[Git][security-tracker-team/security-tracker][master] 2 commits: Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Jul 17 21:19:23 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
08ddcdcd by Salvatore Bonaccorso at 2026-07-17T22:19:01+02:00
Process some NFUs

- - - - -
6a696b5e by Salvatore Bonaccorso at 2026-07-17T22:19:01+02:00
Add CVE-2026-63308/Helm

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3,17 +3,17 @@ CVE-2026-9762 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulne
 CVE-2026-9656 (The HubSpot All-In-One Marketing \u2013 Forms, Popups, Live Chat plugi ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-9602 (Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate  ...)
-	TODO: check
+	NOT-FOR-US: Mattermost Desktop App
 CVE-2026-9592 (SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 ...)
-	TODO: check
+	NOT-FOR-US: SEPPmail
 CVE-2026-9588 (A stored cross-site scripting (XSS) vulnerability exists in Sangoma Sw ...)
-	TODO: check
+	NOT-FOR-US: Sangoma Switchvox SMB Edition
 CVE-2026-9587 (An authenticated local file inclusion vulnerability exists in Sangoma  ...)
-	TODO: check
+	NOT-FOR-US: Sangoma Switchvox SMB Edition
 CVE-2026-9586 (An unauthenticated SQL injection vulnerability exists in Sangoma Switc ...)
-	TODO: check
+	NOT-FOR-US: Sangoma Switchvox SMB Edition
 CVE-2026-9585 (An unauthenticated reflected cross-site scripting (XSS) vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: Sangoma Switchvox SMB Edition
 CVE-2026-9537 (Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a  ...)
 	- libmojo-jwt-perl 1.02-1
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41907805/
@@ -29,39 +29,39 @@ CVE-2026-9135 (IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9
 CVE-2026-9103 (IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to ...)
 	NOT-FOR-US: IBM
 CVE-2026-8396 (Improper restriction of XML external entity reference vulnerability in ...)
-	TODO: check
+	NOT-FOR-US: NetGIS
 CVE-2026-8297 (Improper neutralization of special elements used in an SQL command ('S ...)
-	TODO: check
+	NOT-FOR-US: GisLab Laboratory Management System
 CVE-2026-8075 (Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly  ...)
-	TODO: check
+	NOT-FOR-US: Mattermost Desktop App
 CVE-2026-7488 (Insertion of sensitive information into sent data vulnerability in IKA ...)
-	TODO: check
+	NOT-FOR-US: IKAS Technology Inc. E-Commerce
 CVE-2026-7189 (Insertion of sensitive information into sent data vulnerability in Pro ...)
-	TODO: check
+	NOT-FOR-US: Proliz
 CVE-2026-63309 (SurrealDB before 3.1.5 fail to apply field-level SELECT permissions to ...)
-	TODO: check
+	NOT-FOR-US: SurrealDB
 CVE-2026-63308 (Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of serv ...)
-	TODO: check
+	- helm-kubernetes <itp> (bug #910799)
 CVE-2026-63307 (Chat2DB before 5.3.0 contains an insecure direct object reference vuln ...)
-	TODO: check
+	NOT-FOR-US: Chat2DB
 CVE-2026-63101 (Open Event Server through 1.19.1 contains a missing authentication vul ...)
-	TODO: check
+	NOT-FOR-US: Open Event Server
 CVE-2026-63100 (Maybe through 0.6.0 contains a missing authorization vulnerability tha ...)
-	TODO: check
+	NOT-FOR-US: Maybe
 CVE-2026-63099 (TheHive through 4.1.24 contains a broken object-level authorization vu ...)
-	TODO: check
+	NOT-FOR-US: TheHive
 CVE-2026-63098 (TheHive through 4.1.24 contains an unauthenticated information disclos ...)
-	TODO: check
+	NOT-FOR-US: TheHive
 CVE-2026-63097 (Dendrite through 0.13.8 contains an improper access control vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: Dendrite
 CVE-2026-63096 (Dendrite through 0.13.8 contains a server-side request forgery vulnera ...)
-	TODO: check
+	NOT-FOR-US: Dendrite
 CVE-2026-63095 (Dendrite through 0.13.8 contains an improper authorization vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: Dendrite
 CVE-2026-63094 (SigNoz through 0.133.0 contains an open redirect vulnerability in the  ...)
-	TODO: check
+	NOT-FOR-US: SigNoz
 CVE-2026-63093 (Cursor for Windows version 3.2.16 contains a binary planting vulnerabi ...)
-	TODO: check
+	NOT-FOR-US: Cursor
 CVE-2026-62764 (Improper Handling of Insufficient Privileges vulnerability in Apache A ...)
 	TODO: check
 CVE-2026-60025 (The Joomla extension Events Booking prior version 5.8.0 had an fronten ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/cb7d77916bf1dc9ca3f563b3e06972ea3edd2484...6a696b5eddd846cf4d56eda2f0ae5ddf6aafb419

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/cb7d77916bf1dc9ca3f563b3e06972ea3edd2484...6a696b5eddd846cf4d56eda2f0ae5ddf6aafb419
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260717/64857560/attachment.htm>


More information about the debian-security-tracker-commits mailing list