[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 31 20:14:58 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0a87d52a by security tracker role at 2026-08-31T19:13:52+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,417 @@
+CVE-2026-83497 (Unrestricted deserialization of untrusted data in the cursor paginatio ...)
+	TODO: check
+CVE-2026-83492 (Improper input validation vulnerability in Extend Themes Kubio AI Webs ...)
+	TODO: check
+CVE-2026-82970 (Unrestricted Upload of File with Dangerous Type vulnerability in WP Le ...)
+	TODO: check
+CVE-2026-82881 (Aix-DB through 1.2.4 renders markdown with raw HTML enabled into v-htm ...)
+	TODO: check
+CVE-2026-82880 (YaCy Search Server through 1.941 contains an XML external entity injec ...)
+	TODO: check
+CVE-2026-82879 (DataEase before 2.10.26 contains multiple access control defects in th ...)
+	TODO: check
+CVE-2026-82878 (DataEase versions before 2.10.26 omit object-level authorization check ...)
+	TODO: check
+CVE-2026-82877 (ILIAS versions before 9.22, 10.0 through 10.9, and 11.0 through 11.2 c ...)
+	TODO: check
+CVE-2026-82876 (Phison PS3111-S11 controller firmware verifies RSA signatures using a  ...)
+	TODO: check
+CVE-2026-82875 (ToolJet before v3.16.208 contains an authorization bypass vulnerabilit ...)
+	TODO: check
+CVE-2026-82874 (ToolJet before v3.16.208 fails to validate that authenticated users be ...)
+	TODO: check
+CVE-2026-82873 (ToolJet through 3.0.0-ee-beta.2 contains authorization bypass vulnerab ...)
+	TODO: check
+CVE-2026-82872 (ToolJet before v3.16.208 fails to validate that the path organizationI ...)
+	TODO: check
+CVE-2026-82871 (ToolJet before v3.16.208 fails to validate organization membership in  ...)
+	TODO: check
+CVE-2026-82870 (ToolJet before v3.16.208 fails to validate organizationId ownership in ...)
+	TODO: check
+CVE-2026-82869 (ToolJet Database versions before v3.16.44 contain a privilege escalati ...)
+	TODO: check
+CVE-2026-82868 (@pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerabil ...)
+	TODO: check
+CVE-2026-82867 (@pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerabil ...)
+	TODO: check
+CVE-2026-82866 (@pdfme/common before 5.5.10 contains a server-side request forgery vul ...)
+	TODO: check
+CVE-2026-82865 (pdfme schemas before 5.5.10 contains a cross-site scripting vulnerabil ...)
+	TODO: check
+CVE-2026-82864 (pdfme pdf-lib versions before 5.5.10 contain an unbounded buffer growt ...)
+	TODO: check
+CVE-2026-82863 (@hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail ...)
+	TODO: check
+CVE-2026-82862 (Hulumi versions before v1.3.2 resolve the threat-model helper script f ...)
+	TODO: check
+CVE-2026-82861 (@hulumi/policies versions before 1.3.2 contain a parent spoof bypass v ...)
+	TODO: check
+CVE-2026-82860 (@hulumi/policies versions before 1.3.2 fail to fully inspect inline an ...)
+	TODO: check
+CVE-2026-82859 (hulumi versions before v1.3.2 contain a deployment SCP template that a ...)
+	TODO: check
+CVE-2026-82858 (@hulumi/drift versions before 1.3.2 accept externally supplied execute ...)
+	TODO: check
+CVE-2026-82857 (hulumi versions before v1.3.2 contain a privilege escalation vulnerabi ...)
+	TODO: check
+CVE-2026-82856 (@hulumi/policies versions before 1.3.2 fail to properly validate set-q ...)
+	TODO: check
+CVE-2026-82855 (@hulumi/policies versions before 1.3.2 contain an evidence validation  ...)
+	TODO: check
+CVE-2026-82854 (Nodemailer before 8.0.4 is vulnerable to SMTP command injection throug ...)
+	TODO: check
+CVE-2026-82853 (Nodemailer versions before 8.0.5 contain an SMTP command injection vul ...)
+	TODO: check
+CVE-2026-82838 (The default docker image shipped for Venueless did not properly ensure ...)
+	TODO: check
+CVE-2026-82823
+	REJECTED
+CVE-2026-82821 (A vulnerability was determined in FLVMeta up to 1.2.2. Affected by thi ...)
+	TODO: check
+CVE-2026-82820 (A vulnerability was found in FLVMeta up to 1.2.2. Affected is the func ...)
+	TODO: check
+CVE-2026-82818 (A vulnerability was determined in dibo-software diboot 3.8.0. This aff ...)
+	TODO: check
+CVE-2026-82817 (A vulnerability was found in dibo-software diboot 3.8.0. Affected by t ...)
+	TODO: check
+CVE-2026-82816 (A vulnerability has been found in dibo-software diboot 3.8.0. Affected ...)
+	TODO: check
+CVE-2026-82815 (A flaw has been found in MegaEase EaseProbe up to 2.3.0. Affected is t ...)
+	TODO: check
+CVE-2026-82813 (A vulnerability was detected in BEN Group TubeBuddy for YouTube Extens ...)
+	TODO: check
+CVE-2026-82811 (A security vulnerability has been detected in Toggl O\xdc Toggl Track  ...)
+	TODO: check
+CVE-2026-82810 (A weakness has been identified in extension.vn 2FA Authenticator Exten ...)
+	TODO: check
+CVE-2026-82809 (A security flaw has been discovered in vidIQ Vision for YouTube Extens ...)
