[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Jul 26 13:57:28 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
daeb62a2 by Salvatore Bonaccorso at 2026-07-26T14:57:05+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3,13 +3,13 @@ CVE-2026-64530 (In the Linux kernel, the following vulnerability has been resolv
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/a8a02897f2b479127db261de05cbf0c28b98d159 (7.2-rc1)
 CVE-2026-63720 (datamodel-code-generator prior to version 0.70.0 contains a code injec ...)
-	TODO: check
+	NOT-FOR-US: datamodel-code-generator
 CVE-2026-17434 (A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is t ...)
-	TODO: check
+	NOT-FOR-US: nanocoai NanoClaw
 CVE-2026-17433 (A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This i ...)
-	TODO: check
+	NOT-FOR-US: nanocoai NanoClaw
 CVE-2026-17432 (A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Af ...)
-	TODO: check
+	NOT-FOR-US: NousResearch hermes-agent
 CVE-2026-15962 (The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2024-14040 (In the Linux kernel, the following vulnerability has been resolved:  n ...)
@@ -22,7 +22,7 @@ CVE-2026-66012 (SiYuan before v3.7.2 contains a missing authorization vulnerabil
 CVE-2026-66011 (ImageMagick before 7.1.2-27 contains a memory leak vulnerability in th ...)
 	TODO: check
 CVE-2026-16766 (Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell ...)
-	TODO: check
+	NOT-FOR-US: Catalyst::View::Wkhtmltopdf Perl module
 CVE-2026-15425 (The Yoast SEO \u2013 Advanced SEO with real-time guidance and built-in ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-10818 (The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File U ...)
@@ -1383,21 +1383,21 @@ CVE-2026-66036 (FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap o
 CVE-2026-62835 (Improper authorization in Azure Portal allows an unauthorized attacker ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-61892 (Weintek cMT3092X HMI allows a non-privileged user to modify tokens to  ...)
-	TODO: check
+	NOT-FOR-US: Weintek cMT3092X HMI
 CVE-2026-61886 (Weintek cMT3092X HMI stores user account passwords in plaintext.)
-	TODO: check
+	NOT-FOR-US: Weintek cMT3092X HMI
 CVE-2026-61884 (The web management interface ofTycon Systems TPDIN-Monitor-WEB2  does  ...)
-	TODO: check
+	NOT-FOR-US: Tycon Systems
 CVE-2026-60135 (An attacker can modify data that should be restricted to read\u2011onl ...)
-	TODO: check
+	NOT-FOR-US: Weintek
 CVE-2026-60134 (Weintek cMT3092X HMI allows a non-privileged user to modify cookies to ...)
-	TODO: check
+	NOT-FOR-US: Weintek
 CVE-2026-57531 (Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: Milkdown
 CVE-2026-57530 (Milkdown before 7.21.3 contains a stored cross-site scripting vulnerab ...)
-	TODO: check
+	NOT-FOR-US: Milkdown
 CVE-2026-55985 (The web management interface in Tycon Systems TPDIN-Monitor-WEB2  stor ...)
-	TODO: check
+	NOT-FOR-US: Tycon Systems
 CVE-2026-16280 (An integer overflow when calculating physical offsets for sparse PMRs  ...)
 	NOT-FOR-US: Imagination Technologies
 CVE-2026-14955 (The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress i ...)
@@ -1869,13 +1869,13 @@ CVE-2026-12702 (In affected versions of Octopus Deploy Insufficient checks on th
 CVE-2026-12654 (The Payment Plugins for Stripe WooCommerce plugin for WordPress is vul ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-12504 (Improper Authentication (CWE-287)in the PAM configuration in Loytec LI ...)
-	TODO: check
+	NOT-FOR-US: Loytec
 CVE-2026-12503 (Improper Link Resolution (CWE-59)in `/usr/bin/larm_starter` in Loytec  ...)
-	TODO: check
+	NOT-FOR-US: Loytec
 CVE-2026-12502 (Improper Privilege Management (CWE-269)in `/usr/bin/ltsudo` in Loytec  ...)
-	TODO: check
+	NOT-FOR-US: Loytec
 CVE-2026-12496 (Stored Cross-Site Scripting (CWE-79)in the OPC XML-DA server statistic ...)
-	TODO: check
+	NOT-FOR-US: Loytec
 CVE-2026-10610 (Local privilege escalationpotentially allowed an attacker to execute a ...)
 	TODO: check
 CVE-2026-10033 (The EventON Action User plugin for WordPress is vulnerable to authoriz ...)
@@ -2702,7 +2702,7 @@ CVE-2026-15786 (The WP Encryption \u2013 One Click Free SSL Certificate & SSL /
 CVE-2026-15761 (The Tickera \u2013 Sell Tickets & Manage Events plugin for WordPress i ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-15687 (A security issue was discovered in the Kubernetes Java client library  ...)
-	TODO: check
+	NOT-FOR-US: Kubernetes Java client
 CVE-2026-15647 (The Brands for WooCommerce plugin for WordPress is vulnerable to Store ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-15646 (The Brands for WooCommerce plugin for WordPress is vulnerable to Store ...)
@@ -11028,7 +11028,7 @@ CVE-2026-13103 (A potential path traversal vulnerability was reported in Lenovo
 CVE-2026-12393 (The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does n ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-12391 (An insecure symlink following vulnerability exists in Canonical ubuntu ...)
