[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Mon Aug 31 17:45:13 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
afc59eb0 by Moritz Muehlenhoff at 2026-08-31T18:40:09+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -204,7 +204,7 @@ CVE-2026-82483 (A vulnerability was detected in coppermine-gallery Coppermine Ph
CVE-2026-82367 (Exposure of Data Element to Wrong Session vulnerability in ash-project ...)
NOT-FOR-US: ash-project ash_graphql
CVE-2026-81853 (Authorization Bypass Through User-Controlled Key vulnerability in ash- ...)
- TODO: check
+ NOT-FOR-US: ash-project ash_admin
CVE-2026-81852 (Use of Insufficiently Random Values vulnerability in ash-project ash_a ...)
NOT-FOR-US: ash-project ash_admin
CVE-2026-81643 (Incorrect Authorization vulnerability in ash-project ash_graphql deliv ...)
@@ -246,11 +246,11 @@ CVE-2026-77454 (Incorrect Authorization vulnerability in ash-project ash_sql all
CVE-2026-77013 (The \u7231\u91c7\u96c6\u6570\u636e\u91c7\u96c6\u548c\u53d1\u5e03\u63d2 ...)
NOT-FOR-US: WordPress plugin
CVE-2026-75760 (Generation of Error Message Containing Sensitive Information vulnerabi ...)
- TODO: check
+ NOT-FOR-US: ash-project ash_ai
CVE-2026-75757 (Reliance on Cookies without Validation and Integrity Checking vulnerab ...)
- TODO: check
+ NOT-FOR-US: ash-project ash_admin
CVE-2026-68951 (GROWI contains an incorrect authorization vulnerability. If this vulne ...)
- TODO: check
+ NOT-FOR-US: GROWI
CVE-2026-64844
REJECTED
CVE-2026-64843
@@ -266,7 +266,7 @@ CVE-2026-64839
CVE-2026-58574 (Dell PowerStore contains a Missing Authentication for Critical Functio ...)
NOT-FOR-US: Dell / EMC
CVE-2026-56718 (AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a pa ...)
- TODO: check
+ NOT-FOR-US: AJCloud AJY
CVE-2026-56716
REJECTED
CVE-2026-56715
@@ -274,7 +274,7 @@ CVE-2026-56715
CVE-2026-56713
REJECTED
CVE-2026-53620 (GROWI contains a vulnerability with an authorization bypass through us ...)
- TODO: check
+ NOT-FOR-US: GROWI
CVE-2026-40465 (NSP is vulnerable to an open redirect due to insufficient server-side ...)
NOT-FOR-US: Nokia
CVE-2026-40464 (NSP is vulnerable to a stored XSS due to insufficient validation or en ...)
@@ -1125,7 +1125,7 @@ CVE-2026-82220 (Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1
CVE-2026-82181 (Medical Practice Management System developed by Le-yan has a Sensitive ...)
NOT-FOR-US: Medical Practice Management System
CVE-2026-82123 (Improper neutralization of input during web page generation ('cross-si ...)
- TODO: check
+ NOT-FOR-US: Tangible Loops & Logic
CVE-2026-82112 (A flaw has been found in houtini-ai houtini-lm up to 2.13.2. The impac ...)
NOT-FOR-US: houtini-ai houtini-lm
CVE-2026-82111 (A vulnerability was detected in iswalle getnote-mcp up to 1.5.0. The a ...)
@@ -2224,7 +2224,7 @@ CVE-2026-76060 (An authenticated OS command injection vulnerability exists in Zo
CVE-2026-76053 (The TranslatePress \u2013 Translate Multilingual sites with AI Transla ...)
NOT-FOR-US: WordPress plugin
CVE-2026-75889 (Grafana Alloy\u2019s prometheus.operator.servicemonitors component all ...)
- TODO: check
+ NOT-FOR-US: Grafana Alloy
CVE-2026-75814 (The Ebyte device does not adequately verify the origin or authenticity ...)
NOT-FOR-US: Ebyte
CVE-2026-75813 (Certain configuration endpoints may lack proper server-side authoriza ...)
@@ -5910,7 +5910,6 @@ CVE-2026-79655 (A flaw was found in sos clean, a utility within the sos package.
NOTE: https://github.com/sosreport/sos/pull/4461
CVE-2026-79652 (A flaw was found in the JWT Bearer authorization grant implementation ...)
- keycloak <itp> (bug #1088287)
- TODO: check, might though be NFU for Red Hat specific component/build
CVE-2026-79623 (A security vulnerability has been detected in FishCodeTech Muteki up t ...)
NOT-FOR-US: FishCodeTech Muteki
CVE-2026-79622 (A weakness has been identified in dekdee adobe-xd-mcp 1.0.0. Impacted ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/afc59eb060dd66293607fd940a6ae94db98abefa
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/afc59eb060dd66293607fd940a6ae94db98abefa
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260831/b4375319/attachment.htm>
More information about the debian-security-tracker-commits
mailing list