+	TODO: check
+CVE-2026-82808 (A vulnerability was identified in Inbox Foundry ActiveInbox Extension  ...)
+	TODO: check
+CVE-2026-82807 (A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.82. Th ...)
+	TODO: check
+CVE-2026-82805 (A vulnerability was found in Typora up to 1.13.8/1.14.6. This vulnerab ...)
+	TODO: check
+CVE-2026-82803 (A vulnerability has been found in armink struct2json 1.0. This affects ...)
+	TODO: check
+CVE-2026-82802 (A flaw has been found in NASA earthdata-search 1.0.0. Affected by this ...)
+	TODO: check
+CVE-2026-82801 (A vulnerability was detected in NASA earthdata-search 1.0.0. Affected  ...)
+	TODO: check
+CVE-2026-82797 (Uncontrolled Recursion vulnerability in Samsung Open Source rlottie al ...)
+	TODO: check
+CVE-2026-82703 (A security flaw has been discovered in Edimax BR-6214K 1.40. This vuln ...)
+	TODO: check
+CVE-2026-82702 (A vulnerability was identified in Edimax BR-6214K 1.40. This affects t ...)
+	TODO: check
+CVE-2026-82701 (A vulnerability was determined in code-projects Online Shopping System ...)
+	TODO: check
+CVE-2026-82700 (A vulnerability was found in code-projects Online Shopping System 1.0. ...)
+	TODO: check
+CVE-2026-82699 (A flaw has been found in sambitraj Student Management System up to 56b ...)
+	TODO: check
+CVE-2026-82698 (A vulnerability was detected in sambitraj Student-Management-System up ...)
+	TODO: check
+CVE-2026-82697 (A security vulnerability has been detected in sambitraj Student-Manage ...)
+	TODO: check
+CVE-2026-82696 (A weakness has been identified in itsourcecode Sales and Inventory Sys ...)
+	TODO: check
+CVE-2026-82695 (A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacte ...)
+	TODO: check
+CVE-2026-82694 (A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue ...)
+	TODO: check
+CVE-2026-82693 (A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulne ...)
+	TODO: check
+CVE-2026-82692 (A vulnerability was found in D-Link DNS-340L and DNS-345 up to 2026071 ...)
+	TODO: check
+CVE-2026-82691 (A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L  ...)
+	TODO: check
+CVE-2026-82690 (A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717.  ...)
+	TODO: check
+CVE-2026-82689 (A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L an ...)
+	TODO: check
+CVE-2026-82688 (A security vulnerability has been detected in D-Link DNS-340L and DNS- ...)
+	TODO: check
+CVE-2026-82680 (A weakness has been identified in D-Link DSM-G600 1.01. This affects a ...)
+	TODO: check
+CVE-2026-82679 (A security flaw has been discovered in diem-project diem up to 5.1.3.  ...)
+	TODO: check
+CVE-2026-82678 (A vulnerability was identified in diem-project diem up to 5.1.3. The a ...)
+	TODO: check
+CVE-2026-82677 (A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is  ...)
+	TODO: check
+CVE-2026-82671 (A vulnerability has been found in IObit Unlocker 1.3.0.12. This vulner ...)
+	TODO: check
+CVE-2026-82670 (A flaw has been found in IObit Uninstaller 15.5.0.11. This affects the ...)
+	TODO: check
+CVE-2026-82669 (A vulnerability was detected in klaussilveira GitList 2.0.0. Affected  ...)
+	TODO: check
+CVE-2026-82668 (A security vulnerability has been detected in klaussilveira GitList 2. ...)
+	TODO: check
+CVE-2026-82667 (A vulnerability has been found in yaojingang GEOFlow up to 2.1.0. Impa ...)
+	TODO: check
+CVE-2026-82666 (A flaw has been found in yaojingang GEOFlow up to 2.1.0. This issue af ...)
+	TODO: check
+CVE-2026-82665 (A vulnerability was detected in yaojingang GEOFlow up to 2.1.0. This v ...)
+	TODO: check
+CVE-2026-82664 (A security vulnerability has been detected in yaojingang GEOFlow up to ...)
+	TODO: check
+CVE-2026-82662 (Nodemailer before 8.0.8 disables TLS certificate verification in lib/f ...)
+	TODO: check
+CVE-2026-82661 (Nodemailer before 8.0.9 fails to sanitize carriage return and line fee ...)
+	TODO: check
+CVE-2026-82660 (Nodemailer before 8.0.9 fails to enforce disableFileAccess and disable ...)
+	TODO: check
+CVE-2026-82659 (nodemailer before 9.0.1 fails to apply disableFileAccess and disableUr ...)
+	TODO: check
+CVE-2026-82631 (A security flaw has been discovered in valkey-io valkey 9.1.0. The aff ...)
+	TODO: check
+CVE-2026-82630 (A vulnerability was identified in PowerJob up to 5.1.2. Impacted is th ...)
+	TODO: check
+CVE-2026-82629 (A vulnerability was determined in jeecgboot jeewx-boot up to 641ab52c3 ...)
+	TODO: check
+CVE-2026-82217 (In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the A ...)
+	TODO: check
+CVE-2026-81624 (Undertow is a flexible performant web server used in JBoss EAP and Wil ...)
+	TODO: check
+CVE-2026-79750 (MCPHub is a unified hub for centrally managing and dynamically orchest ...)
+	TODO: check
+CVE-2026-79749 (MCPHub is a unified hub for centrally managing and dynamically orchest ...)
+	TODO: check
+CVE-2026-79748 (MCPHub is a unified hub for centrally managing and dynamically orchest ...)
