[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Jul 28 21:05:20 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
fe98afbc by Salvatore Bonaccorso at 2026-07-28T22:04:33+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,9 +1,9 @@
CVE-2026-9680 (Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-se ...)
- TODO: check
+ NOT-FOR-US: alibabacloud-rds-openapi-mcp-server
CVE-2026-8167 (Improper neutralization of input during web page generation ('cross-si ...)
- TODO: check
+ NOT-FOR-US: News Theme V8
CVE-2026-8164 (Uncontrolled Search Path Element vulnerability in ArkSigner Software a ...)
- TODO: check
+ NOT-FOR-US: ArkSigner Desktop Client
CVE-2026-8058 (IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060. ...)
NOT-FOR-US: IBM
CVE-2026-7868 (IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060. ...)
@@ -17,37 +17,37 @@ CVE-2026-7521 (Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <=
CVE-2026-7362 (IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 thr ...)
NOT-FOR-US: IBM
CVE-2026-7187 (Missing authentication for critical function vulnerability in Universa ...)
- TODO: check
+ NOT-FOR-US: UKBS
CVE-2026-6879 (`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O ...)
TODO: check
CVE-2026-67185 (TinyWeb through 0.0.8 contains a path traversal vulnerability that all ...)
- TODO: check
+ NOT-FOR-US: TinyWeb
CVE-2026-67184 (TinyWeb through 0.0.8 contains a null pointer dereference vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: TinyWeb
CVE-2026-67183 (TinyWeb through 0.0.8 contains a memory leak vulnerability that allows ...)
- TODO: check
+ NOT-FOR-US: TinyWeb
CVE-2026-67182 (Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnera ...)
TODO: check
CVE-2026-67181 (Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnera ...)
TODO: check
CVE-2026-67178 (MISP installation scripts generated an Apache HTTP virtual-host config ...)
- TODO: check
+ NOT-FOR-US: MISP
CVE-2026-67174 (Pivotick contains a DOM-based cross-site scripting vulnerability in it ...)
- TODO: check
+ NOT-FOR-US: Pivotick
CVE-2026-67173 (Pivotick did not validate the URL scheme of node imagePath values deri ...)
- TODO: check
+ NOT-FOR-US: Pivotick
CVE-2026-66922 (Pivotick used plain JavaScript objects as lookup tables indexed by cal ...)
- TODO: check
+ NOT-FOR-US: Pivotick
CVE-2026-66921 (Pivotick\u2019s Markdown node-reference renderer failed to HTML-escape ...)
- TODO: check
+ NOT-FOR-US: Pivotick
CVE-2026-66920 (Pivotick contains an uncontrolled-recursion vulnerability when process ...)
- TODO: check
+ NOT-FOR-US: Pivotick
CVE-2026-66919 (Pivotick contains a cross-site scripting vulnerability in the inspect ...)
- TODO: check
+ NOT-FOR-US: Pivotick
CVE-2026-66918 (Pivotick fails to sanitize attacker-controlled SVG markup supplied thr ...)
- TODO: check
+ NOT-FOR-US: Pivotick
CVE-2026-66913 (Lookyloo did not enforce limits on the decompressed size of uploaded c ...)
- TODO: check
+ NOT-FOR-US: Lookyloo
CVE-2026-66754 (Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerabili ...)
TODO: check
CVE-2026-66753 (tiny-http through 0.12.0 contains an HTTP header injection vulnerabili ...)
@@ -55,17 +55,17 @@ CVE-2026-66753 (tiny-http through 0.12.0 contains an HTTP header injection vulne
CVE-2026-66752 (tiny-http through 0.12.0 contains an HTTP request smuggling vulnerabil ...)
TODO: check
CVE-2026-66751 (Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vuln ...)
- TODO: check
+ NOT-FOR-US: Let's Chat
CVE-2026-66750 (Let's Chat 0.3.0 through 0.4.8 contains a broken access control vulner ...)
- TODO: check
+ NOT-FOR-US: Let's Chat
CVE-2026-66749 (Let's Chat 0.4.0 through 0.4.8 contains a null dereference vulnerabili ...)
- TODO: check
+ NOT-FOR-US: Let's Chat
CVE-2026-66748 (Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated re ...)
- TODO: check
+ NOT-FOR-US: Camaleon CMS
CVE-2026-66746 (Rouille 0.4.0 through 3.6.2 contains an HTTP response splitting vulner ...)
TODO: check
CVE-2026-66745 (Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 202607 ...)
- TODO: check
+ NOT-FOR-US: Artica Proxy
CVE-2026-66713 (Deserialization of Untrusted Data (CWE-502) in the Tribes-based cluste ...)
