[Git][security-tracker-team/security-tracker][master] 8 commits: Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Jul 23 15:06:08 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
ba5eacaa by Salvatore Bonaccorso at 2026-07-23T16:03:48+02:00
Process some NFUs
- - - - -
8bed17f3 by Salvatore Bonaccorso at 2026-07-23T16:04:09+02:00
Add new librest issue
- - - - -
620b387d by Salvatore Bonaccorso at 2026-07-23T16:04:22+02:00
Add new 389-ds-base issue
- - - - -
c38ad973 by Salvatore Bonaccorso at 2026-07-23T16:04:36+02:00
Add new systemd issue
- - - - -
66fd116a by Salvatore Bonaccorso at 2026-07-23T16:04:48+02:00
Add sbc issue, CVE-2026-16473
- - - - -
b07001e2 by Salvatore Bonaccorso at 2026-07-23T16:05:03+02:00
Add new duplicati issue, itp'ed
- - - - -
9a5ef793 by Salvatore Bonaccorso at 2026-07-23T16:05:16+02:00
Add new libarchive issue
- - - - -
a03cb112 by Salvatore Bonaccorso at 2026-07-23T16:05:30+02:00
Add new libsoup issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -72,25 +72,25 @@ CVE-2026-60366 (Vulnerability in the Oracle Platform Security for Java product o
CVE-2026-59676 (A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in s ...)
TODO: check
CVE-2026-38766 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a l ...)
- TODO: check
+ NOT-FOR-US: Unistal Systems Pvt. Ltd.Protegent 360
CVE-2026-38765 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a l ...)
- TODO: check
+ NOT-FOR-US: Unistal Systems Pvt. Ltd.Protegent 360
CVE-2026-38763 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a l ...)
- TODO: check
+ NOT-FOR-US: Unistal Systems Pvt. Ltd.Protegent 360
CVE-2026-21723 (The alertmanager templates test endpoint (/api/alertmanager/grafana/co ...)
NOT-FOR-US: Grafana Labs
CVE-2026-16653 (A security flaw has been discovered in boazsegev facil.io up to 0.7.58 ...)
- TODO: check
+ NOT-FOR-US: boazsegev facil.io
CVE-2026-16632 (A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is t ...)
- TODO: check
+ NOT-FOR-US: boazsegev facil.io
CVE-2026-16631 (A vulnerability was detected in publint up to 0.1.4. This impacts the ...)
- TODO: check
+ NOT-FOR-US: publint
CVE-2026-16630 (A security vulnerability has been detected in syncfusion ej2-javascrip ...)
- TODO: check
+ NOT-FOR-US: syncfusion ej2-javascript-ui-controls
CVE-2026-16629 (A vulnerability was identified in danger danger-js up to 13.0.7. Impac ...)
- TODO: check
+ NOT-FOR-US: danger danger-js
CVE-2026-16628 (A vulnerability was detected in oclif up to 4.23.16. Affected by this ...)
- TODO: check
+ NOT-FOR-US: oclif
CVE-2026-15074 (@fastify/static up to and including version 10.1.0 fails to reject dot ...)
TODO: check
CVE-2026-14899 (The code to parse MIME headers for display when forwarding a message ( ...)
@@ -100,7 +100,7 @@ CVE-2026-14881 (When importing connections in Compass it is possible to override
CVE-2026-14291 (The security-ninja-premium WordPress plugin before 5.290 does not veri ...)
NOT-FOR-US: WordPress plugin
CVE-2026-13089 (OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature v ...)
- TODO: check
+ NOT-FOR-US: OIDC::Lite Perl module
CVE-2026-13078 (A vulnerability was discovered in MongoDB Server where the server-side ...)
TODO: check
CVE-2026-13077 (A missing bounds check in the BSON CodeWScope element accessors allows ...)
@@ -304,35 +304,40 @@ CVE-2026-40712 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0, cont
CVE-2026-3482 (IBM Sterling B2B Integrator and IBM Sterling File Gateway6.2.0.0 throu ...)
NOT-FOR-US: IBM
CVE-2026-2406 (Authorization bypass through User-Controlled key vulnerability in Univ ...)
- TODO: check
+ NOT-FOR-US: Online Registration and Workflow Management System
CVE-2026-2395 (Improper neutralization of special elements used in an SQL command ('S ...)
- TODO: check
+ NOT-FOR-US: No Code Platform
CVE-2026-22049 (ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentica ...)
NOT-FOR-US: NetApp
CVE-2026-16624 (Cal.com OSS ships lacks authorization on webhook teamId creation, allo ...)
- TODO: check
+ NOT-FOR-US: Cal.com OSS
CVE-2026-16615 (A flaw was found in librest. The PKCE implementation for OAuth authori ...)
- TODO: check
+ - librest <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2504432
+ NOTE: https://gitlab.gnome.org/GNOME/librest/-/issues/25
CVE-2026-16607 (A vulnerability in Fujitsu Software Linux openFT andFujitsu Software O ...)
- TODO: check
+ NOT-FOR-US: Fujitsu
CVE-2026-16606 (A vulnerability in Fujitsu Software Linux openFT andFujitsu Software O ...)
- TODO: check
+ NOT-FOR-US: Fujitsu
CVE-2026-16560 (A heap-buffer-overflow flaw was found in Directory Server (389-ds-base ...)
- TODO: check
+ - 389-ds-base <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506102
CVE-2026-16552 (A flaw was found in systemd-tmpfiles. When processing a tmpfiles.d con ...)
