODO: check
+ NOT-FOR-US: BitChat
CVE-2026-50980 (Cross-Site Scripting (XSS) vulnerability in the DNS lookup/management ...)
- TODO: check
+ NOT-FOR-US: oPanel
CVE-2026-41012 (Traffic interception vulnerability in BOSH Director vCenter CPI allows ...)
- TODO: check
+ NOT-FOR-US: BOSH Director vCenter CPI
CVE-2026-3686 (IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 is vuln ...)
NOT-FOR-US: IBM
CVE-2026-3627 (IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remo ...)
NOT-FOR-US: IBM
CVE-2026-39071 (WordPress plugin (Spiffy Plugin) before 5.0.9 is affected by Stored Cr ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-39070 (WordPress plugin (Bit Assist) before 1.7.2 is affected by Stored Cross ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-22056 (StorageGRID (formerly StorageGRID Webscale) versions 11.5 and higher i ...)
NOT-FOR-US: NetApp
CVE-2026-19430 (The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does ...)
@@ -648,7 +648,7 @@ CVE-2026-6176 (The Customer Reviews for WooCommerce plugin for WordPress is vuln
CVE-2026-6128 (The All-in-One WP Migration Unlimited Extension plugin for WordPress i ...)
NOT-FOR-US: WordPress plugin
CVE-2026-5953 (Improper neutralization of input during web page generation ('cross-si ...)
- TODO: check
+ NOT-FOR-US: Ceviz Informatics Inc. Web Design
CVE-2026-5934 (The WP Rocket plugin for WordPress is vulnerable to Stored Cross-Site ...)
NOT-FOR-US: WordPress plugin
CVE-2026-5800 (Improper neutralization of input during web page generation ('cross-si ...)
@@ -767,11 +767,11 @@ CVE-2026-27852 (An attacker that can send mail to a user can craft a message who
CVE-2026-19423 (The Ultimate Member WordPress plugin before 2.13.0 does not validate ...)
NOT-FOR-US: WordPress plugin
CVE-2026-19412 (This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to th ...)
- TODO: check
+ NOT-FOR-US: CP Plus CP-XR-DE21-S Router
CVE-2026-19084 (The shared-files-pro WordPress plugin before 1.7.70 does not validate ...)
NOT-FOR-US: WordPress plugin
CVE-2026-18918 (In Eclipse Lyo versions 2.0.0 to 7.0.0, OAuth server authorization che ...)
- TODO: check
+ NOT-FOR-US: Eclipse Lyo
CVE-2026-18393 (A flaw was found in FFmpeg. The tdsc_load_cursor() function writes bey ...)
TODO: check
CVE-2026-15603 (morgan is an HTTP request logger middleware for Node.js. In versions p ...)
@@ -783,7 +783,7 @@ CVE-2026-14567 (The User Frontend WordPress plugin before 4.3.10 does not restr
CVE-2026-14558 (The User Frontend WordPress plugin before 4.3.10 does not properly va ...)
NOT-FOR-US: WordPress plugin
CVE-2026-13761 (Pega Platform versions 7.1.0 through 25.1.2 are affected by an imprope ...)
- TODO: check
+ NOT-FOR-US: Pega Platform
CVE-2026-12514 (The Shared Files WordPress plugin before 1.7.67, shared-files-pro Wor ...)
NOT-FOR-US: WordPress plugin
CVE-2026-12513 (The Shared Files WordPress plugin before 1.7.67, shared-files-pro Wor ...)
@@ -1873,9 +1873,9 @@ CVE-2026-37003 (Agno up to and including 2.5.8 is vulnerable to Remote Code Exec
CVE-2026-36102 (An issue in the inviteController.js component in Bluewave Labs Checkma ...)
NOT-FOR-US: Bluewave Labs Checkmate
CVE-2026-35869 (A Command Injection vulnerability exists in the bs_SetLimitCli_info fu ...)
- TODO: check
+ NOT-FOR-US: LB-link Router
CVE-2026-35868 (A Command Injection vulnerability exists in the bs_SetLimitCli_info fu ...)
- TODO: check
+ NOT-FOR-US: LB-link Router
CVE-2026-34620 (DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-boun ...)
NOT-FOR-US: Adobe
CVE-2026-34616 (DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-boun ...)
@@ -1903,13 +1903,13 @@ CVE-2026-18983 (The One User Avatar | User Profile Picture plugin for WordPress
CVE-2026-18978 (The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross ...)
NOT-FOR-US: WordPress plugin
CVE-2026-18965 (PayRange APIis missing proper authorization on management endpoints, w ...)
- TODO: check
+ NOT-FOR-US: PayRange
CVE-2026-18886 (ServiceNow has remediated an improper access control vulnerability tha ...)
NOT-FOR-US: ServiceNow
CVE-2026-18885 (ServiceNow has remediated a code injection vulnerability that was iden ...)
