[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Jul 21 21:35:27 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
3f95dd6e by Salvatore Bonaccorso at 2026-07-21T22:34:21+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -41,11 +41,11 @@ CVE-2026-64628 (Grav contains a stored cross-site scripting vulnerability in sho
 CVE-2026-64627 (Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and versions befo ...)
 	NOT-FOR-US: Parse Server
 CVE-2026-64609 (Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-ban ...)
-	TODO: check
+	NOT-FOR-US: Apache Fory
 CVE-2026-64608 (Heap type confusion and out-of-bounds read/write in the Apache Fory C+ ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-64606 (Deserialization of untrusted data vulnerability that may allow class-r ...)
-	TODO: check
+	NOT-FOR-US: Apache Fory
 CVE-2026-63454 (An authenticated path traversal vulnerability exists in AOS-CX. Succes ...)
 	NOT-FOR-US: HPE
 CVE-2026-63453 (Buffer overflow vulnerabilities exist in the command line interface of ...)
@@ -149,9 +149,9 @@ CVE-2026-47122 (Sparkle is a software update framework for macOS. In versions up
 CVE-2026-47121 (Sparkle is a software update framework for macOS. Prior to version 2.9 ...)
 	NOT-FOR-US: Sparkle
 CVE-2026-46681 (@nevware21/ts-utils is a comprehensive TypeScript/JavaScript utility l ...)
-	TODO: check
+	NOT-FOR-US: nevware21/ts-utils
 CVE-2026-44907 (A denial of service vulnerability could be triggered by sending specia ...)
-	TODO: check
+	NOT-FOR-US: react-server-dom-webpack, react-server-dom-parcel and react-server-dom-turbopack
 CVE-2026-44880 (A buffer overflow vulnerability was found in the command line interfac ...)
 	NOT-FOR-US: HPE
 CVE-2026-3183 (Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vuln ...)
@@ -197,7 +197,7 @@ CVE-2026-21575 (This High severity RCE (Remote Code Execution) vulnerability was
 CVE-2026-1771 (The MapSVG plugin for WordPress is vulnerable to arbitrary file upload ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-1617 (Improper neutralization of special elements used in an SQL command ('S ...)
-	TODO: check
+	NOT-FOR-US: Turkhotspot 5651 Loglama
 CVE-2026-1372 (The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to M ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-16493 (A flaw was found in ansible-core. The _extract_collection_from_git() f ...)
@@ -207,11 +207,11 @@ CVE-2026-16461 (A stack-based buffer overflow was found in rpcbind's rpcinfo uti
 CVE-2026-16454 (InEclipse hawkBitversions 1.0.3 and prior, a privilege escalation vuln ...)
 	TODO: check
 CVE-2026-16451 (A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e ...)
-	TODO: check
+	NOT-FOR-US: zsadmin2025 ZS-Admin
 CVE-2026-16450 (A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536 ...)
-	TODO: check
+	NOT-FOR-US: zsadmin2025 ZS-Admin
 CVE-2026-16449 (A vulnerability was determined in zsadmin2025 ZS-Admin up to b52e14536 ...)
-	TODO: check
+	NOT-FOR-US: zsadmin2025 ZS-Admin
 CVE-2026-16448 (A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-3 ...)
 	NOT-FOR-US: D-Link
 CVE-2026-16447 (A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an ...)
@@ -237,9 +237,9 @@ CVE-2026-15789 (A custom client can produce such an upload request to the BuildK
 CVE-2026-15724 (In Progress ShareFile Storage Zones Controller versions prior to 5.12. ...)
 	NOT-FOR-US: Progress Software
 CVE-2026-15432 (When verifying a mac with a ChunkedMacVerification object, Tink compar ...)
-	TODO: check
+	NOT-FOR-US: tink-java
 CVE-2026-15342 (Plane contains a multi\u2011tenant authorization flaw in its asset\u20 ...)
-	TODO: check
+	NOT-FOR-US: Plane
 CVE-2026-15145 (The Essential Addons for Elementor \u2013 Popular Elementor Templates  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-12548 (A heap out-of-bounds read flaw was found in libsoup. When parsing mult ...)
@@ -5234,7 +5234,7 @@ CVE-2026-26719 (Cross Site Scripting vulnerability in xxl-job-admin v.3.0.0 allo
 CVE-2026-26718 (A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-jo ...)
 	NOT-FOR-US: xxl-job-admin
 CVE-2026-26032 (The PackagerResolver of Apache Ivy is able to download online artifact ...)
-	TODO: check
+	NOT-FOR-US: Apache Ivy
 CVE-2026-21729 (Loki queries with large limits can cause large memory allocations whic ...)
 	NOT-FOR-US: Grafana Loki
 CVE-2026-15925 (Improper TLS hostname verification in Snowflake Connector for Python v ...)
@@ -7658,7 +7658,7 @@ CVE-2026-15410 (Post-authentication improper control of generation of code ('Cod
 CVE-2026-15409 (A Server-side request forgery (SSRF) vulnerability has been identified ...)
 	NOT-FOR-US: SonicWall
 CVE-2026-15389 (A vulnerability relating to insufficient access control has been ident ...)
-	TODO: check
+	NOT-FOR-US: Sesame Time
 CVE-2026-15305 (Users were able to upload files with arbitrary MIME types to forms usi ...)
 	NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-15265 (A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and  ...)
@@ -9476,7 +9476,7 @@ CVE-2026-41877 (R-SOFT DMS is vulnerable to Stored XSS in file upload functional
 CVE-2026-41876 (R-SOFT DMS is vulnerable toOS Command Injection in konwertujAction() f ...)
 	NOT-FOR-US: R-SOFT DMS
 CVE-2026-40454 (Out-of-bounds Read, Improper Input Validation vulnerability in Apache  ...)
-	TODO: check
+	NOT-FOR-US: Apache IoTDB C++
 CVE-2026-40452 (Incorrect Authorization, Improper Access Control vulnerability in Apac ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-40009 (Improper Privilege Management, Improper Access Control vulnerability i ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3f95dd6e24c5ec93470068b236dbc6eb3c674a8c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3f95dd6e24c5ec93470068b236dbc6eb3c674a8c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260721/8f41484e/attachment.htm>


More information about the debian-security-tracker-commits mailing list