TODO: check
CVE-2026-66299 (Uncontrolled Resource Consumption vulnerability in Apache Tomcat's Web ...)
@@ -79,109 +79,109 @@ CVE-2026-65880 (Joomla Extension - balbooa.com - Unauthenticated remote code exe
CVE-2026-65624 (Allocation of Resources Without Limits or Throttling vulnerability in ...)
TODO: check
CVE-2026-63727 (Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an ...)
- TODO: check
+ NOT-FOR-US: Anchore Enterprise
CVE-2026-63303 (A Path Traversal vulnerability exists in Quick.CMS through the URI pat ...)
- TODO: check
+ NOT-FOR-US: Quick.CMS
CVE-2026-63302 (Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php ...)
- TODO: check
+ NOT-FOR-US: Quick.CMS
CVE-2026-63301 (In Quick.CMS, the administrative user interface restricts deletion of ...)
- TODO: check
+ NOT-FOR-US: Quick.CMS
CVE-2026-62828 (Improper input validation in Microsoft Edge for Android allows an unau ...)
NOT-FOR-US: Microsoft
CVE-2026-61609 (Pterodactyl is a free, open-source game server management panel. From ...)
- TODO: check
+ NOT-FOR-US: Pterodactyl
CVE-2026-61487 (Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ...)
TODO: check
CVE-2026-61376 (ELECOM wireless LAN routers and access points devices contain an OS Co ...)
- TODO: check
+ NOT-FOR-US: ELECOM wireless LAN routers
CVE-2026-5114 (The SpeedyCache plugin for WordPress is vulnerable to Arbitrary File R ...)
NOT-FOR-US: WordPress plugin
CVE-2026-59933 (PhpSpreadsheet is a pure PHP library for reading and writing spreadshe ...)
- TODO: check
+ NOT-FOR-US: PhpSpreadsheet
CVE-2026-59932 (PhpSpreadsheet is a pure PHP library for reading and writing spreadshe ...)
- TODO: check
+ NOT-FOR-US: PhpSpreadsheet
CVE-2026-59931 (PhpSpreadsheet is a pure PHP library for reading and writing spreadshe ...)
- TODO: check
+ NOT-FOR-US: PhpSpreadsheet
CVE-2026-59878 (Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apach ...)
TODO: check
CVE-2026-59764 (ELECOM wireless LAN routers and access points devices contain an OS Co ...)
- TODO: check
+ NOT-FOR-US: ELECOM wireless LAN routers
CVE-2026-59248 (Allocation of resources without limits vulnerability in ninenines cowl ...)
TODO: check
CVE-2026-58246 (SAP NetWeaver Application Server for ABAP and ABAP Platform writes sen ...)
NOT-FOR-US: SAP
CVE-2026-55977 (Successful exploitation of this vulnerability could allow an attacker ...)
- TODO: check
+ NOT-FOR-US: EShare
CVE-2026-54635 (pytonapi is a Python SDK for TONAPI that provides REST API, streaming, ...)
- TODO: check
+ NOT-FOR-US: pytonapi
CVE-2026-54620 (sqlite3 provides Ruby bindings for the SQLite3 embedded database. From ...)
TODO: check
CVE-2026-54619 (sqlite3 provides Ruby bindings for the SQLite3 embedded database. In v ...)
TODO: check
CVE-2026-54609 (QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer prot ...)
- TODO: check
+ NOT-FOR-US: QTI Neon
CVE-2026-54605 (OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providin ...)
TODO: check
CVE-2026-54603 (OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frame ...)
TODO: check
CVE-2026-54593 (Pterodactyl is a free, open-source game server management panel. Prior ...)
- TODO: check
+ NOT-FOR-US: Pterodactyl
CVE-2026-54545 (wakaru is a JavaScript decompiler and unminifier toolkit. From 1.0.0 u ...)
- TODO: check
+ NOT-FOR-US: wakaru
CVE-2026-54345 (gopacket provides packet processing capabilities for Go. In version 1. ...)
TODO: check
CVE-2026-54332 (gopacket provides packet processing capabilities for Go. In version 1. ...)
TODO: check
CVE-2026-51275 (In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in ...)
- TODO: check
+ NOT-FOR-US: schreibfaul1 ESP32-audioI2S
CVE-2026-51274 (In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in ...)
- TODO: check
+ NOT-FOR-US: schreibfaul1 ESP32-audioI2S
CVE-2026-51273 (In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vul ...)
- TODO: check
+ NOT-FOR-US: schreibfaul1 ESP32-audioI2S
CVE-2026-51271 (In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vul ...)