NOT-FOR-US: ServiceNow
CVE-2026-18717 (ASE2000 2.35 through 2.37 is vulnerable to an improper certificate val ...)
- TODO: check
+ NOT-FOR-US: ASE2000
CVE-2026-18324 (The Forminator Forms \u2013 Contact Form, Payment Form & Custom Form B ...)
NOT-FOR-US: WordPress plugin
CVE-2026-17610 (In SiSDK v2026.6.0 and earlier, high network traffic loads can cause a ...)
@@ -1925,7 +1925,7 @@ CVE-2026-13108 (WatchGuard Dimension is susceptible to a denial-of-service condi
CVE-2026-13086 (A stack-based buffer overflow in the epm (Endpoint Protection Manager) ...)
NOT-FOR-US: WatchGuard
CVE-2026-10036 (SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerab ...)
- TODO: check
+ NOT-FOR-US: SpeechBrain
CVE-2026-81893 (A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG ...)
- gdk-pixbuf <unfixed> (bug #1145988)
NOTE: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/merge_requests/278
@@ -2891,7 +2891,7 @@ CVE-2026-19223 (The Smush WordPress plugin before 4.3.2 does not restrict a net
CVE-2026-18823
REJECTED
CVE-2026-16895 (A logic vulnerability (fail-open condition) has been identified within ...)
- TODO: check
+ NOT-FOR-US: Metasploit Framework's JSON-RPC web service interface
CVE-2026-16809 (LimeSurvey Community Edition 7.0.5 contains a stored cross-site script ...)
TODO: check
CVE-2026-16569 (The Mobile App for WooCommerce: ShopApper Mobile App Builder Service f ...)
@@ -2909,7 +2909,7 @@ CVE-2026-13415 (The CMP WordPress plugin before 4.1.18 does not enforce an opti
CVE-2026-13414 (The CMP WordPress plugin before 4.1.18 does not perform authorization ...)
NOT-FOR-US: WordPress plugin
CVE-2025-70340 (A Broken Access Control vulnerability exists in ThingsBoard Profession ...)
- TODO: check
+ NOT-FOR-US: ThingsBoard
CVE-2025-70293 (An issue was discovered in Denx U-Boot before 2026.04. An integer over ...)
- u-boot <unfixed>
NOTE: https://www.openwall.com/lists/oss-security/2026/08/28/4
@@ -2929,15 +2929,15 @@ CVE-2025-70290 (An issue was discovered in Denx U-Boot before 2026.04. An intege
CVE-2025-62341 (HCL Connections is vulnerable to server-side request forgery (SSRF) wh ...)
NOT-FOR-US: HCL
CVE-2025-61480 (An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Boar ...)
- TODO: check
+ NOT-FOR-US: Acre Security SPC5300.000 Main Board
CVE-2025-61479 (An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Boar ...)
- TODO: check
+ NOT-FOR-US: Acre Security SPC5300.000 Main Board
CVE-2025-61478 (An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Boar ...)
- TODO: check
+ NOT-FOR-US: Acre Security SPC5300.000 Main Board
CVE-2025-51679 (An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch b ...)
- TODO: check
+ NOT-FOR-US: openRISC OR1200
CVE-2025-51675 (An issue was discovered in openRISC OR1200 commit 83ac6b. An inaccurat ...)
- TODO: check
+ NOT-FOR-US: openRISC OR1200
CVE-2023-27503
REJECTED
CVE-2026-80158 (A flaw was found in the ipa_getkeytab module of the community.general ...)
@@ -3614,12 +3614,12 @@ CVE-2026-19538 (The BLOCKED access control list items that are evaluated to deny
- nsd 4.15.1-1
NOTE: https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19538.txt
CVE-2026-19485 (A Predictable Resource Name vulnerability in BigQuery Import Staging i ...)
- TODO: check
+ NOT-FOR-US: Google Cloud Vertex AI Search for Commerce
CVE-2026-19401 (Any remote client can crash a (debugging/non-release build type) NSD s ...)
- nsd 4.15.1-1
NOTE: https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19401.txt
CVE-2026-19271 (Improper Neutralization of Special Elements used in an LDAP Query ('LD ...)
- TODO: check
+ NOT-FOR-US: Liderahenk
CVE-2026-19197 (A user with organization administrator permissions can delete dashboar ...)
TODO: check
CVE-2026-19042 (A command injection vulnerability in TeamViewer Full Client and Host f ...)
@@ -3655,25 +3655,25 @@ CVE-2026-13480 (The LoRaWAN TS004 Fragmented Data Block Transport handler frag_t
CVE-2026-13479 (The LoRaWAN application-layer clock-synchronization service parses dow ...)
NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-12717 (An Improper Input Validation vulnerability in CData JDBC driver integr ...)
- TODO: check
+ NOT-FOR-US: CData JDBC driver integration in Google Cloud BigQuery Data Transfer Service
CVE-2026-12587 (The vulnerability allows the unauthorised generation of physical acces ...)