+	TODO: check
+CVE-2026-79747 (MCPHub is a unified hub for centrally managing and dynamically orchest ...)
+	TODO: check
+CVE-2026-79746 (MCPHub is a unified hub for centrally managing and dynamically orchest ...)
+	TODO: check
+CVE-2026-79745 (MCPHub is a unified hub for centrally managing and dynamically orchest ...)
+	TODO: check
+CVE-2026-79744 (MCPHub is a unified hub for centrally managing and dynamically orchest ...)
+	TODO: check
+CVE-2026-79743 (MCPHub is a unified hub for centrally managing and dynamically orchest ...)
+	TODO: check
+CVE-2026-78422 (Subject::new_for_owner() in the zbus_polkit crate encodes the uid entr ...)
+	TODO: check
+CVE-2026-78079 (Joomla Extension - joomshaper.com - Open Redirect via Base64 Return Pa ...)
+	TODO: check
+CVE-2026-78078 (Joomla Extension - joomshaper.com - Privileged File Upload Bypass via  ...)
+	TODO: check
+CVE-2026-78077 (Joomla Extension - joomshaper.com -  Stored Cross-Site Scripting (XSS) ...)
+	TODO: check
+CVE-2026-78076 (Joomla Extension - joomshaper.com - Broken Access Control & Missing Au ...)
+	TODO: check
+CVE-2026-78075 (Joomla Extension - joomshaper.com - Broken Object-Level Authorization  ...)
+	TODO: check
+CVE-2026-78074 (Joomla Extension - miniorgange.com - Unauthenticated arbitrary extensi ...)
+	TODO: check
+CVE-2026-77975 (The affected Ebyte   product exports administrative credentials and ot ...)
+	TODO: check
+CVE-2026-77966 (The affectedEbyte   productdoes not provide separation between limited ...)
+	TODO: check
+CVE-2026-76986 (Improper neutralization of input during web page generation in Apache  ...)
+	TODO: check
+CVE-2026-76985 (Improper neutralization of input during web page generation in Apache  ...)
+	TODO: check
+CVE-2026-76984 (Improper neutralization of input during web page generation in Apache  ...)
+	TODO: check
+CVE-2026-76983 (Improper neutralization of input during web page generation in Apache  ...)
+	TODO: check
+CVE-2026-76982 (Improper neutralization of input during web page generation in Apache  ...)
+	TODO: check
+CVE-2026-76763 (A flaw was found in SmallRye GraphQL. The number scalar coercion for B ...)
+	TODO: check
+CVE-2026-76133 (The affectedEbyte   product  uses a deprecated hashing algorithm in an ...)
+	TODO: check
+CVE-2026-75802 (AjaxEditableChoiceLabel in wicket-extensions, when constructed with a  ...)
+	TODO: check
+CVE-2026-75133 (Keep Backup Daily plugin for WordPress before 2.1.4 contains a sensiti ...)
+	TODO: check
+CVE-2026-75132 (WAPT Server versions 2.6.1.17834 and earlier contains a SQL injection  ...)
+	TODO: check
+CVE-2026-74010 (Missing Authorization vulnerability in John James Jacoby bbPress allow ...)
+	TODO: check
+CVE-2026-73819 (The affectedEbyte   product's vendor configuration utility permits acc ...)
+	TODO: check
+CVE-2026-72001 (Pangolin before 1.22.0 contains an authentication bypass vulnerability ...)
+	TODO: check
+CVE-2026-71378 (ResourceIsolationRequestCycleListener protects a Wicket application ag ...)
+	TODO: check
+CVE-2026-71257 (Apache Wicket enforces the upload limits configured on a form or uploa ...)
+	TODO: check
+CVE-2026-70449 (Improper validation of resource URL attributes in Apache Wicket allows ...)
+	TODO: check
+CVE-2026-66047 (ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains  ...)
+	TODO: check
+CVE-2026-63083
+	REJECTED
+CVE-2026-5956 (Improper neutralization of special elements used in an SQL command ('S ...)
+	TODO: check
+CVE-2026-59111 (Improper neutralization of special elements used in an OS command ('OS ...)
+	TODO: check
+CVE-2026-58301 (When Apache Shiro is used with the Jakarta EE integration module, a lo ...)
+	TODO: check
+CVE-2026-53553 (Goploy is an open-source automation deployment system. Prior to versio ...)
+	TODO: check
+CVE-2026-53552 (Goploy is an open-source automation deployment system. In versions 1.1 ...)
+	TODO: check
+CVE-2026-53508 (oasdiff is a command-line and Go package that compares and detects bre ...)
+	TODO: check
+CVE-2026-53507 (oasdiff-action is a GitHub Action that detects breaking changes in Ope ...)
+	TODO: check
+CVE-2026-51730 (Incorrect access control in the delWiFiAclRules function of TOTOLINK T ...)
+	TODO: check
+CVE-2026-51729 (Incorrect access control in the delDevice function of TOTOLINK T6 4.1. ...)
+	TODO: check
+CVE-2026-51728 (Incorrect access control in the UploadFirmwareFile function of TOTOLIN ...)
+	TODO: check
+CVE-2026-51727 (Incorrect access control in the SystemSettings function of TOTOLINK T6 ...)
+	TODO: check
+CVE-2026-51726 (Incorrect access control in the delParentalRules function of TOTOLINK  ...)
+	TODO: check
+CVE-2026-51725 (Incorrect access control in the NTPSyncWithHost function of TOTOLINK T ...)
