[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Aug 29 20:35:18 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b43390a7 by security tracker role at 2026-08-29T19:13:12+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,67 @@
+CVE-2026-82481 (The cohttp package before 6.3.0 for OCaml allows directory traversal.)
+	TODO: check
+CVE-2026-82477 (In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF iss ...)
+	TODO: check
+CVE-2026-82476 (Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT address ...)
+	TODO: check
+CVE-2026-82475 (iFlytek astron-agent through 1.1.1 contains an authorization bypass vu ...)
+	TODO: check
+CVE-2026-82474 (Sudo through 1.9.17p2 fails to apply intercept policy checks to the ex ...)
+	TODO: check
+CVE-2026-82473 (KubeEdge CloudCore through 1.23.1 accepts node task status reports on  ...)
+	TODO: check
+CVE-2026-82472 (Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upl ...)
+	TODO: check
+CVE-2026-82470 (Rodauth before 2.47.0 contains a time-based one-time password reuse vu ...)
+	TODO: check
+CVE-2026-82469 (Rodauth before 2.47.0 contains an authentication bypass vulnerability  ...)
+	TODO: check
+CVE-2026-82468 (Rodauth before 2.47.0 contains a cross-site request forgery protection ...)
+	TODO: check
+CVE-2026-82467 (Rodauth before 2.47.0 fails to validate protocol-relative return-to pa ...)
+	TODO: check
+CVE-2026-82466 (Rodauth before 2.46.0 contains an authentication bypass vulnerability  ...)
+	TODO: check
+CVE-2026-82465 (pac4j-saml before 6.5.6 does not require signature validation of SAML  ...)
+	TODO: check
+CVE-2026-82464 (pac4j-core before 6.5.6 contains an open redirect vulnerability in Def ...)
+	TODO: check
+CVE-2026-82463 (pac4j-core before 6.5.6 contains an authentication bypass vulnerabilit ...)
+	TODO: check
+CVE-2026-82462 (pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only an access ...)
+	TODO: check
+CVE-2026-82461 (pac4j-oidc before 6.5.6 fails to verify access token signatures, issue ...)
+	TODO: check
+CVE-2026-82460 (Cloud Commander before 19.20.2 contains a directory traversal vulnerab ...)
+	TODO: check
+CVE-2026-82457 (su-exec through 0.3 fails to validate numeric user and group identifie ...)
+	TODO: check
+CVE-2026-82456 (argocd-mcp 0.8.0 binds its HTTP transport to every network interface a ...)
+	TODO: check
+CVE-2026-82455 (RubyGems fails to re-validate path containment after filesystem symlin ...)
+	TODO: check
+CVE-2026-82454 (The Omnivore API (packages/api) before the fix in commit abf53d6 conta ...)
+	TODO: check
+CVE-2026-82453 (rust-iot-platform through commit 5df942ab stores user passwords in cle ...)
+	TODO: check
+CVE-2026-82452 (rust-iot-platform through commit 5df942ab contains an authentication b ...)
+	TODO: check
+CVE-2026-82451 (Formwork through 2.3.14 contains a stored cross-site scripting vulnera ...)
+	TODO: check
+CVE-2026-82450 (BookStack before 26.05.4 contains a remote code execution vulnerabilit ...)
+	TODO: check
+CVE-2026-82449 (Cockpit CMS before 2.14.1 contains an account enumeration vulnerabilit ...)
+	TODO: check
+CVE-2026-82448 (Shinobi before commit 5a76c74f contains a hardcoded connection key in  ...)
+	TODO: check
+CVE-2026-82447 (Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextP ...)
+	TODO: check
+CVE-2026-82364 (A security vulnerability has been detected in macrozheng mall up to 1. ...)
+	TODO: check
+CVE-2026-75807 (The SAML Single Sign On \u2013 SSO Login plugin for WordPress is vulne ...)
+	TODO: check
+CVE-2026-14494 (The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code  ...)
+	TODO: check
 CVE-2026-82343 (A flaw was found in the file-psd plugin in GIMP. When processing a spe ...)
