[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 31 20:15:21 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
30ee9421 by security tracker role at 2026-08-31T19:14:55+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,17 +1,17 @@
 CVE-2026-83497 (Unrestricted deserialization of untrusted data in the cursor paginatio ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-83492 (Improper input validation vulnerability in Extend Themes Kubio AI Webs ...)
 	TODO: check
 CVE-2026-82970 (Unrestricted Upload of File with Dangerous Type vulnerability in WP Le ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-82881 (Aix-DB through 1.2.4 renders markdown with raw HTML enabled into v-htm ...)
 	TODO: check
 CVE-2026-82880 (YaCy Search Server through 1.941 contains an XML external entity injec ...)
 	TODO: check
 CVE-2026-82879 (DataEase before 2.10.26 contains multiple access control defects in th ...)
-	TODO: check
+	NOT-FOR-US: DataEase
 CVE-2026-82878 (DataEase versions before 2.10.26 omit object-level authorization check ...)
-	TODO: check
+	NOT-FOR-US: DataEase
 CVE-2026-82877 (ILIAS versions before 9.22, 10.0 through 10.9, and 11.0 through 11.2 c ...)
 	TODO: check
 CVE-2026-82876 (Phison PS3111-S11 controller firmware verifies RSA signatures using a  ...)
@@ -63,7 +63,7 @@ CVE-2026-82854 (Nodemailer before 8.0.4 is vulnerable to SMTP command injection
 CVE-2026-82853 (Nodemailer versions before 8.0.5 contain an SMTP command injection vul ...)
 	TODO: check
 CVE-2026-82838 (The default docker image shipped for Venueless did not properly ensure ...)
-	TODO: check
+	NOT-FOR-US: rami.io products
 CVE-2026-82823
 	REJECTED
 CVE-2026-82821 (A vulnerability was determined in FLVMeta up to 1.2.2. Affected by thi ...)
@@ -101,13 +101,13 @@ CVE-2026-82801 (A vulnerability was detected in NASA earthdata-search 1.0.0. Aff
 CVE-2026-82797 (Uncontrolled Recursion vulnerability in Samsung Open Source rlottie al ...)
 	TODO: check
 CVE-2026-82703 (A security flaw has been discovered in Edimax BR-6214K 1.40. This vuln ...)
-	TODO: check
+	NOT-FOR-US: Edimax
 CVE-2026-82702 (A vulnerability was identified in Edimax BR-6214K 1.40. This affects t ...)
-	TODO: check
+	NOT-FOR-US: Edimax
 CVE-2026-82701 (A vulnerability was determined in code-projects Online Shopping System ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2026-82700 (A vulnerability was found in code-projects Online Shopping System 1.0. ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2026-82699 (A flaw has been found in sambitraj Student Management System up to 56b ...)
 	TODO: check
 CVE-2026-82698 (A vulnerability was detected in sambitraj Student-Management-System up ...)
@@ -115,25 +115,25 @@ CVE-2026-82698 (A vulnerability was detected in sambitraj Student-Management-Sys
 CVE-2026-82697 (A security vulnerability has been detected in sambitraj Student-Manage ...)
 	TODO: check
 CVE-2026-82696 (A weakness has been identified in itsourcecode Sales and Inventory Sys ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-82695 (A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacte ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-82694 (A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-82693 (A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulne ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-82692 (A vulnerability was found in D-Link DNS-340L and DNS-345 up to 2026071 ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2026-82691 (A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L  ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2026-82690 (A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717.  ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2026-82689 (A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L an ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2026-82688 (A security vulnerability has been detected in D-Link DNS-340L and DNS- ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2026-82680 (A weakness has been identified in D-Link DSM-G600 1.01. This affects a ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2026-82679 (A security flaw has been discovered in diem-project diem up to 5.1.3.  ...)
 	TODO: check
 CVE-2026-82678 (A vulnerability was identified in diem-project diem up to 5.1.3. The a ...)
@@ -171,7 +171,7 @@ CVE-2026-82630 (A vulnerability was identified in PowerJob up to 5.1.2. Impacted
 CVE-2026-82629 (A vulnerability was determined in jeecgboot jeewx-boot up to 641ab52c3 ...)
 	TODO: check
 CVE-2026-82217 (In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the A ...)
-	TODO: check
+	NOT-FOR-US: Eclipse
 CVE-2026-81624 (Undertow is a flexible performant web server used in JBoss EAP and Wil ...)
 	TODO: check
 CVE-2026-79750 (MCPHub is a unified hub for centrally managing and dynamically orchest ...)
@@ -193,53 +193,53 @@ CVE-2026-79743 (MCPHub is a unified hub for centrally managing and dynamically o
 CVE-2026-78422 (Subject::new_for_owner() in the zbus_polkit crate encodes the uid entr ...)
