[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Jul 2 07:05:17 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e34edd08 by Salvatore Bonaccorso at 2026-07-02T08:03:18+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -80,11 +80,11 @@ CVE-2026-57720 (Missing Authorization vulnerability in Codexpert Inc ThumbPress
 CVE-2026-57692 (Incorrect Privilege Assignment vulnerability in LCweb PrivateContent a ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57517 (Control Web Panel before 0.9.8.1225 contains a blind SQL injection vul ...)
-	TODO: check
+	NOT-FOR-US: Control Web Panel
 CVE-2026-57516 (Ray prior to 2.56.0 contains an unsafe deserialization vulnerability i ...)
-	TODO: check
+	NOT-FOR-US: Ray
 CVE-2026-56152 (Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauth ...)
-	TODO: check
+	NOT-FOR-US: Elastic Defend
 CVE-2026-56151 (Improper Input Validation (CWE-20) in Kibana can lead to a denial of s ...)
 	TODO: check
 CVE-2026-56150 (Allocation of Resources Without Limits or Throttling (CWE-770) in Flee ...)
@@ -637,7 +637,7 @@ CVE-2026-56278 (Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses
 CVE-2026-56277 (Flowise before 3.1.2 sets Access-Control-Allow-Origin to a hardcoded w ...)
 	NOT-FOR-US: Flowise
 CVE-2026-56264 (Crawl4AI before 0.8.7 contains an arbitrary JavaScript execution vulne ...)
-	TODO: check
+	NOT-FOR-US: Crawl4AI
 CVE-2026-56249 (Capgo before 12.128.2 contains an authorization bypass vulnerability i ...)
 	NOT-FOR-US: Cap-go
 CVE-2026-56247 (Capgo before 12.128.2 allows org admins to assign org-scoped RBAC role ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e34edd081905a836faf15dc22dcd60d8b472e5be

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e34edd081905a836faf15dc22dcd60d8b472e5be
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260702/13e15227/attachment.htm>


More information about the debian-security-tracker-commits mailing list