[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Jul 25 06:44:26 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a0983093 by Salvatore Bonaccorso at 2026-07-25T07:43:58+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1445,7 +1445,7 @@ CVE-2026-15074 (@fastify/static up to and including version 10.1.0 fails to reje
 CVE-2026-14899 (The code to parse MIME headers for display when forwarding a message ( ...)
 	TODO: check
 CVE-2026-14881 (When importing connections in Compass it is possible to override some  ...)
-	TODO: check
+	NOT-FOR-US: mongodb-js (not same as node-mongodb)
 CVE-2026-14291 (The security-ninja-premium WordPress plugin before 5.290 does not veri ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-13089 (OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature v ...)
@@ -1720,7 +1720,7 @@ CVE-2026-14932 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, th
 CVE-2026-14865 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, the inte ...)
 	NOT-FOR-US: Progress Software
 CVE-2026-14551 (The servereye client (also known as sensorhub, technically ClientAgent ...)
-	TODO: check
+	NOT-FOR-US: servereye
 CVE-2026-13192 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, insuffic ...)
 	NOT-FOR-US: Progress Software
 CVE-2026-13190 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, a deseri ...)
@@ -5681,7 +5681,7 @@ CVE-2026-16277 (A stack-based buffer overflow was found in rpcbind's rpcinfo uti
 	- rpcbind <unfixed> (bug #1142506)
 	NOTE: Fixed by: https://git.linux-nfs.org/?p=steved/rpcbind.git;a=commitdiff;h=bb9bb7286a4c345442946dc2ce3c9e7f67e96d4d (rpcbind-1_2_9)
 CVE-2026-16254 (A flaw was found in claircore's apk package scanner. Malformed package ...)
-	TODO: check
+	NOT-FOR-US: claircore
 CVE-2026-16252 (A security flaw has been discovered in Beijing Shenzhou Shihan Technol ...)
 	NOT-FOR-US: Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System
 CVE-2026-16248 (A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This  ...)
@@ -5704,7 +5704,7 @@ CVE-2026-15588 (A denial-of-service and resource exhaustion vulnerability exists
 	NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5241
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/glib/-/commit/4235f7b42ba51d6fdb4abd7c4276031802f39834 (glib-2-88 branch)
 CVE-2026-14448 (An high privileged remote attacker can exploit an authenticated OS com ...)
-	TODO: check
+	NOT-FOR-US: MB connect line
 CVE-2026-13724 (Client-Side Enforcement of Server-Side Security vulnerability in Gobit ...)
 	NOT-FOR-US: Corporate Training Management System
 CVE-2026-12701 (A path traversal vulnerability was found in pulpcore. The relative_pat ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a09830930f907d9756f25a4ff9ff0c5748799183

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a09830930f907d9756f25a4ff9ff0c5748799183
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260725/0402a82b/attachment.htm>


More information about the debian-security-tracker-commits mailing list