[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Jul 24 20:14:47 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
627373a9 by security tracker role at 2026-07-24T19:14:40+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
 CVE-2026-9765 (Note: The CVE and blog post don't exist because we determined this is  ...)
 	TODO: check
 CVE-2026-8789 (The Easy Appointments plugin for WordPress is vulnerable to unauthoriz ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-8308 (Improper neutralization of input during web page generation ('cross-si ...)
 	TODO: check
 CVE-2026-7484 (External control of Assumed-Immutable web parameter vulnerability in A ...)
@@ -9,13 +9,13 @@ CVE-2026-7484 (External control of Assumed-Immutable web parameter vulnerability
 CVE-2026-7483 (Local privilege escalationpotentially allowed an attacker to write an  ...)
 	TODO: check
 CVE-2026-7007 (The Zephyr ext2 file system validates the on-disk superblock in ext2_v ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-66144 (Although remote policy references are not retrieved during policy norm ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-66143 (It is possible to bypass themaximum number of normalized policy altern ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-66142 (Apache Neethi is vulnerable to uncontrolled recursion when parsing pol ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-66035 (libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authen ...)
 	TODO: check
 CVE-2026-66034 (libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bo ...)
@@ -29,9 +29,9 @@ CVE-2026-66027 (Suna before 0.9.102 contains a broken access control vulnerabili
 CVE-2026-66010 (DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook fo ...)
 	TODO: check
 CVE-2026-66009 (Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 befo ...)
-	TODO: check
+	NOT-FOR-US: Parse Server
 CVE-2026-66008 (Parse Server versions >= 9.0.0 before 9.10.0-alpha.6 and >= 8.2.2 befo ...)
-	TODO: check
+	NOT-FOR-US: Parse Server
 CVE-2026-66007 (Datasets through 5.0.0, fixed in commit f989ef9, contains a path trave ...)
 	TODO: check
 CVE-2026-66006 (lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentica ...)
@@ -153,17 +153,17 @@ CVE-2026-64208 (In the Linux kernel, the following vulnerability has been resolv
 CVE-2026-63317 (Arbitrary Class Instantiation via XML Feature Generator Descriptor and ...)
 	TODO: check
 CVE-2026-58630 (Improper access control in Azure App Service allows an unauthorized at ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-58586 (Image::WebP versions through 0.2 for Perl bundle a vulnerable version  ...)
 	TODO: check
 CVE-2026-57106 (Server-side request forgery (ssrf) in Data Quality allows an unauthori ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-56392 (GNU coreutils unexpand is vulnerable to a heap-based buffer overflow d ...)
 	TODO: check
 CVE-2026-56391 (GNU coreutils uniq is vulnerable to an out\u2011of\u2011bounds read du ...)
 	TODO: check
 CVE-2026-56163 (Missing authentication for critical function in Microsoft Azure Kubern ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-55732 (Out-of-bounds Read (CWE-125)in BACnet packet parsing (`bacdt_datetime_ ...)
 	TODO: check
 CVE-2026-55731 (Unchecked input for loop condition (CWE-606)in the SNMP agent in Loyte ...)
@@ -177,11 +177,11 @@ CVE-2026-55728 (Stack-based Buffer Overflow (CWE-121)in `/usr/bin/ltsudo` `cmd_i
 CVE-2026-54342 (In epa4all, prior to version 2026-05-20, an attacker on the network pa ...)
 	TODO: check
 CVE-2026-49745 (Kernel software installed and running inside a Guest VM may post impro ...)
-	TODO: check
+	NOT-FOR-US: Imagination Technologies
 CVE-2026-49744 (Kernel software installed and running inside a Guest VM may post impro ...)
-	TODO: check
+	NOT-FOR-US: Imagination Technologies
 CVE-2026-49743 (Software installed and run as a non-privileged user may conduct improp ...)
-	TODO: check
+	NOT-FOR-US: Imagination Technologies
 CVE-2026-49326 (Missing Authorization vulnerability in Apache HBase thrift and rest de ...)
 	TODO: check
 CVE-2026-48037 (Hulumi is an open-source toolkit that ships secure-by-default cloud an ...)
@@ -199,17 +199,17 @@ CVE-2026-48032 (Hulumi is an open-source toolkit that ships secure-by-default cl
 CVE-2026-48021 (In epa4all, prior to version 2026-05-20, an attacker who can intercept ...)
