[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Jul 21 20:50:52 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
64789536 by Salvatore Bonaccorso at 2026-07-21T21:50:33+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3,37 +3,37 @@ CVE-2026-9499 (An out-of-bounds read (buffer over-read) vulnerability exists in
 CVE-2026-8593 (Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0 ...)
 	- check-mk <removed>
 CVE-2026-8285 (Improper restriction of excessive authentication attempts vulnerabilit ...)
-	TODO: check
+	NOT-FOR-US: FlexCity
 CVE-2026-8284 (URL redirection to untrusted site ('open redirect') vulnerability in U ...)
-	TODO: check
+	NOT-FOR-US: FlexCity
 CVE-2026-6792 (Missing Authorization vulnerability in Universal Software Inc. FlexCit ...)
-	TODO: check
+	NOT-FOR-US: FlexCity
 CVE-2026-65052 (Ninja Forms WordPress plugin version 3.14.8 and prior contains an impr ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-65051 (Ninja Forms WordPress plugin version 3.14.8 contains a client-side enf ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-65050 (Ninja Forms WordPress plugin version 3.14.8 and prior contains a missi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-65049 (Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite co ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-65048 (Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contai ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-65009 (OpenRemote versions before 1.26.2 contain an information disclosure vu ...)
-	TODO: check
+	NOT-FOR-US: OpenRemote
 CVE-2026-65008 (Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerabi ...)
-	TODO: check
+	NOT-FOR-US: Grav CMS
 CVE-2026-65007 (The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly a ...)
-	TODO: check
+	NOT-FOR-US: Grav plugin
 CVE-2026-64877 (An authenticated non-admin user can exploit a SQL injection flaw in th ...)
 	NOT-FOR-US: Tenable
 CVE-2026-64825 (Home Assistant Core before 2026.6.0 contains a path traversal vulnerab ...)
-	TODO: check
+	NOT-FOR-US: Home Assistant Core
 CVE-2026-64824 (Home Assistant Core before 2026.7.0 contains a path traversal vulnerab ...)
-	TODO: check
+	NOT-FOR-US: Home Assistant Core
 CVE-2026-64823 (Home Assistant Core before 2026.5.4 contains a cross-site scripting vu ...)
-	TODO: check
+	NOT-FOR-US: Home Assistant Core
 CVE-2026-64628 (Grav contains a stored cross-site scripting vulnerability in shortcode ...)
-	TODO: check
+	NOT-FOR-US: Grav CMS
 CVE-2026-64627 (Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and versions befo ...)
 	NOT-FOR-US: Parse Server
 CVE-2026-64609 (Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-ban ...)
@@ -51,13 +51,13 @@ CVE-2026-62415 (The Joomla extension Membership Pro prior version 4.6.2 did by d
 CVE-2026-60080 (Use After Free vulnerability in the Rust deserialization logic of Apac ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-59142 (Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bo ...)
-	TODO: check
+	NOT-FOR-US: Data::HashMap::Shared Perl module
 CVE-2026-59141 (Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of- ...)
-	TODO: check
+	NOT-FOR-US: Data::RadixTree::Shared Perl module
 CVE-2026-59140 (Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of- ...)
-	TODO: check
+	NOT-FOR-US: Data::SortedSet::Shared Perl module
 CVE-2026-59139 (Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bou ...)
-	TODO: check
+	NOT-FOR-US: Data::ReqRep::Shared Perl module
 CVE-2026-56587 (HCL IEM was affected with Strict transport security not enforced. It m ...)
 	NOT-FOR-US: HCL
 CVE-2026-56586 (HCL IEM was affected with X-Content-Type-Options Header Missing. It ma ...)
@@ -81,69 +81,69 @@ CVE-2026-56578 (HCL MyCloud was affected by Server Version Disclosure. It may he
 CVE-2026-56577 (HCL MyCloud was affected with Weak Password Policy. It may increase th ...)
 	NOT-FOR-US: HCL
 CVE-2026-55084 (DHIS2 is a flexible information system for data capture, management, v ...)
-	TODO: check
+	NOT-FOR-US: DHIS2
 CVE-2026-55082 (DHIS2 is a flexible information system for data capture, management, v ...)
-	TODO: check
+	NOT-FOR-US: DHIS2
 CVE-2026-55081 (DHIS2 is a flexible information system for data capture, management, v ...)
-	TODO: check
+	NOT-FOR-US: DHIS2
 CVE-2026-47657 (HumHub is an Open Source Enterprise Social Network. In versions 1.13.0 ...)
-	TODO: check
+	NOT-FOR-US: HumHub
 CVE-2026-47425 (Rattler is a library that provides common functionality used within th ...)
-	TODO: check
+	NOT-FOR-US: Rattler
 CVE-2026-47419 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-47418 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-47417 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-47416 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-47415 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-47414 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-47413 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-47412 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-47411 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-47410 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-47409 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-47408 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-47407 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-47406 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-47405 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-47399 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-47398 (PraisonAI is a multi-agent teams system. The v4.6.32 chokepoint refact ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-47397 (PraisonAI is a multi-agent teams system. Prior to version 4.6.40, hidd ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-47396 (PraisonAI is a multi-agent teams system. Prior to version 4.6.40, Prai ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-47395 (PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of Pr ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-47394 (PraisonAI is a multi-agent teams system. Prior to version 4.6.40, the  ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-47393 (PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xc ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-47392 (PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of Pr ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-47391 (PraisonAI is a multi-agent teams system. Prior to version 4.6.40, Prai ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-47390 (PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of Pr ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-47122 (Sparkle is a software update framework for macOS. In versions up to an ...)
-	TODO: check
+	NOT-FOR-US: Sparkle
 CVE-2026-47121 (Sparkle is a software update framework for macOS. Prior to version 2.9 ...)
-	TODO: check
+	NOT-FOR-US: Sparkle
 CVE-2026-46681 (@nevware21/ts-utils is a comprehensive TypeScript/JavaScript utility l ...)
 	TODO: check
 CVE-2026-44907 (A denial of service vulnerability could be triggered by sending specia ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/64789536f550fe08932890c11f3a8829cc341549

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/64789536f550fe08932890c11f3a8829cc341549
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260721/d6ea89ff/attachment.htm>


More information about the debian-security-tracker-commits mailing list