- TODO: check
+ NOT-FOR-US: schreibfaul1 ESP32-audioI2S
CVE-2026-51270 (schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vul ...)
- TODO: check
+ NOT-FOR-US: schreibfaul1 ESP32-audioI2S
CVE-2026-51269 (schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vul ...)
- TODO: check
+ NOT-FOR-US: schreibfaul1 ESP32-audioI2S
CVE-2026-51268 (schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vul ...)
- TODO: check
+ NOT-FOR-US: schreibfaul1 ESP32-audioI2S
CVE-2026-51267 (schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vul ...)
- TODO: check
+ NOT-FOR-US: schreibfaul1 ESP32-audioI2S
CVE-2026-51266 (schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vul ...)
- TODO: check
+ NOT-FOR-US: schreibfaul1 ESP32-audioI2S
CVE-2026-51263 (schreibfaul1 ESP32-audioI2S 3.4.5 is vulnerable to Buffer Overflow. Th ...)
- TODO: check
+ NOT-FOR-US: schreibfaul1 ESP32-audioI2S
CVE-2026-51261 (Missing mutex synchronization in AudioBuffer::freeSpace() in schreibfa ...)
- TODO: check
+ NOT-FOR-US: schreibfaul1 ESP32-audioI2S
CVE-2026-51260 (Unsafe fixed-size memcpy operation in AudioBuffer::writeSpace() of sch ...)
- TODO: check
+ NOT-FOR-US: schreibfaul1 ESP32-audioI2S
CVE-2026-51259 (Unchecked unsigned integer overflow in buffer size calculation in schr ...)
- TODO: check
+ NOT-FOR-US: schreibfaul1 ESP32-audioI2S
CVE-2026-51254 (schreibfaul1 ESP32-audioI2S v3.4.5 has an integer underflow vulnerabil ...)
- TODO: check
+ NOT-FOR-US: schreibfaul1 ESP32-audioI2S
CVE-2026-51252 (schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability ...)
- TODO: check
+ NOT-FOR-US: schreibfaul1 ESP32-audioI2S
CVE-2026-51251 (Schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability ...)
- TODO: check
+ NOT-FOR-US: schreibfaul1 ESP32-audioI2S
CVE-2026-50738 (A use-after-free condition exists in pglogical's worker signaling code ...)
- TODO: check
+ NOT-FOR-US: EnterpriseDB pglogical
CVE-2026-50737 (When applying replicated changes for a row that is missing one or more ...)
- TODO: check
+ NOT-FOR-US: EnterpriseDB
CVE-2026-50736 (The pglogical queue mechanism, used to convey out-of-band commands suc ...)
- TODO: check
+ NOT-FOR-US: EnterpriseDB
CVE-2026-50735 (pglogical's apply worker does not sufficiently validate the length of ...)
- TODO: check
+ NOT-FOR-US: EnterpriseDB
CVE-2026-4932 (IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 thro ...)
NOT-FOR-US: IBM
CVE-2026-4912 (The Media Cleaner: Clean your WordPress! plugin for WordPress is vulne ...)
NOT-FOR-US: WordPress plugin
CVE-2026-4648 (Use of an insecure cryptographic algorithm in the cashless payment sys ...)
- TODO: check
+ NOT-FOR-US: CasfID Servicios TEcnologicos S.L.U.
CVE-2026-49332 (A flaw was found in openshift/oauth-proxy. The proxy sets authenticate ...)
- TODO: check
+ NOT-FOR-US: openshift/oauth-proxy
CVE-2026-49258 (Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh V ...)
- TODO: check
+ NOT-FOR-US: Nebula Mesh
CVE-2026-48396 (Bridge is affected by an Incorrect Authorization vulnerability that co ...)
NOT-FOR-US: Adobe
CVE-2026-48395 (Bridge is affected by an Untrusted Search Path vulnerability that coul ...)
@@ -203,27 +203,27 @@ CVE-2026-48374 (Bridge is affected by an Improper Limitation of a Pathname to a
CVE-2026-48372 (Format Plugins is affected by a Heap-based Buffer Overflow vulnerabili ...)
NOT-FOR-US: Adobe
CVE-2026-48058 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtu ...)
- TODO: check
+ NOT-FOR-US: Nebula Mesh
CVE-2026-48025 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtu ...)
- TODO: check
+ NOT-FOR-US: Nebula Mesh
CVE-2026-47768 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtu ...)
- TODO: check
+ NOT-FOR-US: Nebula Mesh
CVE-2026-47726 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtu ...)
