[Git][security-tracker-team/security-tracker][master] Add new nginx issue

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Jul 18 07:07:29 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
fbfcaaf2 by Salvatore Bonaccorso at 2026-07-18T08:07:11+02:00
Add new nginx issue

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1418,7 +1418,8 @@ CVE-2026-56699 (Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.i
 CVE-2026-56687 (Dell ThinOS 10, versions prior to 2605_10.2100, contain an Obsolete Fe ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-56434 (NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ ...)
-	TODO: check
+	- nginx <unfixed>
+	NOTE: https://my.f5.com/manage/s/article/K000162098
 CVE-2026-56400 (open-webui before 0.3.14 contains a cross-origin resource sharing misc ...)
 	NOT-FOR-US: open-webui
 CVE-2026-56398 (Open WebUI before 0.9.5 contains a stored cross-site scripting vulnera ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fbfcaaf227d252933742a4ef4e4e883a01cbb8ad

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fbfcaaf227d252933742a4ef4e4e883a01cbb8ad
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260718/39fd991b/attachment.htm>


More information about the debian-security-tracker-commits mailing list