[Git][security-tracker-team/security-tracker][master] 3 commits: auto-nfu: Add additional product for the Apache CNA rule
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Jul 26 14:56:55 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
830b7e58 by Salvatore Bonaccorso at 2026-07-26T15:54:48+02:00
auto-nfu: Add additional product for the Apache CNA rule
- - - - -
ade75961 by Salvatore Bonaccorso at 2026-07-26T15:55:49+02:00
auto-nfu: Add some additional products for Eclipse CNA rule
- - - - -
302e9962 by Salvatore Bonaccorso at 2026-07-26T15:56:28+02:00
Process some NFUs
- - - - -
2 changed files:
- data/CVE/list
- data/packages/nfu.yaml
Changes:
=====================================
data/CVE/list
=====================================
@@ -1776,7 +1776,7 @@ CVE-2026-49744 (Kernel software installed and running inside a Guest VM may post
CVE-2026-49743 (Software installed and run as a non-privileged user may conduct improp ...)
NOT-FOR-US: Imagination Technologies
CVE-2026-49326 (Missing Authorization vulnerability in Apache HBase thrift and rest de ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-48037 (Hulumi is an open-source toolkit that ships secure-by-default cloud an ...)
NOT-FOR-US: Hulumi
CVE-2026-48036 (Hulumi is an open-source toolkit that ships secure-by-default cloud an ...)
@@ -1845,7 +1845,7 @@ CVE-2026-15755 (The Open User Map \u2013 Interactive Leaflet Maps plugin for Wor
CVE-2026-15739 (The Rich Showcase for Google Reviews plugin for WordPress is vulnerabl ...)
NOT-FOR-US: WordPress plugin
CVE-2026-15704 (In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABA ...)
- TODO: check
+ NOT-FOR-US: Eclipse
CVE-2026-15665 (The Fluent Support \u2013 Helpdesk & Customer Support Ticket System pl ...)
NOT-FOR-US: WordPress plugin
CVE-2026-15663 (The Ninja Forms \u2013 The Contact Form Builder That Grows With You pl ...)
@@ -13834,7 +13834,7 @@ CVE-2026-12707 (Summary Cloudflare quiche was discovered to be vulnerable to
CVE-2026-12659 (A denial-of-service security issue exists in the affected products. Th ...)
NOT-FOR-US: Rockwell Automation
CVE-2026-12606 (Eclipse Grizzly in versions before 5.0.2, cannot properly parse the tr ...)
- TODO: check
+ NOT-FOR-US: Eclipse
CVE-2026-12588 (An attacker with access to an HX 10.0.0 and previous versions, may sen ...)
NOT-FOR-US: Trellix
CVE-2026-12523 (Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulne ...)
@@ -24352,7 +24352,7 @@ CVE-2026-12856 (A flaw was found in the vscode-java extension, which provides Ja
CVE-2026-12672
REJECTED
CVE-2026-12616 (The /v1/upload/sbom endpoint extracts the iss claim from the attacker- ...)
- TODO: check
+ NOT-FOR-US: Eclipse
CVE-2026-11979 (libxml2 is vulnerable to multiple stack-based buffer overflows in the ...)
- libxml2 <unfixed> (unimportant)
NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1124
=====================================
data/packages/nfu.yaml
=====================================
@@ -357,6 +357,7 @@
- product: Apache Fory
- product: Apache Geode
- product: Apache Gravitino
+ - product: Apache HBase
- product: Apache Helix REST
- product: Apache HertzBeat
- product: Apache HertzBeat (incubating)
@@ -453,7 +454,10 @@
- anyOf:
- product: Eclipse 4diac
- product: Eclipse BaSyx
+ - product: Eclipse BaSyx Go Components
+ - product: Eclipse CSI - PIA
- product: Eclipse Cyclone DDS
+ - product: Eclipse GlassFish
- product: Eclipse Glassfish
- product: Eclipse KUKSA - Databroker
- product: Eclipse Kura
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/49da3580b34b4a34d846a6184acadfb8c85a0e13...302e9962a7be88177cc75fa35c16f9f7ffdc656d
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/49da3580b34b4a34d846a6184acadfb8c85a0e13...302e9962a7be88177cc75fa35c16f9f7ffdc656d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260726/ea7d3892/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list