- TODO: check
+ - systemd <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506073
CVE-2026-16551 (Denial-of-Service in Thinkst Applied Research OpenCanary (MongoDB modu ...)
- TODO: check
+ NOT-FOR-US: Thinkst Applied Research OpenCanary (MongoDB module)
CVE-2026-16544 (A flaw was found in AWX. The websocket event consumer performs RBAC au ...)
- TODO: check
+ NOT-FOR-US: Ansible Tower
CVE-2026-16473 (A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one e ...)
- TODO: check
+ - sbc <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2503650
CVE-2026-16270 (Open Mercato does not validate regex rules. An attacker with privilege ...)
- TODO: check
+ NOT-FOR-US: Open Mercato
CVE-2026-16232 (An authentication bypass vulnerability in the Check Point SmartConsole ...)
- TODO: check
+ NOT-FOR-US: Check Point
CVE-2026-16157 (Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY pe ...)
- TODO: check
+ - duplicati <itp> (bug #969188)
CVE-2026-15787 (The Ultimate Addons for Elementor plugin for WordPress is vulnerable t ...)
NOT-FOR-US: WordPress plugin
CVE-2026-14985 (The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains ...)
@@ -2904,31 +2909,35 @@ CVE-2026-42397 (Allocation of Resources Without Limits or Throttling (CWE-770) i
CVE-2026-3821 (Supermicro (SMC) SMASH services contain an Arbitrary code execution is ...)
NOT-FOR-US: Supermicro
CVE-2026-35290 (Vulnerability in Oracle Application Testing Suite. The supported ver ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-35287 (Vulnerability in Oracle Application Testing Suite. The supported ver ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-34316 (Vulnerability in the Oracle Commerce Service Center product of Oracle ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-30633 (Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via craf ...)
- TODO: check
+ NOT-FOR-US: knowns-dev/knowns
CVE-2026-30632 (Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via craf ...)
- TODO: check
+ NOT-FOR-US: knowns-dev/knowns
CVE-2026-30631 (An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc ...)
- TODO: check
+ NOT-FOR-US: bytebot-ai
CVE-2026-21954 (Vulnerability in the Oracle Retail Xstore Point of Service product of ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-21953 (Vulnerability in the Oracle Retail Xstore Point of Service product of ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-16517 (A signed integer overflow vulnerability was found in libarchive's ZIP ...)
- TODO: check
+ - libarchive <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2505492
+ NOTE: https://github.com/libarchive/libarchive/issues/3225
+ NOTE: https://github.com/libarchive/libarchive/pull/3228
+ NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/1c6e7b491f60fce335c20a9692f870d1f1ca39aa
CVE-2026-16492 (A weakness has been identified in umijs umi up to 4.6.63. The affected ...)
- TODO: check
+ NOT-FOR-US: umijs umi
CVE-2026-16490 (A security flaw has been discovered in itsourcecode Hospital Managemen ...)
NOT-FOR-US: itsourcecode System
CVE-2026-16489 (A vulnerability was identified in jsforce up to 3.10.16. This issue af ...)
- TODO: check
+ NOT-FOR-US: jsforce
CVE-2026-16488 (A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. Thi ...)
- TODO: check
+ NOT-FOR-US: QUSETIONS MiniCode-Python
CVE-2026-16486 (A vulnerability was found in SourceCodester Class and Exam Timetabling ...)
NOT-FOR-US: SourceCodester
CVE-2026-16485 (A vulnerability has been found in SourceCodester Class and Exam Timeta ...)
@@ -10810,15 +10819,30 @@ CVE-2026-15720 (InOpen5GS through version 2.7.7 a pre-authenticationheap out-of-
CVE-2026-15715 (A vulnerability was identified in SourceCodester Class and Exam Timeta ...)
NOT-FOR-US: SourceCodester
CVE-2026-15714 (An out-of-bounds read vulnerability was found in libsoup's multipart p ...)
- TODO: check
+ - libsoup3 <unfixed>
+ - libsoup2.4 <removed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499942
+ NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/542
CVE-2026-15713 (A vulnerability was found in libsoup's HTTP/2 protocol implementation. ...)
- TODO: check
+ - libsoup3 <unfixed>
+ - libsoup2.4 <removed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499941
+ NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/541
CVE-2026-15712 (A heap buffer over-read vulnerability was discovered in libsoup's (ver ...)
- TODO: check
+ - libsoup3 <unfixed>
+ - libsoup2.4 <removed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499939
+ NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/540
CVE-2026-15711 (A vulnerability was found in libsoup's WebSocket frame parsing impleme ...)
- TODO: check
+ - libsoup3 <unfixed>
+ - libsoup2.4 <removed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499924
+ NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/issues/515
CVE-2026-15709 (A flaw was found in libsoup's WebSocket implementation when using the ...)
- TODO: check
+ - libsoup3 <unfixed>
+ - libsoup2.4 <removed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499922
+ NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/issues/511
CVE-2026-15703 (A vulnerability was detected in SourceCodester Simple and Nice Shoppin ...)
NOT-FOR-US: SourceCodester
CVE-2026-15702 (A security vulnerability has been detected in tamagui up to 2.3.0. Thi ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ed7793a9745ce2ccfbf939d33f2c1d5eca7bfd5f...a03cb112b7789afadfa97e1dc924cf577de5e781
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ed7793a9745ce2ccfbf939d33f2c1d5eca7bfd5f...a03cb112b7789afadfa97e1dc924cf577de5e781
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260723/3a3f0dfb/attachment.htm>
More information about the debian-security-tracker-commits
mailing list