[Git][security-tracker-team/security-tracker][master] Process some new NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 31 15:59:36 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
636511f0 by Salvatore Bonaccorso at 2026-08-31T16:49:50+02:00
Process some new NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -206,43 +206,43 @@ CVE-2026-82367 (Exposure of Data Element to Wrong Session vulnerability in ash-p
 CVE-2026-81853 (Authorization Bypass Through User-Controlled Key vulnerability in ash- ...)
 	TODO: check
 CVE-2026-81852 (Use of Insufficiently Random Values vulnerability in ash-project ash_a ...)
-	TODO: check
+	NOT-FOR-US: ash-project ash_admin
 CVE-2026-81643 (Incorrect Authorization vulnerability in ash-project ash_graphql deliv ...)
-	TODO: check
+	NOT-FOR-US: ash-project ash_graphql
 CVE-2026-81636 (Allocation of Resources Without Limits or Throttling vulnerability in  ...)
-	TODO: check
+	NOT-FOR-US: ash-project ash_graphql
 CVE-2026-81633 (Improper Input Validation vulnerability in ash-project ash_graphql all ...)
-	TODO: check
+	NOT-FOR-US: ash-project ash_graphql
 CVE-2026-81322 (Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: ash-project ash_cloak
 CVE-2026-81319 (Deserialization of Untrusted Data vulnerability in ash-project ash_clo ...)
-	TODO: check
+	NOT-FOR-US: ash-project ash_cloak
 CVE-2026-81318 (Incorrect Authorization vulnerability in ash-project ash_sql allows a  ...)
-	TODO: check
+	NOT-FOR-US: ash-project ash_sql
 CVE-2026-81316 (Incorrect Authorization vulnerability in ash-project ash_sql allows a  ...)
-	TODO: check
+	NOT-FOR-US: ash-project ash_sql
 CVE-2026-81315 (Origin Validation Error vulnerability in ash-project ash_ai allows a m ...)
-	TODO: check
+	NOT-FOR-US: ash-project ash_ai
 CVE-2026-80227 (Incorrect Comparison vulnerability in ash-project ash_sql allows a use ...)
-	TODO: check
+	NOT-FOR-US: ash-project ash_sql
 CVE-2026-80223 (Incorrect Authorization vulnerability in ash-project ash_graphql allow ...)
-	TODO: check
+	NOT-FOR-US: ash-project ash_graphql
 CVE-2026-78699 (Unchecked Return Value vulnerability in ash-project ash_postgres allow ...)
-	TODO: check
+	NOT-FOR-US: ash-project ash_postgres
 CVE-2026-78693 (Generation of Error Message Containing Sensitive Information vulnerabi ...)
-	TODO: check
+	NOT-FOR-US: ash-project ash_graphql
 CVE-2026-78691 (Improper Neutralization of Special Elements in Data Query Logic vulner ...)
-	TODO: check
+	NOT-FOR-US: ash-project ash_sql
 CVE-2026-78228 (Uncontrolled Recursion vulnerability in ash-project ash_oban allows a  ...)
-	TODO: check
+	NOT-FOR-US: ash-project ash_oban
 CVE-2026-78038 (Improperly Controlled Modification of Dynamically-Determined Object At ...)
-	TODO: check
+	NOT-FOR-US: ash-project ash_oban
 CVE-2026-77956 (Improper Control of Generation of Code (Code Injection) vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: ash-project ash_ai
 CVE-2026-77850 (Stored Cross-site Scripting vulnerability in ash-project ash_admin exe ...)
-	TODO: check
+	NOT-FOR-US: ash-project ash_admin
 CVE-2026-77454 (Incorrect Authorization vulnerability in ash-project ash_sql allows a  ...)
-	TODO: check
+	NOT-FOR-US: ash-project ash_sql
 CVE-2026-77013 (The \u7231\u91c7\u96c6\u6570\u636e\u91c7\u96c6\u548c\u53d1\u5e03\u63d2 ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-75760 (Generation of Error Message Containing Sensitive Information vulnerabi ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/636511f0daec6fb820f3ed80fed51ec7677f9983

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/636511f0daec6fb820f3ed80fed51ec7677f9983
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260831/b816e276/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list