+	TODO: check
+CVE-2026-51724 (Incorrect access control in the delSmartQosCfg function of TOTOLINK T6 ...)
+	TODO: check
+CVE-2026-51723 (Incorrect access control in the UploadCustomModule function of TOTOLIN ...)
+	TODO: check
+CVE-2026-51722 (Incorrect access control in the setWiFiRepeaterCfg function of TOTOLIN ...)
+	TODO: check
+CVE-2026-51721 (Incorrect access control in the setPairCfg function of TOTOLINK T6 4.1 ...)
+	TODO: check
+CVE-2026-51720 (Incorrect access control in the delIpPortFilterRules function of TOTOL ...)
+	TODO: check
+CVE-2026-51719 (Incorrect access control in the delUrlFilterRules function of TOTOLINK ...)
+	TODO: check
+CVE-2026-51718 (Incorrect access control in the delStaticDhcpRules function of TOTOLIN ...)
+	TODO: check
+CVE-2026-51717 (Incorrect access control in the setOpModeCfg function of TOTOLINK T6 4 ...)
+	TODO: check
+CVE-2026-51716 (Incorrect access control in the delPortForwardRules function of TOTOLI ...)
+	TODO: check
+CVE-2026-51715 (Incorrect access control in the delMacFilterRules function of TOTOLINK ...)
+	TODO: check
+CVE-2026-51714 (Incorrect access control in the setRoamingCfg function of TOTOLINK T6  ...)
+	TODO: check
+CVE-2026-51713 (Incorrect access control in the setManualDialCfg function of TOTOLINK  ...)
+	TODO: check
+CVE-2026-51712 (Incorrect access control in the setApWiFiSchCfg function of TOTOLINK T ...)
+	TODO: check
+CVE-2026-51711 (Incorrect access control in the setWiFiWpsStart function of TOTOLINK T ...)
+	TODO: check
+CVE-2026-51710 (Incorrect access control in the setParentalRules function of TOTOLINK  ...)
+	TODO: check
+CVE-2026-51709 (Incorrect access control in the setWiFiBasicCfg function of TOTOLINK T ...)
+	TODO: check
+CVE-2026-51708 (Incorrect access control in the setWiFiWpsCfg function of TOTOLINK T6  ...)
+	TODO: check
+CVE-2026-51706 (Incorrect access control in the setSmartQosCfg function of TOTOLINK T6 ...)
+	TODO: check
+CVE-2026-51705 (Incorrect access control in the setWiFiMeshName function of TOTOLINK T ...)
+	TODO: check
+CVE-2026-51704 (Incorrect access control in the setWiFiMeshConfig function of TOTOLINK ...)
+	TODO: check
+CVE-2026-51703 (Incorrect access control in the setWiFiScheduleCfg function of TOTOLIN ...)
+	TODO: check
+CVE-2026-51702 (Incorrect access control in the setIpPortFilterRules function of TOTOL ...)
+	TODO: check
+CVE-2026-51701 (Incorrect access control in the setMacFilterRules function of TOTOLINK ...)
+	TODO: check
+CVE-2026-51700 (Incorrect access control in the setWiFiAdvancedCfg function of TOTOLIN ...)
+	TODO: check
+CVE-2026-51699 (Incorrect access control in the setDmzCfg function of TOTOLINK T6 4.1. ...)
+	TODO: check
+CVE-2026-51698 (Incorrect access control in the setUrlFilterRules function of TOTOLINK ...)
+	TODO: check
+CVE-2026-51697 (Incorrect access control in the setIptvCfg function of TOTOLINK T6 4.1 ...)
+	TODO: check
+CVE-2026-51696 (Incorrect access control in the setPortForwardRules function of TOTOLI ...)
+	TODO: check
+CVE-2026-51695 (Incorrect access control in the setDdnsCfg function of TOTOLINK T6 4.1 ...)
+	TODO: check
+CVE-2026-51694 (Incorrect access control in the setStaticDhcpRules function of TOTOLIN ...)
+	TODO: check
+CVE-2026-51693 (Incorrect access control in the setVpnPassCfg function of TOTOLINK T6  ...)
+	TODO: check
+CVE-2026-51692 (Incorrect access control in the setWiFiGuestCfg function of TOTOLINK T ...)
+	TODO: check
+CVE-2026-51691 (Incorrect access control in the setUploadSetting function of TOTOLINK  ...)
+	TODO: check
+CVE-2026-51690 (Incorrect access control in the setWanCfg function of TOTOLINK T6 4.1. ...)
+	TODO: check
+CVE-2026-51689 (Incorrect access control in the setUpgradeFW function of TOTOLINK T6 4 ...)
+	TODO: check
+CVE-2026-51688 (Incorrect access control in the setWiFiSignalCfg function of TOTOLINK  ...)
+	TODO: check
+CVE-2026-51687 (Incorrect access control in the setWiFiEasyGuestCf function of TOTOLIN ...)
+	TODO: check
+CVE-2026-51686 (Incorrect access control in the setWiFiEasyCfg function of TOTOLINK T6 ...)
+	TODO: check
+CVE-2026-51684 (Incorrect access control in the setStorageCfg function of TOTOLINK T6  ...)
+	TODO: check
+CVE-2026-51683 (Incorrect access control in the setLanCfg function of TOTOLINK T6 4.1. ...)
+	TODO: check
+CVE-2026-51681 (Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4 ...)
+	TODO: check
+CVE-2026-51680 (Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1. ...)
+	TODO: check
+CVE-2026-51679 (Incorrect access control in the setPasswordCfg function of TOTOLINK T6 ...)
