[Git][security-tracker-team/security-tracker][master] 2 commits: Do not mention non-fix for CVE-2026-56362

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Jul 17 20:20:25 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a6c798fa by Salvatore Bonaccorso at 2026-07-17T21:18:46+02:00
Do not mention non-fix for CVE-2026-56362

- - - - -
d177759c by Salvatore Bonaccorso at 2026-07-17T21:19:55+02:00
Remove notes on some rejected CVEs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -6722,7 +6722,6 @@ CVE-2026-56775 (n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorizatio
 	NOT-FOR-US: n8n
 CVE-2026-56401
 	REJECTED
-	NOT-FOR-US: Wazuh
 CVE-2026-56374 (ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerabil ...)
 	- imagemagick 8:7.1.2.19+dfsg1-1
 	[trixie] - imagemagick <postponed> (Minor issue, fix along in future update)
@@ -6736,7 +6735,6 @@ CVE-2026-56362 (ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read
 	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-gq5v-qf8q-fp77
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/364606e5cb955b622b13015814e255e1dadd701b (7.1.2-14)
 	NOTE: See also https://github.com/ImageMagick/ImageMagick/issues/8567
-	NOTE: Not fixed in jumbo patch https://github.com/ImageMagick/ImageMagick/commit/e046417675d5c26e5f48816851a406c121c77469
 CVE-2026-56360 (n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 sig ...)
 	NOT-FOR-US: n8n
 CVE-2026-56359 (n8n before 2.8.0 contains a cross-site scripting vulnerability in the  ...)
@@ -10064,7 +10062,6 @@ CVE-2026-6686 (FatFs R0.16 and earlier contains an uninitialized cluster exposur
 	NOT-FOR-US: FatFs
 CVE-2026-6685
 	REJECTED
-	NOT-FOR-US: FatFs
 CVE-2026-6684 (FatFs prior to R0.16 that use GPT scanning with 'FF_LBA64 = 1' contain ...)
 	NOT-FOR-US: FatFs
 CVE-2026-6683 (FatFs R0.16 and earlier contains a divide-by-zero in exFAT sync logic  ...)
@@ -211921,7 +211918,6 @@ CVE-2024-7983 (In version 0.3.8 of open-webui, an endpoint for converting markdo
 	NOT-FOR-US: open-webui/open-webui
 CVE-2024-7959
 	REJECTED
-	NOT-FOR-US: open-webui/open-webui
 CVE-2024-7957 (An arbitrary file overwrite vulnerability exists in the ZulipConnector ...)
 	NOT-FOR-US: danswer-ai/danswer
 CVE-2024-7819 (A CORS misconfiguration in danswer-ai/danswer v1.4.1 allows attackers  ...)
@@ -211978,20 +211974,16 @@ CVE-2024-7043 (An improper access control vulnerability in open-webui/open-webui
 	NOT-FOR-US: open-webui/open-webui
 CVE-2024-7040
 	REJECTED
-	NOT-FOR-US: open-webui/open-webui
 CVE-2024-7039
 	REJECTED
-	NOT-FOR-US: open-webui/open-webui
 CVE-2024-7036 (A vulnerability in open-webui/open-webui v0.3.8 allows an unauthentica ...)
 	NOT-FOR-US: open-webui/open-webui
 CVE-2024-7035 (In version v0.3.8 of open-webui/open-webui, sensitive actions such as  ...)
 	NOT-FOR-US: open-webui/open-webui
 CVE-2024-7034
 	REJECTED
-	NOT-FOR-US: open-webui/open-webui
 CVE-2024-7033
 	REJECTED
-	NOT-FOR-US: open-webui/open-webui
 CVE-2024-6986 (A Cross-site Scripting (XSS) vulnerability exists in the Settings page ...)
 	NOT-FOR-US: parisneo/lollms-webui
 CVE-2024-6982 (A remote code execution vulnerability exists in the Calculate function ...)
@@ -262519,7 +262511,6 @@ CVE-2024-7041 (An Insecure Direct Object Reference (IDOR) vulnerability exists i
 	NOT-FOR-US: open-webui
 CVE-2024-7038
 	REJECTED
-	NOT-FOR-US: open-webui
 CVE-2024-7037 (In version v0.3.8 of open-webui/open-webui, the endpoint /api/pipeline ...)
 	NOT-FOR-US: open-webui
 CVE-2024-5968 (The Photo Gallery by 10Web  WordPress plugin before 1.8.28 does not pr ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/54324d2597780343f75a8856717e91310fba3023...d177759c50d22ab79a6d08145678e3a3d7478a29

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/54324d2597780343f75a8856717e91310fba3023...d177759c50d22ab79a6d08145678e3a3d7478a29
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260717/b14b4567/attachment.htm>


More information about the debian-security-tracker-commits mailing list