[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Jul 9 06:41:11 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
bd3193bd by Salvatore Bonaccorso at 2026-07-09T07:40:53+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -235,33 +235,33 @@ CVE-2026-59868 (js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 befor
 	NOTE: https://github.com/nodeca/js-yaml/security/advisories/GHSA-g796-fgmg-93mv
 	NOTE: Fixed by: https://github.com/nodeca/js-yaml/commit/3105455b81dee69e0fd36e09ac0b2ccfdb54adc1 (5.2.0)
 CVE-2026-59731 (Astro is a web framework for content-driven websites. Version 6.4.7 pe ...)
-	TODO: check
+	NOT-FOR-US: Astro
 CVE-2026-59725 (Socket.IO enables bidirectional and low-latency communication for ever ...)
 	TODO: check
 CVE-2026-59724 (Socket.IO enables bidirectional and low-latency communication for ever ...)
 	TODO: check
 CVE-2026-59703 (repomix contains a local file inclusion vulnerability in the git clone ...)
-	TODO: check
+	NOT-FOR-US: repomix
 CVE-2026-59702 (repomix contains a server-side request forgery vulnerability in the PO ...)
-	TODO: check
+	NOT-FOR-US: repomix
 CVE-2026-59262 (AFFiNE's histories GraphQL field fails to validate Doc.Read permission ...)
 	TODO: check
 CVE-2026-59261 (OpenClaw before 2026.5.28 contains a credential exposure vulnerability ...)
 	NOT-FOR-US: OpenClaw
 CVE-2026-59257 (n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 conta ...)
-	TODO: check
+	NOT-FOR-US: n8n
 CVE-2026-59253 (n8n before 2.28.0 contains an improper authorization vulnerability all ...)
-	TODO: check
+	NOT-FOR-US: n8n
 CVE-2026-58657 (Grav before 2.0.0 (affected through 2.0.0-rc.9 and the 2.0 branch) con ...)
-	TODO: check
+	NOT-FOR-US: Grav CMS
 CVE-2026-58656 (Grav API plugin before v1.0.0-rc.16 accepts JWT tokens via the ?token= ...)
-	TODO: check
+	NOT-FOR-US: Grav CMS
 CVE-2026-58654 (The Grav API plugin (getgrav/grav-plugin-api) 1.0.0 contains an unrest ...)
-	TODO: check
+	NOT-FOR-US: Grav CMS
 CVE-2026-58480 (Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an u ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-57439 (CyberChef is a web app for encryption, encoding, compression, and data ...)
-	TODO: check
+	NOT-FOR-US: CyberChef
 CVE-2026-57260 (The application opened a PDF file containing an abnormal Unity 3D obje ...)
 	NOT-FOR-US: Foxit
 CVE-2026-57259 (The input file does not need to be strictly in a structurally valid PD ...)
@@ -311,13 +311,13 @@ CVE-2026-57238 (After the application opened the PDF, JavaScript deleted the for
 CVE-2026-57237 (When the application opens a PDF and JavaScript modifies the propertie ...)
 	NOT-FOR-US: Foxit
 CVE-2026-56778 (n8n before 2.25.7 and 2.26.x before 2.26.2 contains an authorization b ...)
-	TODO: check
+	NOT-FOR-US: n8n
 CVE-2026-56776 (n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization bypa ...)
-	TODO: check
+	NOT-FOR-US: n8n
 CVE-2026-56775 (n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization vuln ...)
-	TODO: check
+	NOT-FOR-US: n8n
 CVE-2026-56401 (Wazuh wazuh-modulesd before 5.0.0-beta3 contains a null pointer derefe ...)
-	TODO: check
+	NOT-FOR-US: Wazuh
 CVE-2026-56374 (ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerabil ...)
 	TODO: check
 CVE-2026-56362 (ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulne ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bd3193bd253ad8b9ae80728a9ac4145841ba693c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bd3193bd253ad8b9ae80728a9ac4145841ba693c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260709/2961124b/attachment.htm>


More information about the debian-security-tracker-commits mailing list