[Git][security-tracker-team/security-tracker][master] 4 commits: Simplify overlong note, the advisory contains enough information

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Jul 12 07:56:30 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9946565b by Salvatore Bonaccorso at 2026-07-12T08:40:24+02:00
Simplify overlong note, the advisory contains enough information

- - - - -
2e894241 by Salvatore Bonaccorso at 2026-07-12T08:54:11+02:00
Process some NFUs

- - - - -
b44f15ef by Salvatore Bonaccorso at 2026-07-12T08:54:37+02:00
Add CVE-2026-55213/h2o

- - - - -
951fca40 by Salvatore Bonaccorso at 2026-07-12T08:54:54+02:00
Add CVE-2026-54329/snipe-it

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -98,7 +98,7 @@ CVE-2026-6801 (The Context Blog theme for WordPress is vulnerable to Sensitive I
 CVE-2026-5743 (The SimpLy Gallery Block & Lightbox plugin for WordPress is vulnerable ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-59155 (Nezha Monitoring is a self-hostable, lightweight, servers and websites ...)
-	TODO: check
+	NOT-FOR-US: Nezha Monitoring
 CVE-2026-58591 (Improper Neutralization of Input During Web Page Generation ("Cross-si ...)
 	NOT-FOR-US: Drupal core and addons
 CVE-2026-58590 (Missing Authorization vulnerability in Drupal FlowDrop allows Forceful ...)
@@ -110,21 +110,21 @@ CVE-2026-58588 (Improper Neutralization of Input During Web Page Generation ("Cr
 CVE-2026-58587 (Improper Neutralization of Input During Web Page Generation ("Cross-si ...)
 	NOT-FOR-US: Drupal core and addons
 CVE-2026-58503 (Frappe is a full-stack web application framework. Prior to 16.16.0 and ...)
-	TODO: check
+	NOT-FOR-US: Frappe
 CVE-2026-58499 (EverOS is a memory runtime for agents. Prior to 1.0.1, EverOS is vulne ...)
-	TODO: check
+	NOT-FOR-US: EverOS
 CVE-2026-57850 (RustDesk before 1.4.9 does not enforce a session's authorized connecti ...)
-	TODO: check
+	NOT-FOR-US: RustDesk
 CVE-2026-57807 (Authentication Bypass Using an Alternate Path or Channel vulnerability ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57584 (Phalcon is a high-performance, full-stack PHP framework. Prior to 5.15 ...)
-	TODO: check
+	NOT-FOR-US: RustDesk
 CVE-2026-57575 (Misskey is an open source, federated social media platform. Prior to 2 ...)
-	TODO: check
+	NOT-FOR-US: Misskey
 CVE-2026-57574 (Misskey is an open source, federated social media platform. Prior to 2 ...)
-	TODO: check
+	NOT-FOR-US: Misskey
 CVE-2026-57230 (OpenReplay is a self-hosted session replay suite. Prior to 1.27.0, the ...)
-	TODO: check
+	NOT-FOR-US: OpenReplay
 CVE-2026-57221 (RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20 ...)
 	TODO: check
 CVE-2026-57220 (RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the Rabb ...)
@@ -148,19 +148,19 @@ CVE-2026-57212 (RabbitMQ is a messaging and streaming broker. Prior to 3.13.14,
 CVE-2026-57211 (RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2. ...)
 	TODO: check
 CVE-2026-55884 (Tilt defines dev environments as code for microservice apps on Kuberne ...)
-	TODO: check
+	NOT-FOR-US: Tilt
 CVE-2026-55883 (Tilt defines dev environments as code for microservice apps on Kuberne ...)
-	TODO: check
+	NOT-FOR-US: Tilt
 CVE-2026-55882 (Tilt defines dev environments as code for microservice apps on Kuberne ...)
-	TODO: check
+	NOT-FOR-US: Tilt
 CVE-2026-55881 (OpenReplay is a self-hosted session replay suite. From 1.22.0 before 1 ...)
-	TODO: check
+	NOT-FOR-US: OpenReplay
 CVE-2026-55880 (OpenReplay is a self-hosted session replay suite. In 1.27.0 and earlie ...)
-	TODO: check
+	NOT-FOR-US: OpenReplay
 CVE-2026-55879 (OpenReplay is a self-hosted session replay suite. From 1.24.0 before 1 ...)
-	TODO: check
+	NOT-FOR-US: OpenReplay
 CVE-2026-55852 (Frappe is a full-stack web application framework. Prior to 16.23.0 and ...)
-	TODO: check
+	NOT-FOR-US: Frappe
