[Git][security-tracker-team/security-tracker][master] 2 commits: Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Jul 13 06:05:07 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f41d70da by Salvatore Bonaccorso at 2026-07-13T07:04:00+02:00
Process some NFUs

- - - - -
50569cd1 by Salvatore Bonaccorso at 2026-07-13T07:04:03+02:00
Add CVE-2026-449512/onnx

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -632,9 +632,9 @@ CVE-2026-57474 (Deloitte AI Assist for Customer disclosed some configuration inf
 CVE-2026-57167 (PeerTube is an ActivityPub-federated video streaming platform. Prior t ...)
 	- peertube <itp> (bug #950821)
 CVE-2026-56814 (Plug.Parsers.MULTIPART, the multipart request-body parser used to hand ...)
-	TODO: check
+	NOT-FOR-US: elixir-plug plug
 CVE-2026-56813 (Improper Neutralization of Parameter/Argument Delimiters vulnerability ...)
-	TODO: check
+	NOT-FOR-US: elixir-plug plug
 CVE-2026-56765 (Vikunja before 2.2.1 contains an authorization flaw where the LinkShar ...)
 	NOT-FOR-US: Vikunja
 CVE-2026-56690 (Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improp ...)
@@ -806,7 +806,7 @@ CVE-2026-3251 (Improper neutralization of input during web page generation ('cro
 CVE-2026-39903 (Simple Machines Forum 2.1 prior to 2.1.8 and 3.0 prior to 3.0 Alpha 5  ...)
 	NOT-FOR-US: Simple Machines Forum
 CVE-2026-39244 (adm-zip before 0.5.18 is vulnerable to denial of service via a crafted ...)
-	TODO: check
+	NOT-FOR-US: Node adm-zip module
 CVE-2026-38059 (The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoin ...)
 	NOT-FOR-US: iDirect iQ200
 CVE-2026-38057 (The iDirect iQ200 does not validate CSRF tokens on state-changing API  ...)
@@ -1026,11 +1026,11 @@ CVE-2026-44787 (Discourse is an open-source discussion platform. Prior to 2026.6
 CVE-2026-44342 (New API is a large language mode (LLM) gateway and artificial intellig ...)
 	NOT-FOR-US: New API
 CVE-2026-39246 (decompress before 4.2.2 allows arbitrary symlink creation during archi ...)
-	TODO: check
+	NOT-FOR-US: Node decompress module
 CVE-2026-39245 (decompress before 4.2.2 contains an improper path containment check th ...)
-	TODO: check
+	NOT-FOR-US: Node decompress module
 CVE-2026-39243 (decompress before 4.2.2 allows arbitrary hardlink creation during arch ...)
-	TODO: check
+	NOT-FOR-US: Node decompress module
 CVE-2026-38076 (An integer overflow in the jbig2_arith_iaid_ctx_new() function of Arti ...)
 	TODO: check
 CVE-2026-33803 (An Improper Restriction of Communication Channel to Intended Endpoints ...)
@@ -1793,7 +1793,10 @@ CVE-2026-47646 (Improper neutralization of input during web page generation ('cr
 CVE-2026-45045 (Fiber is an Express inspired web framework written in Go. Prior to 3.3 ...)
 	NOT-FOR-US: Fiber
 CVE-2026-44512 (Open Neural Network Exchange (ONNX) is an open standard for machine le ...)
-	TODO: check
+	- onnx <unfixed>
+	NOTE: https://github.com/onnx/onnx/security/advisories/GHSA-hwpq-hmq9-wj77
+	NOTE: https://github.com/onnx/onnx/pull/7813
+	NOTE: Fixed by: https://github.com/onnx/onnx/commit/cd310408165ad47c3cd7eb2b86cb5b80aa2e4fdf (v1.22.0)
 CVE-2026-44332 (Fiber is an Express inspired web framework written in Go. Prior to 3.3 ...)
 	NOT-FOR-US: Fiber
 CVE-2026-44161 (Fluentd collects events from various data sources and writes them to f ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/c01edb230a4a051605ffccbb81a600d5df306769...50569cd1e96aa347f198226c02c432fee41813f9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/c01edb230a4a051605ffccbb81a600d5df306769...50569cd1e96aa347f198226c02c432fee41813f9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260713/5eb66ca9/attachment.htm>


More information about the debian-security-tracker-commits mailing list