 	TODO: check
 CVE-2026-78079 (Joomla Extension - joomshaper.com - Open Redirect via Base64 Return Pa ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-78078 (Joomla Extension - joomshaper.com - Privileged File Upload Bypass via  ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-78077 (Joomla Extension - joomshaper.com -  Stored Cross-Site Scripting (XSS) ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-78076 (Joomla Extension - joomshaper.com - Broken Access Control & Missing Au ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-78075 (Joomla Extension - joomshaper.com - Broken Object-Level Authorization  ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-78074 (Joomla Extension - miniorgange.com - Unauthenticated arbitrary extensi ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-77975 (The affected Ebyte   product exports administrative credentials and ot ...)
 	TODO: check
 CVE-2026-77966 (The affectedEbyte   productdoes not provide separation between limited ...)
 	TODO: check
 CVE-2026-76986 (Improper neutralization of input during web page generation in Apache  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-76985 (Improper neutralization of input during web page generation in Apache  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-76984 (Improper neutralization of input during web page generation in Apache  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-76983 (Improper neutralization of input during web page generation in Apache  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-76982 (Improper neutralization of input during web page generation in Apache  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-76763 (A flaw was found in SmallRye GraphQL. The number scalar coercion for B ...)
 	TODO: check
 CVE-2026-76133 (The affectedEbyte   product  uses a deprecated hashing algorithm in an ...)
 	TODO: check
 CVE-2026-75802 (AjaxEditableChoiceLabel in wicket-extensions, when constructed with a  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-75133 (Keep Backup Daily plugin for WordPress before 2.1.4 contains a sensiti ...)
 	TODO: check
 CVE-2026-75132 (WAPT Server versions 2.6.1.17834 and earlier contains a SQL injection  ...)
 	TODO: check
 CVE-2026-74010 (Missing Authorization vulnerability in John James Jacoby bbPress allow ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73819 (The affectedEbyte   product's vendor configuration utility permits acc ...)
 	TODO: check
 CVE-2026-72001 (Pangolin before 1.22.0 contains an authentication bypass vulnerability ...)
 	TODO: check
 CVE-2026-71378 (ResourceIsolationRequestCycleListener protects a Wicket application ag ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-71257 (Apache Wicket enforces the upload limits configured on a form or uploa ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-70449 (Improper validation of resource URL attributes in Apache Wicket allows ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-66047 (ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains  ...)
 	TODO: check
 CVE-2026-63083
@@ -259,137 +259,137 @@ CVE-2026-53508 (oasdiff is a command-line and Go package that compares and detec
 CVE-2026-53507 (oasdiff-action is a GitHub Action that detects breaking changes in Ope ...)
 	TODO: check
 CVE-2026-51730 (Incorrect access control in the delWiFiAclRules function of TOTOLINK T ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51729 (Incorrect access control in the delDevice function of TOTOLINK T6 4.1. ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51728 (Incorrect access control in the UploadFirmwareFile function of TOTOLIN ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51727 (Incorrect access control in the SystemSettings function of TOTOLINK T6 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51726 (Incorrect access control in the delParentalRules function of TOTOLINK  ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51725 (Incorrect access control in the NTPSyncWithHost function of TOTOLINK T ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51724 (Incorrect access control in the delSmartQosCfg function of TOTOLINK T6 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51723 (Incorrect access control in the UploadCustomModule function of TOTOLIN ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51722 (Incorrect access control in the setWiFiRepeaterCfg function of TOTOLIN ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51721 (Incorrect access control in the setPairCfg function of TOTOLINK T6 4.1 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51720 (Incorrect access control in the delIpPortFilterRules function of TOTOL ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51719 (Incorrect access control in the delUrlFilterRules function of TOTOLINK ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51718 (Incorrect access control in the delStaticDhcpRules function of TOTOLIN ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51717 (Incorrect access control in the setOpModeCfg function of TOTOLINK T6 4 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51716 (Incorrect access control in the delPortForwardRules function of TOTOLI ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51715 (Incorrect access control in the delMacFilterRules function of TOTOLINK ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51714 (Incorrect access control in the setRoamingCfg function of TOTOLINK T6  ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51713 (Incorrect access control in the setManualDialCfg function of TOTOLINK  ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51712 (Incorrect access control in the setApWiFiSchCfg function of TOTOLINK T ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51711 (Incorrect access control in the setWiFiWpsStart function of TOTOLINK T ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51710 (Incorrect access control in the setParentalRules function of TOTOLINK  ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51709 (Incorrect access control in the setWiFiBasicCfg function of TOTOLINK T ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51708 (Incorrect access control in the setWiFiWpsCfg function of TOTOLINK T6  ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51706 (Incorrect access control in the setSmartQosCfg function of TOTOLINK T6 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51705 (Incorrect access control in the setWiFiMeshName function of TOTOLINK T ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51704 (Incorrect access control in the setWiFiMeshConfig function of TOTOLINK ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51703 (Incorrect access control in the setWiFiScheduleCfg function of TOTOLIN ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51702 (Incorrect access control in the setIpPortFilterRules function of TOTOL ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51701 (Incorrect access control in the setMacFilterRules function of TOTOLINK ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51700 (Incorrect access control in the setWiFiAdvancedCfg function of TOTOLIN ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51699 (Incorrect access control in the setDmzCfg function of TOTOLINK T6 4.1. ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51698 (Incorrect access control in the setUrlFilterRules function of TOTOLINK ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51697 (Incorrect access control in the setIptvCfg function of TOTOLINK T6 4.1 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51696 (Incorrect access control in the setPortForwardRules function of TOTOLI ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51695 (Incorrect access control in the setDdnsCfg function of TOTOLINK T6 4.1 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51694 (Incorrect access control in the setStaticDhcpRules function of TOTOLIN ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51693 (Incorrect access control in the setVpnPassCfg function of TOTOLINK T6  ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51692 (Incorrect access control in the setWiFiGuestCfg function of TOTOLINK T ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51691 (Incorrect access control in the setUploadSetting function of TOTOLINK  ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51690 (Incorrect access control in the setWanCfg function of TOTOLINK T6 4.1. ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51689 (Incorrect access control in the setUpgradeFW function of TOTOLINK T6 4 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51688 (Incorrect access control in the setWiFiSignalCfg function of TOTOLINK  ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51687 (Incorrect access control in the setWiFiEasyGuestCf function of TOTOLIN ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51686 (Incorrect access control in the setWiFiEasyCfg function of TOTOLINK T6 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51684 (Incorrect access control in the setStorageCfg function of TOTOLINK T6  ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51683 (Incorrect access control in the setLanCfg function of TOTOLINK T6 4.1. ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51681 (Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51680 (Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1. ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51679 (Incorrect access control in the setPasswordCfg function of TOTOLINK T6 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51678 (Incorrect access control in the setSyslogCfg function of TOTOLINK T6 4 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51677 (Incorrect access control in the setUPnPCfg function of TOTOLINK T6 4.1 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51676 (Incorrect access control in the setAccessDeviceCfg function of TOTOLIN ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51675 (Incorrect access control in the setWanIeCfg function of TOTOLINK T6 4. ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51674 (Incorrect access control in the setScheduleCfg function of TOTOLINK T6 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51673 (Incorrect access control in the setNtpCfg function of TOTOLINK T6 4.1. ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51672 (Incorrect access control in the getRoamingCfg function of TOTOLINK T6  ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51671 (Incorrect access control in the getCloudDownloadStatus function of TOT ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51670 (Incorrect access control in the getSlaveUpdate function of TOTOLINK T6 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51669 (Incorrect access control in the getPairCfg function of TOTOLINK T6 4.1 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51668 (Incorrect access control in the setLanguageCfg function of TOTOLINK T6 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51667 (Incorrect access control in the getWiFiIpMacTable function of TOTOLINK ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51666 (Incorrect access control in the setWizardCfg function of TOTOLINK T6 4 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51153 (Stored Cross-Site Scripting (XSS) in TaskRunHandler.post() in web/hand ...)
 	TODO: check
 CVE-2026-51152 (Server-side request forgery (SSRF) in the /har/test endpoint in QD 202 ...)
 	TODO: check
 CVE-2026-49003 (Attackers can exploit command injection vulnerabilities to delete core ...)
-	TODO: check
+	NOT-FOR-US: ZTE
 CVE-2026-21827 (HCL Connections is vulnerable to an information disclosure vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: HCL
 CVE-2026-19702 (Improper neutralization of special elements used in an OS command ('OS ...)
 	TODO: check
 CVE-2026-19616 (Missing Authorization vulnerability in TBC Technology Inc. KitLogistic ...)
@@ -399,13 +399,13 @@ CVE-2026-19410 (An Incorrect Authorization vulnerability in GitHub Trigger Comme
 CVE-2026-17615 (A flaw was found in RESTEasy's SourceProvider. This vulnerability allo ...)
 	TODO: check
 CVE-2026-14696 (When Ethernet bridging is enabled (CONFIG_NET_ETHERNET_BRIDGE), eth_br ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-14368 (The LwM2M JSON content formatter's get_string() in subsys/net/lib/lwm2 ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-14367 (The I3C IBI subsystem in drivers/i3c/i3c_ibi_workq.c hands out statica ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-14366 (The Silicon Labs SiWx917 WiFi driver's transmit callback siwx91x_send( ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-12894 (A flaw was found in the Qute template engine, which is used by Quarkus ...)
 	TODO: check
 CVE-2024-58379 (nodemailer before 6.9.9 contains a regular expression denial of servic ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/30ee9421a770c1c3c944ac3644de2b8f117e0b85

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/30ee9421a770c1c3c944ac3644de2b8f117e0b85
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260831/4fb86573/attachment.htm>


More information about the debian-security-tracker-commits mailing list