 CVE-2026-55810 (Improperly Controlled Modification of Dynamically-Determined Object At ...)
 	NOT-FOR-US: Drupal core and addons
 CVE-2026-55809 (Improperly Controlled Modification of Dynamically-Determined Object At ...)
@@ -176,13 +176,13 @@ CVE-2026-55804 (Improperly Controlled Modification of Dynamically-Determined Obj
 CVE-2026-55803 (Improperly Controlled Modification of Dynamically-Determined Object At ...)
 	NOT-FOR-US: Drupal core and addons
 CVE-2026-55789 (Logto is the modern, open-source auth infrastructure for SaaS and AI a ...)
-	TODO: check
+	NOT-FOR-US: Logto
 CVE-2026-55665 (Grist is spreadsheet software using Python as its formula language. Pr ...)
-	TODO: check
+	NOT-FOR-US: Grist
 CVE-2026-55664 (Grist is spreadsheet software using Python as its formula language. Pr ...)
-	TODO: check
+	NOT-FOR-US: Grist
 CVE-2026-55659 (Grist is spreadsheet software using Python as its formula language. Pr ...)
-	TODO: check
+	NOT-FOR-US: Grist
 CVE-2026-55515 (Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the ...)
 	- snipe-it <itp> (bug #1005172)
 CVE-2026-55481 (Snipe-IT is an IT asset/license management system. Prior to 8.6.2, def ...)
@@ -202,25 +202,26 @@ CVE-2026-55461 (Snipe-IT is an IT asset/license management system. Prior to 8.6.
 CVE-2026-55452 (Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Act ...)
 	- snipe-it <itp> (bug #1005172)
 CVE-2026-55405 (LangChain4j is a Java library for building LLM-powered applications on ...)
-	TODO: check
+	NOT-FOR-US: LangChain4j
 CVE-2026-55377 (Logto is the modern, open-source auth infrastructure for SaaS and AI a ...)
-	TODO: check
+	NOT-FOR-US: Logto
 CVE-2026-55370 (Logto is the modern, open-source auth infrastructure for SaaS and AI a ...)
-	TODO: check
+	NOT-FOR-US: Logto
 CVE-2026-55233 (OpenResty is a high performance web platform. From 1.29.2.1 to before  ...)
 	TODO: check
 CVE-2026-55229 (Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8. ...)
-	TODO: check
+	NOT-FOR-US: Gotenberg
 CVE-2026-55213 (h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Pr ...)
-	TODO: check
+	- h2o <removed>
+	NOTE: https://github.com/h2o/h2o/security/advisories/GHSA-432c-8xmj-frmq
 CVE-2026-55187 (Mailpit is an email testing tool and API for developers. Prior to 1.30 ...)
 	TODO: check
 CVE-2026-55175 (Spinnaker is an open source, multi-cloud continuous delivery platform. ...)
-	TODO: check
+	NOT-FOR-US: Spinnaker
 CVE-2026-54736 (Phalcon is a high-performance, full-stack PHP framework. Prior to 5.14 ...)
-	TODO: check
+	NOT-FOR-US: Phalcon
 CVE-2026-54714 (Logto is the modern, open-source auth infrastructure for SaaS and AI a ...)
-	TODO: check
+	NOT-FOR-US: Logto
 CVE-2026-52761 (ModSecurity is an open source, cross platform web application firewall ...)
 	TODO: check
 CVE-2026-52747 (ModSecurity is an open source, cross platform web application firewall ...)
@@ -485,9 +486,9 @@ CVE-2026-59180 (Apprise is an open source library which allows you to send a not
 	NOTE: https://github.com/caronc/apprise/pull/1610
 	NOTE: Fixed by: https://github.com/caronc/apprise/commit/68c0aef218055e4586cf4605fd6b56358f5f462d (v1.11.0)
 CVE-2026-59162 (Excelize is a Go language library for reading and writing Microsoft Ex ...)
-	TODO: check
+	NOT-FOR-US: Excelize
 CVE-2026-59161 (Excelize is a Go language library for reading and writing Microsoft Ex ...)
-	TODO: check
+	NOT-FOR-US: Excelize
 CVE-2026-59154 (Wekan is open source kanban built with Meteor. Prior to 9.64, Wekan ha ...)
 	- wekan <itp> (bug #819238)
 CVE-2026-59151 (Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML  ...)
@@ -499,7 +500,7 @@ CVE-2026-58493 (grav-plugin-database is the database plugin for Grav CMS. Prior
 CVE-2026-58492 (grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2 ...)
 	NOT-FOR-US: grav-plugin-database
 CVE-2026-58225 (SQL Injection vulnerability in elixir-ecto postgrex allows an attacker ...)