-	TODO: check
+	NOT-FOR-US: Canonical
 CVE-2026-12379 (An Open Redirect vulnerability (CWE-601) exists in the OAuth/OIDC auth ...)
 	TODO: check
 CVE-2026-11966 (The User Registration & Membership  WordPress plugin before 5.2.3 does ...)
@@ -11843,7 +11843,7 @@ CVE-2026-14251 (A flaw was found in the OpenShift GitOps operator. The ClusterRo
 CVE-2026-12997 (The Gravity Forms plugin for WordPress is vulnerable to Directory Trav ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-12382 (A flaw was found in the AAP Gateway Envoy proxy configuration. The non ...)
-	TODO: check
+	NOT-FOR-US: AAP Gateway (Red Hat)
 CVE-2026-10673 (The Zephyr ADIN2111/ADIN1110 10BASE-T1S/T1L Ethernet driver (drivers/e ...)
 	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2025-32781 (Apollo is a reliable configuration management system suitable for micr ...)
@@ -14624,7 +14624,7 @@ CVE-2026-15540 (A vulnerability was detected in SourceCodester Online Book Store
 CVE-2026-14934 (A Missing Authorization vulnerability in the repository creation funct ...)
 	NOT-FOR-US: Google Cloud BigQuery, Dataform and Colab Enterprise
 CVE-2026-14906 (Pages with malicious titles could potentially allow saved PDF content  ...)
-	TODO: check
+	NOT-FOR-US: Firefox for iOS
 CVE-2026-14846 (In version 8.2.1 of PrestaShop, there is a vulnerability relating to t ...)
 	NOT-FOR-US: PrestaShop
 CVE-2026-14453 (This vulnerability is a critical Server-Side Template Injection (SSTI) ...)
@@ -16358,7 +16358,7 @@ CVE-2026-13011 (The ERP: Complete HR, Accounting & CRM Suite with Recruitment an
 CVE-2026-12879 (An Improper Input Validation vulnerability in BigQuery DAO in Google C ...)
 	NOT-FOR-US: Google Cloud Apigee
 CVE-2026-12593 (The implementation of an internalandundocumentedDashboardAPI endpoint( ...)
-	TODO: check
+	NOT-FOR-US: QT Axivion
 CVE-2026-12590 (Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 ( ...)
 	TODO: check
 CVE-2026-12433 (The Hydra Booking \u2013 Appointment Scheduling & Booking Calendar plu ...)
@@ -17329,7 +17329,7 @@ CVE-2026-22927 (Omnissa Workspace ONE\xae Tunnel for Windows addresses a   Local
 CVE-2026-15067 (Snowflake Terraform Provider versions prior to 2.18.0 contain several  ...)
 	NOT-FOR-US: Snowflake Terraform Provider
 CVE-2026-15063 (A flaw was found in the gorch service template, which is part of the t ...)
-	TODO: check
+	NOT-FOR-US: Red Hat OpenShift AI (RHOAI)
 CVE-2026-15062 (SQL injection vulnerabilities in the Snowflake Snowpark Python SDK (sn ...)
 	NOT-FOR-US: Snowflake Snowpark Python SDK
 CVE-2026-15053 (Tanium addressed a denial of service vulnerability in Tanium Server.)
@@ -17349,7 +17349,7 @@ CVE-2026-15036 (A vulnerability was determined in Harness up to 2.28.2. This vul
 CVE-2026-15035 (A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the  ...)
 	NOT-FOR-US: bentoml OpenLLM
 CVE-2026-15034 (A vulnerability has been found in flask-dashboard Flask-MonitoringDash ...)
-	TODO: check
+	NOT-FOR-US: Flask-MonitoringDashboard
 CVE-2026-15033 (A flaw has been found in christopherthielen check-peer-dependencies up ...)
 	NOT-FOR-US: christopherthielen check-peer-dependencies
 CVE-2026-14967 (BBOT's `github_workflows` module could be induced to write a downloade ...)
@@ -98020,7 +98020,7 @@ CVE-2026-26002 (Open OnDemand is an open-source high-performance computing porta
 CVE-2026-25750 (Langchain Helm Charts are Helm charts for deploying Langchain applicat ...)
 	NOT-FOR-US: Langchain Helm Charts
 CVE-2026-25702 (A Improper Access Control vulnerability in the kernel of SUSE SUSE Lin ...)
-	TODO: check
+	NOT-FOR-US: SUSE
 CVE-2026-24963 (Incorrect Privilege Assignment vulnerability in ameliabooking Amelia a ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-24960 (Unrestricted Upload of File with Dangerous Type vulnerability in zozot ...)
@@ -100715,7 +100715,7 @@ CVE-2026-25746 (OpenEMR is a free and open source electronic health records and
 CVE-2026-25743 (OpenEMR is a free and open source electronic health records and medica ...)
 	NOT-FOR-US: OpenEMR
 CVE-2026-25701 (An Insecure Temporary File vulnerability in openSUSE sdbootutil allows ...)
-	TODO: check
+	NOT-FOR-US: openSUSE sdbootutil package
 CVE-2026-25554 (OpenSIPS versions 3.1 before 3.6.4 containing the auth_jwt module (pri ...)
 	NOT-FOR-US: OpenSIPS
 CVE-2026-25476 (OpenEMR is a free and open source electronic health records and medica ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/daeb62a2ca83b78d76aa8059f174df70c230fe64

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/daeb62a2ca83b78d76aa8059f174df70c230fe64
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260726/412fea49/attachment.htm>


More information about the debian-security-tracker-commits mailing list