+	TODO: check
+CVE-2026-51678 (Incorrect access control in the setSyslogCfg function of TOTOLINK T6 4 ...)
+	TODO: check
+CVE-2026-51677 (Incorrect access control in the setUPnPCfg function of TOTOLINK T6 4.1 ...)
+	TODO: check
+CVE-2026-51676 (Incorrect access control in the setAccessDeviceCfg function of TOTOLIN ...)
+	TODO: check
+CVE-2026-51675 (Incorrect access control in the setWanIeCfg function of TOTOLINK T6 4. ...)
+	TODO: check
+CVE-2026-51674 (Incorrect access control in the setScheduleCfg function of TOTOLINK T6 ...)
+	TODO: check
+CVE-2026-51673 (Incorrect access control in the setNtpCfg function of TOTOLINK T6 4.1. ...)
+	TODO: check
+CVE-2026-51672 (Incorrect access control in the getRoamingCfg function of TOTOLINK T6  ...)
+	TODO: check
+CVE-2026-51671 (Incorrect access control in the getCloudDownloadStatus function of TOT ...)
+	TODO: check
+CVE-2026-51670 (Incorrect access control in the getSlaveUpdate function of TOTOLINK T6 ...)
+	TODO: check
+CVE-2026-51669 (Incorrect access control in the getPairCfg function of TOTOLINK T6 4.1 ...)
+	TODO: check
+CVE-2026-51668 (Incorrect access control in the setLanguageCfg function of TOTOLINK T6 ...)
+	TODO: check
+CVE-2026-51667 (Incorrect access control in the getWiFiIpMacTable function of TOTOLINK ...)
+	TODO: check
+CVE-2026-51666 (Incorrect access control in the setWizardCfg function of TOTOLINK T6 4 ...)
+	TODO: check
+CVE-2026-51153 (Stored Cross-Site Scripting (XSS) in TaskRunHandler.post() in web/hand ...)
+	TODO: check
+CVE-2026-51152 (Server-side request forgery (SSRF) in the /har/test endpoint in QD 202 ...)
+	TODO: check
+CVE-2026-49003 (Attackers can exploit command injection vulnerabilities to delete core ...)
+	TODO: check
+CVE-2026-21827 (HCL Connections is vulnerable to an information disclosure vulnerabili ...)
+	TODO: check
+CVE-2026-19702 (Improper neutralization of special elements used in an OS command ('OS ...)
+	TODO: check
+CVE-2026-19616 (Missing Authorization vulnerability in TBC Technology Inc. KitLogistic ...)
+	TODO: check
+CVE-2026-19410 (An Incorrect Authorization vulnerability in GitHub Trigger Comment Con ...)
+	TODO: check
+CVE-2026-17615 (A flaw was found in RESTEasy's SourceProvider. This vulnerability allo ...)
+	TODO: check
+CVE-2026-14696 (When Ethernet bridging is enabled (CONFIG_NET_ETHERNET_BRIDGE), eth_br ...)
+	TODO: check
+CVE-2026-14368 (The LwM2M JSON content formatter's get_string() in subsys/net/lib/lwm2 ...)
+	TODO: check
+CVE-2026-14367 (The I3C IBI subsystem in drivers/i3c/i3c_ibi_workq.c hands out statica ...)
+	TODO: check
+CVE-2026-14366 (The Silicon Labs SiWx917 WiFi driver's transmit callback siwx91x_send( ...)
+	TODO: check
+CVE-2026-12894 (A flaw was found in the Qute template engine, which is used by Quarkus ...)
+	TODO: check
+CVE-2024-58379 (nodemailer before 6.9.9 contains a regular expression denial of servic ...)
+	TODO: check
+CVE-2023-31308 (A malicious virtual function can invoke the certain command handlers i ...)
+	TODO: check
 CVE-2026-XXXX [GHSA-fmgr-6ggq-9859: PCRE2: integer overflow in pcre2_compile_32() causes out-of-bounds write on 32-bit systems]
 	- pcre2 <unfixed>
 	NOTE: https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-fmgr-6ggq-9859
@@ -18,7 +432,7 @@ CVE-2026-XXXX [GHSA-2p8c-ff85-vh9x: PCRE2: out-of-bounds read in pcre2_match() a
 	- pcre2 <unfixed>
 	NOTE: https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-2p8c-ff85-vh9x
 	NOTE: Fixed by: https://github.com/PCRE2Project/pcre2/commit/f67db227af31bba7cdf2a7a00b97af91b588c2f5 pcre2-10.48-RC1)
-CVE-2026-19873
+CVE-2026-19873 (HTML::FormFu versions through 2.08 for Perl allow resource exhaustion  ...)
 	- libhtml-formfu-perl <unfixed> (bug #1146310)
 	[trixie] - libhtml-formfu-perl <no-dsa> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/43141785/
@@ -2439,6 +2853,7 @@ CVE-2026-38350 (An integer overflow in the target_sws_fuzzer() function (libswsc
 	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/20060
 	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aca41d3d9327be4d6ab036f494b700118fcc04e1 (n8.0)
 CVE-2026-38349 (An integer overflow in the hScale16To19_c() function (libswscale/outpu ...)
+	{DSA-6276-1 DSA-6268-1}
 	- ffmpeg 7:8.1-1
 	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/issues/21592
 	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22369
@@ -2446,6 +2861,7 @@ CVE-2026-38349 (An integer overflow in the hScale16To19_c() function (libswscale
 	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5f9cdf11fc49e41b7a99e2c3f009ef046a9a02d2 (n7.1.4)
 	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4425208158170180b0a574c8161247404445b45b (n5.1.9)
 CVE-2026-38348 (An integer overflow in the libswscale/utils.c component of FFmpeg N-12 ...)