-	TODO: check
+	NOT-FOR-US: elixir-ecto postgrex
 CVE-2026-57994 (phpMyFAQ before 4.1.5 applies inconsistent active=yes and publication- ...)
 	NOT-FOR-US: phpMyFAQ
 CVE-2026-57961 (phpMyFAQ before 4.1.5 contains a potential authenticated path traversa ...)
@@ -581,7 +582,7 @@ CVE-2026-55781 (NanaZip is the 7-Zip derivative intended for the modern Windows
 CVE-2026-55780 (NanaZip is the 7-Zip derivative intended for the modern Windows experi ...)
 	NOT-FOR-US: NanaZip
 CVE-2026-55687 (ESF-IDF is the Espressif Internet of Things (IOT) Development Framewor ...)
-	TODO: check
+	NOT-FOR-US: ESF-IDF
 CVE-2026-55672 (ZITADEL is an open source identity management platform. Prior to 3.4.1 ...)
 	NOT-FOR-US: Zitadel
 CVE-2026-55671 (ZITADEL is an open source identity management platform. From 4.0.0-rc. ...)
@@ -621,11 +622,11 @@ CVE-2026-54469 (Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, cont
 CVE-2026-54468 (Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-54329 (Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-54149 (MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.0-l ...)
-	TODO: check
+	NOT-FOR-US: MaxKB
 CVE-2026-54063 (Excelize is a Go language library for reading and writing Microsoft Ex ...)
-	TODO: check
+	NOT-FOR-US: Excelize
 CVE-2026-54001 (osquery is a SQL powered operating system instrumentation, monitoring, ...)
 	TODO: check
 CVE-2026-54000 (osquery is a SQL powered operating system instrumentation, monitoring, ...)
@@ -633,9 +634,9 @@ CVE-2026-54000 (osquery is a SQL powered operating system instrumentation, monit
 CVE-2026-53780
 	REJECTED
 CVE-2026-53657 (Lima launches Linux virtual machines, typically on macOS, for running  ...)
-	TODO: check
+	NOT-FOR-US: Lima
 CVE-2026-53653 (Grav is a file-based Web platform. Prior to 1.7.53 and 2.0.0-rc.8, Gra ...)
-	TODO: check
+	NOT-FOR-US: Grav CMS
 CVE-2026-53450 (Coturn is a free open source implementation of TURN and STUN Server. P ...)
 	TODO: check
 CVE-2026-53449 (Coturn is a free open source implementation of TURN and STUN Server. P ...)
@@ -643,7 +644,7 @@ CVE-2026-53449 (Coturn is a free open source implementation of TURN and STUN Ser
 CVE-2026-53448 (Coturn is a free open source implementation of TURN and STUN Server. P ...)
 	TODO: check
 CVE-2026-51119 (An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalat ...)
-	TODO: check
+	NOT-FOR-US: Invixium IXM WEB
 CVE-2026-46388 (osquery is a SQL powered operating system instrumentation, monitoring, ...)
 	TODO: check
 CVE-2026-41880 (R-SOFT DMS is vulnerable toOS Command Injection in the Optical Charact ...)
@@ -2186,7 +2187,7 @@ CVE-2026-49145 (App::Ack versions through 3.10.0 for Perl read arbitrary files v
 	[bullseye] - ack <postponed> (Minor issue; local-only, needs untrusted project .ackrc; --files-from still unfixed upstream)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41643327/
 	NOTE: Fixed by: https://github.com/beyondgrep/ack3/commit/45ff5fe77dbd96f7332f31943102291f878f30b8 (v3.10.0)
-	NOTE: 45ff5fe (v3.10.0) is only a partial fix: it adds --follow to the project .ackrc blocklist but --files-from remains accepted, so arbitrary file read via --files-from is still unfixed upstream.
+	NOTE: v3.10.0 only released with a partial fix for the --follow-option.
 CVE-2026-44840 (Dgraph is an open source distributed GraphQL database. Prior to versio ...)
 	TODO: check
 CVE-2026-41122 (Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 r ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/b8641cc96f8f8797f11d05a985e95fd6b248af3f...951fca40b0b0efb61a9237c79143ec2c712f4ee1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/b8641cc96f8f8797f11d05a985e95fd6b248af3f...951fca40b0b0efb61a9237c79143ec2c712f4ee1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260712/ebbbb089/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list