[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 31 08:35:30 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9badb6b8 by Salvatore Bonaccorso at 2026-08-31T09:34:57+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -47,25 +47,25 @@ CVE-2026-82643 (WWBN AVideo contains an unauthenticated credential submission vu
 CVE-2026-82642 (Readest is an open-source e-book reader built on Tauri. In versions pr ...)
 	- readest <itp> (bug #1107071)
 CVE-2026-82641 (keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP ...)
-	TODO: check
+	NOT-FOR-US: keploy
 CVE-2026-82640 (browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM A ...)
-	TODO: check
+	NOT-FOR-US: browser-use web-ui
 CVE-2026-82639 (NextChat versions from 2.15.8 through 2.16.1 contain an improper URL v ...)
-	TODO: check
+	NOT-FOR-US: NextChat
 CVE-2026-82638 (jina-ai reader disables its private-address guard outside Google Cloud ...)
-	TODO: check
+	NOT-FOR-US: jina-ai reader
 CVE-2026-82637 (browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate brows ...)
-	TODO: check
+	NOT-FOR-US: browser-use web-ui
 CVE-2026-82636 (Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injecti ...)
-	TODO: check
+	NOT-FOR-US: Qubes OS
 CVE-2026-82635 (Pake before 3.13.1 joins the JavaScript-supplied filename for the down ...)
-	TODO: check
+	NOT-FOR-US: Pake
 CVE-2026-82634 (Frappe Framework development builds contain an authorization flaw in t ...)
-	TODO: check
+	NOT-FOR-US: Frappe Framework
 CVE-2026-82633 (Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object auth ...)
 	NOT-FOR-US: Dolibarr
 CVE-2026-82628 (A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulne ...)
-	TODO: check
+	NOT-FOR-US: Colorful iGameCenter
 CVE-2026-82625 (A vulnerability has been found in code-projects Simple Inventory Syste ...)
 	NOT-FOR-US: code-projects
 CVE-2026-82624 (A flaw has been found in code-projects Simple Inventory System 1.0. Af ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9badb6b8ee3d9e6c9e2543eeb13ed4fb2571149b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9badb6b8ee3d9e6c9e2543eeb13ed4fb2571149b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260831/dbef69cd/attachment.htm>


More information about the debian-security-tracker-commits mailing list