+	{DSA-6276-1 DSA-6268-1}
 	- ffmpeg 7:8.1-1
 	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/issues/21588
 	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22369
@@ -2453,6 +2869,7 @@ CVE-2026-38348 (An integer overflow in the libswscale/utils.c component of FFmpe
 	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2e1e4706d40f94669b3812d10523f1410e9c0c10 (n7.1.4)
 	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/35b23b73f259515592445d8cdd142d6296994417 (n5.1.9)
 CVE-2026-38347 (A heap overflow in the ff_sws_alphablendaway function (libswscale/alph ...)
+	{DSA-6361-1}
 	- ffmpeg 7:8.0.1-2
 	NOTE: https://trac.ffmpeg.org/ticket/11692
 	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/20063
@@ -2460,6 +2877,7 @@ CVE-2026-38347 (A heap overflow in the ff_sws_alphablendaway function (libswscal
 	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/bb88e295394e5db584063bde790bfbdba04d54ec (n7.1.5)
 	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/7ee2f9004bd292cbe98deea3664dc00223d4275c (n5.1.10)
 CVE-2026-38346 (An integer overflow in the yuv2planeX_8_c() function (libswscale/outpu ...)
+	{DSA-6276-1 DSA-6268-1}
 	- ffmpeg 7:8.1-1
 	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/issues/21584
 	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22365
@@ -2475,6 +2893,7 @@ CVE-2026-38345 (A Division-by-Zero vulnerability in the ff_sws_init_single_conte
 	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/21768
 	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/04fe98482a264117fa49a166c18227f3f93f921b (n8.1)
 CVE-2026-38344 (A NULL pointer dereference in the get_min_buffer_size function (/libsw ...)
+	{DSA-6276-1 DSA-6268-1}
 	- ffmpeg 7:8.1-1
 	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/issues/21583
 	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22365
@@ -2482,6 +2901,7 @@ CVE-2026-38344 (A NULL pointer dereference in the get_min_buffer_size function (
 	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/af29ae54a4c9b2d3b3ccb4963f86698c69f28091 (n7.1.4)
 	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/ea3290bf6e92b0fd905121ee6fbebf1199f8fd24 (n5.1.9)
 CVE-2026-38343 (An integer overflow in the libavfilter/vf_scale.c component of FFmpeg  ...)
+	{DSA-6276-1 DSA-6268-1}
 	- ffmpeg 7:8.1-1
 	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/issues/21587
 	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22369
@@ -5538,7 +5958,7 @@ CVE-2026-66422 (Improper Authorization vulnerability in Apache Tomcat cause by s
 	NOTE: https://github.com/apache/tomcat/commit/bd05d5ced387da0c967bb232f7e3cd57685d2a7b (9.0.121)
 CVE-2026-66153 (The NEService auto-upgrade process insecurely handles temporary files  ...)
 	NOT-FOR-US: SonicWall
-CVE-2026-66152 (A Path traversal vulnerability in OPSWAT tarball in the SonicWall NetE ...)
+CVE-2026-66152 (A Path traversal vulnerability in the SonicWall NetExtender Linux clie ...)
 	NOT-FOR-US: SonicWall
 CVE-2026-65927 (Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag ...)
 	- tomcat11 <unfixed> (bug #1145698)
@@ -6508,7 +6928,7 @@ CVE-2026-63075 (Issue summary: When OpenSSL processes QUIC traffic from a peer t
 	NOTE: https://github.com/openssl/openssl/commit/7c98d79738549df92868e7dd9be4bbf061eed709 (openssl-3.5.8)
 	NOTE: https://github.com/openssl/openssl/commit/c902e5f16d6a9e130e96d3ca6d8f64d71652e393 (openssl-3.4.7)
 	NOTE: https://openssl-library.org/news/secadv/20260825.txt
-CVE-2026-19953
+CVE-2026-19953 (URI versions before 5.36 for Perl encode non-NFC host names to non-sta ...)
 	- liburi-perl 5.36-1
 	[trixie] - liburi-perl <no-dsa> (Minor issue)
 	NOTE: Fixed by: https://github.com/libwww-perl/URI/commit/8c213ff92fdae45d0fabb7bc16f6a6f27e911395 (v5.36)
@@ -16207,12 +16627,12 @@ CVE-2026-15142 (The Real Estate Manager Pro plugin for WordPress is vulnerable t
 CVE-2026-12248 (The WPML Multilingual CMS plugin for WordPress is vulnerable to SQL In ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-73194 (DBI versions before 1.652 for Perl allow a heap out-of-bounds write vi ...)
-	{DSA-6473-1}
+	{DSA-6473-1 DLA-4764-1}
 	- libdbi-perl 1.652-1 (bug #1144471)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/42707363/
 	NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/29b72ae7d2a8114a734a55840bf1c45b89207809 (1.652)
 CVE-2026-73193 (DBI versions before 1.652 for Perl allow a heap out-of-bounds write on ...)
-	{DSA-6473-1}
+	{DSA-6473-1 DLA-4764-1}
 	- libdbi-perl 1.652-1 (bug #1144470)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/42707360/
 	NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/c751ae5a5a6f56c2f8284f37c1f4d43500352ef1 (1.652)
@@ -21724,7 +22144,7 @@ CVE-2026-16815 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to ca
 	NOT-FOR-US: IBM
 CVE-2026-16810 (The Bit Form \u2013 Contact Form, Payment Forms, Multi Step Forms, Cal ...)