 	- gimp <unfixed>
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16587
@@ -184,7 +248,7 @@ CVE-2026-62904 (Incorrect authorization in Microsoft Edge (Chromium-based) allow
 	NOT-FOR-US: Microsoft
 CVE-2026-58616 (Concurrent execution using shared resource with improper synchronizati ...)
 	NOT-FOR-US: Microsoft
-CVE-2026-56100 (SpringBlade versions 2.7.3 through 3.5.0 contain a privilege escalatio ...)
+CVE-2026-56100 (SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain  ...)
 	NOT-FOR-US: SpringBlade
 CVE-2026-55891 (PrivateBin is an online pastebin where the server has zero knowledge o ...)
 	NOT-FOR-US: PrivateBin
@@ -5225,7 +5289,7 @@ CVE-2026-79673 (Ech0 before 4.4.3 protects the PUT /user endpoint with the profi
 	NOT-FOR-US: Ech0
 CVE-2026-79672 (Ech0 before 4.4.3 fails to enforce scope-based authorization on nine c ...)
 	NOT-FOR-US: Ech0
-CVE-2026-79671 (Ech0 through 4.2.1 contains a server-side request forgery vulnerabilit ...)
+CVE-2026-79671 (Ech0 before 4.4.3 contains a server-side request forgery vulnerability ...)
 	NOT-FOR-US: Ech0
 CVE-2026-79670 (Ech0 before 4.4.3 contains a stored cross-site scripting vulnerability ...)
 	NOT-FOR-US: Ech0
@@ -6286,13 +6350,13 @@ CVE-2026-78212 (4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an
 	NOT-FOR-US: 4MOSAn
 CVE-2026-78211 (4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Com ...)
 	NOT-FOR-US: 4MOSAn
-CVE-2026-78209 (exceljs-hardened versions before 5.0.0 fail to neutralize leading equa ...)
+CVE-2026-78209 (exceljs through 4.4.0 fails to neutralize leading equals, plus, minus, ...)
 	NOT-FOR-US: exceljs-hardened
-CVE-2026-78208 (exceljs-hardened before 5.0.0 contains a path traversal vulnerability  ...)
+CVE-2026-78208 (exceljs through 4.4.0 contains a path traversal vulnerability in the W ...)
 	NOT-FOR-US: exceljs-hardened
-CVE-2026-78207 (exceljs-hardened before 5.0.0 contains a prototype pollution vulnerabi ...)
+CVE-2026-78207 (exceljs through 4.4.0 contains a prototype pollution vulnerability in  ...)
 	NOT-FOR-US: exceljs-hardened
-CVE-2026-78206 (exceljs-hardened before 5.0.0 decompresses all entries from supplied x ...)
+CVE-2026-78206 (exceljs through 4.4.0 decompresses all entries from supplied xlsx arch ...)
 	NOT-FOR-US: exceljs-hardened
 CVE-2026-78205 (BentoML's outbound connection safeguard (make_safe_connect in _interna ...)
 	NOT-FOR-US: BentoML
@@ -6384,7 +6448,7 @@ CVE-2026-77994 (Joomla Extension - joomlack.fr - Second order SQL injection in P
 	NOT-FOR-US: Joomla
 CVE-2026-77993 (Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3. ...)
 	NOT-FOR-US: Joomla
-CVE-2026-77915 (rConfig Core 8.0.0 before 8.2.13 contains an authentication bypass vul ...)
+CVE-2026-77915 (rConfig Core 8.0.0 before 8.2.10 contains an authentication bypass vul ...)
 	NOT-FOR-US: rConfig
 CVE-2026-77914 (rConfig Core 8.0.0 before 8.2.13 contains a path traversal vulnerabili ...)
 	NOT-FOR-US: rConfig



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b43390a70a9e6fe34b6b4f494a66a2d3a7427496

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b43390a70a9e6fe34b6b4f494a66a2d3a7427496
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260829/e8bab391/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list