 	TODO: check
 CVE-2026-46452 (Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-45816 (NULL Pointer Dereference vulnerability in Apache NimBLE inLE Long Term ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-45815 (Reachable Assertion vulnerability in Apache NimBLE. A specially crafte ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-45813 (Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-45812 (Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE wh ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-45811 (Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-24727 (An unrestricted upload of file with dangerous type vulnerability in th ...)
 	TODO: check
 CVE-2026-17107 (A flaw was found in the cluster-proxy service-proxy component used in  ...)
@@ -223,55 +223,55 @@ CVE-2026-17039 (A flaw was found in pki-core. The certificate authority (CA) ren
 CVE-2026-16910 (A flaw was found in Red Hat Quay's notification webhook feature. The S ...)
 	TODO: check
 CVE-2026-16802 (Cleartext storage of sensitive information in the variables feature in ...)
-	TODO: check
+	NOT-FOR-US: Devolutions
 CVE-2026-16801 (Improper control of generation of code ('Code Injection') in the varia ...)
-	TODO: check
+	NOT-FOR-US: Devolutions
 CVE-2026-16800 (Improper control of generation of code ('Code Injection') in the sched ...)
-	TODO: check
+	NOT-FOR-US: Devolutions
 CVE-2026-16799 (Improper access control in the automation tests and workflows features ...)
-	TODO: check
+	NOT-FOR-US: Devolutions
 CVE-2026-16798 (Insertion of sensitive information into sent data in the automation jo ...)
-	TODO: check
+	NOT-FOR-US: Devolutions
 CVE-2026-16743 (A flaw was found in accountsservice. The systemd-homed code path for S ...)
 	TODO: check
 CVE-2026-16730 (A flaw was found in dbus-broker. When the process file-descriptor limi ...)
 	TODO: check
 CVE-2026-16519 (A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Uti ...)
-	TODO: check
+	NOT-FOR-US: GeoVision
 CVE-2026-15821 (The SureDash \u2013 Community, Courses & Member Dashboard plugin for W ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15810 (A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker vers ...)
 	TODO: check
 CVE-2026-15755 (The Open User Map \u2013 Interactive Leaflet Maps plugin for WordPress ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15739 (The Rich Showcase for Google Reviews plugin for WordPress is vulnerabl ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15704 (In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABA ...)
 	TODO: check
 CVE-2026-15665 (The Fluent Support \u2013 Helpdesk & Customer Support Ticket System pl ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15663 (The Ninja Forms \u2013 The Contact Form Builder That Grows With You pl ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15653 (The Visualizer \u2013 Tables & Charts Manager with Built-in AI Generat ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15648 (The Brands for WooCommerce plugin for WordPress is vulnerable to Store ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15464 (The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cros ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15401 (The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vuln ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15346 (The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vuln ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15334 (The Cozy Blocks \u2013 Page Builder for Gutenberg Editor & FSE with 60 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15333 (The Cozy Blocks \u2013 Page Builder for Gutenberg Editor & FSE with 60 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15243 (Apereo CAS Clientaccepts any CA-trusted certificate for any hostname,  ...)
 	TODO: check
 CVE-2026-12702 (In affected versions of Octopus Deploy Insufficient checks on the proj ...)
-	TODO: check
+	NOT-FOR-US: Octopus Deploy
 CVE-2026-12654 (The Payment Plugins for Stripe WooCommerce plugin for WordPress is vul ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12504 (Improper Authentication (CWE-287)in the PAM configuration in Loytec LI ...)
 	TODO: check
 CVE-2026-12503 (Improper Link Resolution (CWE-59)in `/usr/bin/larm_starter` in Loytec  ...)
@@ -283,7 +283,7 @@ CVE-2026-12496 (Stored Cross-Site Scripting (CWE-79)in the OPC XML-DA server sta
 CVE-2026-10610 (Local privilege escalationpotentially allowed an attacker to execute a ...)
 	TODO: check
 CVE-2026-10033 (The EventON Action User plugin for WordPress is vulnerable to authoriz ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16634 (TOML::XS versions before 0.06 for Perl bundle an unsupported and vulne ...)
 	NOT-FOR-US: TOML::XS Perl module
 CVE-2026-6924 (A bug in the entropy initialization for SiWx917 causes the DRBG to use ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/627373a97c3e09e0d4563992cefd82eadeaf8c64

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/627373a97c3e09e0d4563992cefd82eadeaf8c64
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260724/ddaf8574/attachment.htm>


More information about the debian-security-tracker-commits mailing list