 	NOT-FOR-US: WordPress plugin
-CVE-2026-16739 (The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 do ...)
+CVE-2026-16739 (The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.4 do ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-16722 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
 	NOT-FOR-US: IBM
@@ -33889,7 +34309,7 @@ CVE-2026-13506 (In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forci
 	NOTE: Fixed by: https://github.com/bcgit/bc-java/commit/77454da9b3dcaaa2991412d1c3c1a6e1a338ff84 (r1rv85)
 CVE-2026-13340 (The SVG Support WordPress plugin before 2.5.17 does not apply its SVG  ...)
 	NOT-FOR-US: WordPress plugin
-CVE-2026-12965 (The Super Store Finder WordPress plugin through 7.8 does not sanitize  ...)
+CVE-2026-12965 (The Super Store Finder WordPress plugin before 7.11 does not sanitize  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-12872 (The Webinfos WordPress plugin through 1.2 does not validate the type o ...)
 	NOT-FOR-US: WordPress plugin
@@ -38598,12 +39018,12 @@ CVE-2024-14041 (In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM
 	NOTE: Fixed by: https://github.com/bcgit/bc-java/commit/5adb2c5c5b462a332b01a012bea0784b40b904e5 (r1rv78v1)
 	NOTE: Fixed by: https://github.com/bcgit/bc-java/commit/1590247178f2280defa36421475f015175dfbe9e (r1rv78v1)
 CVE-2026-59986
-	{DSA-6447-1}
+	{DSA-6447-1 DLA-4763-1}
 	- librabbitmq 0.17.0-1
 	NOTE: https://github.com/alanxz/rabbitmq-c/security/advisories/GHSA-jgjf-7fwf-f3c7
 	NOTE: Fixed by: https://github.com/alanxz/rabbitmq-c/commit/1bb1b9b1b7bc69eede6295e95fa9527c731f0798 (v0.17.0)
 CVE-2026-61547
-	{DSA-6447-1}
+	{DSA-6447-1 DLA-4763-1}
 	- librabbitmq 0.17.0-1
 	NOTE: https://github.com/alanxz/rabbitmq-c/security/advisories/GHSA-hfjv-vcp3-39wh
 	NOTE: Fixed by: https://github.com/alanxz/rabbitmq-c/commit/02d278663f3a93db9fe4fb4e7e34dc96b83c107b (v0.17.0)
@@ -46097,6 +46517,7 @@ CVE-2026-21954 (Vulnerability in the Oracle Retail Xstore Point of Service produ
 CVE-2026-21953 (Vulnerability in the Oracle Retail Xstore Point of Service product of  ...)
 	NOT-FOR-US: Oracle
 CVE-2026-16517 (A signed integer overflow vulnerability was found in libarchive's ZIP  ...)
+	{DLA-4762-1}
 	- libarchive 3.8.9-1 (bug #1142834)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2505492
 	NOTE: https://github.com/libarchive/libarchive/issues/3225
@@ -54567,19 +54988,19 @@ CVE-2026-15747 (Mojolicious versions from 4.59 before 9.48 for Perl expose a sta
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41816171/
 	NOTE: Fixed by: https://github.com/mojolicious/mojo/commit/01921fbbbbeca2d1397e082d4a647f9b84c24e27 (v9.48)
 CVE-2026-15392 (DBD::File versions before 1.651 for Perl do not ensure the table file  ...)
-	{DSA-6473-1}
+	{DSA-6473-1 DLA-4764-1}
 	- libdbi-perl 1.651-1 (bug #1142072)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41813967/
 	NOTE: https://github.com/perl5-dbi/dbi/security/advisories/GHSA-mh3j-xwf4-jrqw
 	NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/96d62dfe4528bf56fe13f413ed323d4252531728 (1.651)
 CVE-2026-60082 (DBI versions before 1.651 for Perl do not enforce statement handle con ...)
-	{DSA-6473-1}
+	{DSA-6473-1 DLA-4764-1}
 	- libdbi-perl 1.651-1 (bug #1142072)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41813803/
 	NOTE: https://github.com/perl5-dbi/dbi/security/advisories/GHSA-rwhc-hhmv-cjvg
 	NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/397868704291bbf0989b97e2c0661189890653e2 (1.651)
 CVE-2026-60081 (DBI::ProfileData versions before 1.651 for Perl do not limit the path  ...)
-	{DSA-6473-1}
+	{DSA-6473-1 DLA-4764-1}
 	- libdbi-perl 1.651-1 (bug #1142072)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41813962/
 	NOTE: https://github.com/perl5-dbi/dbi/security/advisories/GHSA-ww49-w4mv-jrr4
@@ -56354,6 +56775,7 @@ CVE-2026-15143 (A flaw was found in the file_type content detector of guardrails
 CVE-2026-15104 (The BetterDocs \u2013 AI Documentation, Knowledge Base, Docs, Wikis, F ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-15028 (A flaw was found in libarchive. This vulnerability allows a remote att ...)
+	{DLA-4762-1}
 	- libarchive 3.8.9-1 (bug #1142833)
 	[trixie] - libarchive <no-dsa> (Minor issue)
 	NOTE: https://github.com/libarchive/libarchive/issues/3251
@@ -58058,7 +58480,7 @@ CVE-2026-15053 (Tanium addressed a denial of service vulnerability in Tanium Ser
 CVE-2026-15044 (A flaw was found in the TrustyAI Service Operator. When deploying serv ...)
 	NOT-FOR-US: TrustyAI Service Operator
 CVE-2026-15043 (DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted  ...)
