[Git][security-tracker-team/security-tracker][master] 3 commits: auto-nfu: Add additional product for the Apache CNA rule

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Jul 26 14:56:55 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
830b7e58 by Salvatore Bonaccorso at 2026-07-26T15:54:48+02:00
auto-nfu: Add additional product for the Apache CNA rule

- - - - -
ade75961 by Salvatore Bonaccorso at 2026-07-26T15:55:49+02:00
auto-nfu: Add some additional products for Eclipse CNA rule

- - - - -
302e9962 by Salvatore Bonaccorso at 2026-07-26T15:56:28+02:00
Process some NFUs

- - - - -


2 changed files:

- data/CVE/list
- data/packages/nfu.yaml


Changes:

=====================================
data/CVE/list
=====================================
@@ -1776,7 +1776,7 @@ CVE-2026-49744 (Kernel software installed and running inside a Guest VM may post
 CVE-2026-49743 (Software installed and run as a non-privileged user may conduct improp ...)
 	NOT-FOR-US: Imagination Technologies
 CVE-2026-49326 (Missing Authorization vulnerability in Apache HBase thrift and rest de ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-48037 (Hulumi is an open-source toolkit that ships secure-by-default cloud an ...)
 	NOT-FOR-US: Hulumi
 CVE-2026-48036 (Hulumi is an open-source toolkit that ships secure-by-default cloud an ...)
@@ -1845,7 +1845,7 @@ CVE-2026-15755 (The Open User Map \u2013 Interactive Leaflet Maps plugin for Wor
 CVE-2026-15739 (The Rich Showcase for Google Reviews plugin for WordPress is vulnerabl ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-15704 (In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABA ...)
-	TODO: check
+	NOT-FOR-US: Eclipse
 CVE-2026-15665 (The Fluent Support \u2013 Helpdesk & Customer Support Ticket System pl ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-15663 (The Ninja Forms \u2013 The Contact Form Builder That Grows With You pl ...)
@@ -13834,7 +13834,7 @@ CVE-2026-12707 (Summary    Cloudflare quiche was discovered to be vulnerable to
 CVE-2026-12659 (A denial-of-service security issue exists in the affected products. Th ...)
 	NOT-FOR-US: Rockwell Automation
 CVE-2026-12606 (Eclipse Grizzly in versions before 5.0.2, cannot properly parse the tr ...)
-	TODO: check
+	NOT-FOR-US: Eclipse
 CVE-2026-12588 (An attacker with access to an HX 10.0.0 and previous versions, may sen ...)
 	NOT-FOR-US: Trellix
 CVE-2026-12523 (Summary    Cloudflare quiche's HTTP/3 layer was discovered to be vulne ...)
@@ -24352,7 +24352,7 @@ CVE-2026-12856 (A flaw was found in the vscode-java extension, which provides Ja
 CVE-2026-12672
 	REJECTED
 CVE-2026-12616 (The /v1/upload/sbom endpoint extracts the iss claim from the attacker- ...)
-	TODO: check
+	NOT-FOR-US: Eclipse
 CVE-2026-11979 (libxml2 is vulnerable to multiple stack-based buffer overflows in the  ...)
 	- libxml2 <unfixed> (unimportant)
 	NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1124


=====================================
data/packages/nfu.yaml
=====================================
@@ -357,6 +357,7 @@
       - product: Apache Fory
       - product: Apache Geode
       - product: Apache Gravitino
+      - product: Apache HBase
       - product: Apache Helix REST
       - product: Apache HertzBeat
       - product: Apache HertzBeat (incubating)
@@ -453,7 +454,10 @@
     - anyOf:
       - product: Eclipse 4diac
       - product: Eclipse BaSyx
+      - product: Eclipse BaSyx Go Components
+      - product: Eclipse CSI - PIA
       - product: Eclipse Cyclone DDS
+      - product: Eclipse GlassFish
       - product: Eclipse Glassfish
       - product: Eclipse KUKSA - Databroker
       - product: Eclipse Kura



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/49da3580b34b4a34d846a6184acadfb8c85a0e13...302e9962a7be88177cc75fa35c16f9f7ffdc656d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/49da3580b34b4a34d846a6184acadfb8c85a0e13...302e9962a7be88177cc75fa35c16f9f7ffdc656d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260726/ea7d3892/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list