- TODO: check
+ NOT-FOR-US: Virtuagym
CVE-2025-61165 (An arbitrary file upload vulnerability in the /v1/my_drive/batch_uploa ...)
- TODO: check
+ NOT-FOR-US: cohere North AI
CVE-2025-61164 (Cohere North AI v1.1.5 was discovered to contain an information leak v ...)
- TODO: check
+ NOT-FOR-US: cohere North AI
CVE-2025-61163 (Cohere North AI v1.1.5 was discovered to contain excessively permissiv ...)
- TODO: check
+ NOT-FOR-US: cohere North AI
CVE-2025-61162 (Incorrect access control in Cohere North AI v1.1.5 allows attackers to ...)
- TODO: check
+ NOT-FOR-US: cohere North AI
CVE-2025-56798 (Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, In ...)
- TODO: check
+ NOT-FOR-US: Unraid OS
CVE-2025-29419 (CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle att ...)
- TODO: check
+ NOT-FOR-US: CTFd
CVE-2025-10903 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2023-42179 (Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect A ...)
- TODO: check
+ NOT-FOR-US: Bird Home Automation
CVE-2026-XXXX [GHSA-pxhw-h44j-8pfx: sandbox escape via symlink traversal during setup]
- bubblewrap 0.12.0-1 (bug #1145655)
[trixie] - bubblewrap 0.12.0-1~deb13u1
@@ -5728,7 +5728,7 @@ CVE-2026-13216 (The virtio PCI driver (drivers/virtio/virtio_pci.c) parses a dev
CVE-2026-12878 (In affected versions of the Codefresh platform an authenticated user c ...)
NOT-FOR-US: Octopus Deploy
CVE-2026-12600 (Denial-of-service (DoS) vulnerability in the internal JPEG2000 (JPX) d ...)
- TODO: check
+ NOT-FOR-US: Poppler fork by Innodata Labs
CVE-2025-71407 (Nokogiri before 1.18.3 contains a stack buffer overflow vulnerability ...)
- ruby-nokogiri <not-affected> (Debian uses the system copy of libxml)
CVE-2025-71406 (Nokogiri before 1.18.4 bundles a vulnerable version of libxslt (prior ...)
@@ -6154,7 +6154,7 @@ CVE-2025-9878 (The PPWP \u2013 Password Protect WordPress | #1 Most-Reviewed Pas
CVE-2025-41741
REJECTED
CVE-2020-37268 (Print Assumptions does not report that a definition was produced while ...)
- TODO: check
+ NOT-FOR-US: Print Assumptions
CVE-2026-9728 (The userspace syscall verifier z_vrfy_mbox_send() in drivers/mbox/mbox ...)
NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-9254 (An unauthenticated OS command injection vulnerability exists in the pa ...)
@@ -507603,7 +507603,7 @@ CVE-2022-30985
CVE-2022-30984 (A buffer overflow vulnerability in the Rubrik Backup Service (RBS) Age ...)
NOT-FOR-US: Rubrik CDM
CVE-2022-30983 (A cross-site scripting (XSS) vulnerability in Support chatbot in Nopap ...)
- TODO: check
+ NOT-FOR-US: Nopaperforms Niaa-Chatbot
CVE-2022-30982 (An issue was discovered in Gentics CMS before 5.43.1. There is stored ...)
NOT-FOR-US: Gentics CMS
CVE-2022-30981 (An issue was discovered in Gentics CMS before 5.43.1. By uploading a m ...)
@@ -647513,15 +647513,15 @@ CVE-2020-15879 (Bitwarden Server 1.35.1 allows SSRF because it does not consider
NOT-FOR-US: Bitwarden Server
NOTE: bitwarden client is ITP'ed as #956836
CVE-2020-15878 (An issue was discovered in LibreNMS 1.65. A remote authenticated attac ...)
- TODO: check
+ NOT-FOR-US: LibreNMS
CVE-2020-15877 (An issue was discovered in LibreNMS before 1.65.1. It has insufficient ...)
NOT-FOR-US: LibreNMS
CVE-2020-15876 (An issue was discovered in LibreNMS 1.65. A remote authenticated attac ...)
- TODO: check
+ NOT-FOR-US: LibreNMS
CVE-2020-15875
RESERVED
CVE-2020-15874 (An issue was discovered in LibreNMS 1.65. A remote authenticated attac ...)
- TODO: check
+ NOT-FOR-US: LibreNMS
CVE-2020-15873 (In LibreNMS before 1.65.1, an authenticated attacker can achieve SQL I ...)
NOT-FOR-US: LibreNMS
CVE-2020-15872
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9bc51038e5ee2f3afbb2f4b796ad08d32348a9de
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9bc51038e5ee2f3afbb2f4b796ad08d32348a9de
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260829/87948901/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list