-	{DSA-6473-1}
+	{DSA-6473-1 DLA-4764-1}
 	- libdbi-perl 1.651-1 (bug #1142072)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41805128/
 	NOTE: https://github.com/perl5-dbi/dbi/security/advisories/GHSA-mv45-ff6j-x9jp
@@ -58597,18 +59019,18 @@ CVE-2026-14895 (String::Util versions before 1.36 for Perl are susceptible to a
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41625636/
 	NOTE: Fixed by: https://github.com/scottchiefbaker/String-Util/commit/f8150867aaeb8f57c59601aefb2193f2caed8745 (v1.36)
 CVE-2026-14380 (DBI versions before 1.650 for Perl are vulnerable to code injection vi ...)
-	{DSA-6473-1}
+	{DSA-6473-1 DLA-4764-1}
 	- libdbi-perl 1.650-1 (bug #1141667)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41625527/
 	NOTE: https://github.com/perl5-dbi/dbi/security/advisories/GHSA-ch8w-hxc2-v557
 	NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/b73d5d9901767fc1d16b6661ef08fbed4532e259 (1.650)
 CVE-2026-14739 (DBI versions before 1.650 for Perl have a heap overflow when preparsin ...)
-	{DSA-6473-1}
+	{DSA-6473-1 DLA-4764-1}
 	- libdbi-perl 1.650-1 (bug #1141667)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41625530/
 	NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/2b77c88b655e9539a592c71a61fb965fc0075395 (1.650)
 CVE-2026-14740 (DBI versions before 1.650 for Perl read one byte out-of-bounds in prep ...)
-	{DSA-6473-1}
+	{DSA-6473-1 DLA-4764-1}
 	- libdbi-perl 1.650-1 (bug #1141667)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41625532/
 	NOTE: https://github.com/perl5-dbi/dbi/security/advisories/GHSA-35f4-f8m9-w8xg
@@ -59389,7 +59811,7 @@ CVE-2026-14801 (A security vulnerability has been detected in GPAC 26.03-DEV-rev
 	[bullseye] - gpac <end-of-life> (EOL in bullseye LTS)
 CVE-2026-14800 (A weakness has been identified in imhamzaazam ecommerceFlask up to cb7 ...)
 	NOT-FOR-US: ecommerceFlask
-CVE-2026-13753 (A missing authorization vulnerability exists in the embedded webserver ...)
+CVE-2026-13753 (Certain HP DeskJet All-in-One printers may be potentially vulnerable t ...)
 	NOT-FOR-US: HP
 CVE-2026-12686 (An authenticated user could manipulate a company ID parameter in a POS ...)
 	NOT-FOR-US: Adiss Biloop
@@ -64697,6 +65119,7 @@ CVE-2026-31016 (Cross Site Request Forgery vulnerability in Squidex.io Squidex C
 CVE-2026-28979 (An out-of-bounds access issue was addressed with improved bounds check ...)
 	NOT-FOR-US: Apple
 CVE-2026-14164 (A double free issue has been identified in libarchive's RAR5 reader. D ...)
+	{DLA-4762-1}
 	- libarchive 3.8.8-1 (bug #1141180)
 	[trixie] - libarchive <no-dsa> (Minor issue)
 	NOTE: https://github.com/libarchive/libarchive/issues/3069
@@ -237230,7 +237653,7 @@ CVE-2025-32712 (Use after free in Windows Win32K - GRFX allows an authorized att
 	NOT-FOR-US: Microsoft
 CVE-2025-32710 (Use after free in Windows Remote Desktop Services allows an unauthoriz ...)
 	NOT-FOR-US: Microsoft
-CVE-2025-31104 (An Improper Neutralization of Special Elements used in an OS Command ( ...)
+CVE-2025-31104 (A improper neutralization of special elements used in an os command (' ...)
 	NOT-FOR-US: Fortinet
 CVE-2025-30327 (InCopy versions 20.2, 19.5.3 and earlier are affected by an Integer Ov ...)
 	NOT-FOR-US: Adobe
@@ -264226,7 +264649,8 @@ CVE-2024-7957 (An arbitrary file overwrite vulnerability exists in the ZulipConn
 	NOT-FOR-US: danswer-ai/danswer
 CVE-2024-7819 (A CORS misconfiguration in danswer-ai/danswer v1.4.1 allows attackers  ...)
 	NOT-FOR-US: danswer-ai/danswer
-CVE-2024-7806 (A vulnerability in open-webui/open-webui versions <= 0.3.8 allows remo ...)
+CVE-2024-7806
+	REJECTED
 	NOT-FOR-US: open-webui/open-webui
 CVE-2024-7804
 	REJECTED
@@ -471305,8 +471729,8 @@ CVE-2023-20513 (An insufficient bounds check in PMFW (Power Management Firmware)
 	NOT-FOR-US: AMD
 CVE-2023-20512 (A hardcoded AES   key in PMFW may result in a privileged attacker gain ...)
 	NOT-FOR-US: AMD
-CVE-2023-20511
-	RESERVED
+CVE-2023-20511 (Release of an invalid pointer in the AMD kernel mode driver (KMD) coul ...)
+	TODO: check
 CVE-2023-20510 (An insufficient DRAM address validation in PMFW may allow a privileged ...)
 	NOT-FOR-US: AMD
 CVE-2023-20509 (An insufficient DRAM address validation in PMFW may allow a privileged ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0a87d52ac0aadcec424107f99af04230a8cac110

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0a87d52ac0aadcec424107f99af04230a8cac110
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260831/97d172f4/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list