- TODO: check
+ NOT-FOR-US: Nebula Mesh
CVE-2026-47725 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtu ...)
- TODO: check
+ NOT-FOR-US: Nebula Mesh
CVE-2026-47483 (NVIDIA DCGM Exporter for all platforms contains a vulnerability in the ...)
TODO: check
CVE-2026-47427 (GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the ...)
- TODO: check
+ NOT-FOR-US: GitHub MCP Server
CVE-2026-45293 (WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) ...)
- TODO: check
+ NOT-FOR-US: WordPress Coding Standards
CVE-2026-44387 (ELECOM wireless LAN routers and access points devices contain a reflec ...)
- TODO: check
+ NOT-FOR-US: ELECOM wireless LAN routers
CVE-2026-43910 (Appium Java Client is the Java language binding for writing Appium tes ...)
- TODO: check
+ NOT-FOR-US: Appium
CVE-2026-41874 (Quick.Cart stores hard-coded, plaintext admin credentials in a configu ...)
- TODO: check
+ NOT-FOR-US: Quick.Cart
CVE-2026-21047 (Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allo ...)
NOT-FOR-US: Samsung Mobile
CVE-2026-18107 (A flaw was found in CRIU's handling of restartable sequences (rseq) du ...)
@@ -235,7 +235,7 @@ CVE-2026-18084 (Improper Neutralization of Input During Web Page Generation vuln
CVE-2026-18047 (A flaw was found in Dogtag PKI's ACME responder where the web.xml secu ...)
TODO: check
CVE-2026-18038 (A flaw has been found in nextlevelbuilder GoClaw up to 3.13.2. Affecte ...)
- TODO: check
+ NOT-FOR-US: nextlevelbuilder GoClaw
CVE-2026-18029 (Our payment integration with GiroCheckout did not properly validate p ...)
NOT-FOR-US: rami.io products
CVE-2026-18028 (The "quick setup" view presented to users after they first create an ...)
@@ -247,13 +247,13 @@ CVE-2026-16774 (The Chatbot plugin for WordPress is vulnerable to Missing Author
CVE-2026-16773 (The WPBot \u2013 AI ChatBot for Live Support, Lead Generation, AI Serv ...)
NOT-FOR-US: WordPress plugin
CVE-2026-16771 (In firmware versions 2.7.7 and earlier, the Arris BGW210\u2011700 gate ...)
- TODO: check
+ NOT-FOR-US: Arris BGW210-700 gateway
CVE-2026-16498 (The terraform-mcp-server before version 1.1.0 is vulnerable to a cross ...)
- TODO: check
+ NOT-FOR-US: terraform-mcp-server
CVE-2026-16496 (The terraform-mcp-server before version 1.1.0 is vulnerable to an auth ...)
- TODO: check
+ NOT-FOR-US: terraform-mcp-server
CVE-2026-16462 (In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitiz ...)
- TODO: check
+ NOT-FOR-US: PROCON-WEB SCADA
CVE-2026-16313 (A flaw was found in sg3_utils. The sg_inq command, when invoked with t ...)
TODO: check
CVE-2026-15992 (The WP Password Policy plugin for WordPress is vulnerable to Privilege ...)
@@ -283,7 +283,7 @@ CVE-2026-15016 (The Paid Memberships Pro \u2013 Content Restriction, User Regist
CVE-2026-15014 (The SMS Alert \u2013 SMS & OTP for WooCommerce, Order Notifications & ...)
NOT-FOR-US: WordPress plugin
CVE-2026-14869 (The terraform-mcp-server before version 1.1.0 is vulnerable to a serve ...)
- TODO: check
+ NOT-FOR-US: terraform-mcp-server
CVE-2026-14785 (The Web Directory Free plugin for WordPress is vulnerable to generic S ...)
NOT-FOR-US: WordPress plugin
CVE-2026-14516 (The Online Scheduling and Appointment Booking System \u2013 Bookly plu ...)
@@ -291,15 +291,15 @@ CVE-2026-14516 (The Online Scheduling and Appointment Booking System \u2013 Book
CVE-2026-14328 (The Eazy Plugin Manager \u2013 Powerful Plugin Management Solution for ...)
NOT-FOR-US: WordPress plugin
CVE-2026-14171 (An unauthenticated remote attacker can abuse the improper validation o ...)
- TODO: check
+ NOT-FOR-US: ads-tec Industrial IT
CVE-2026-14170
REJECTED
CVE-2026-14169 (Due to incorrect behavior order a low privileged remote attacker could ...)
- TODO: check
+ NOT-FOR-US: ads-tec Industrial IT
CVE-2026-14168 (A low privileged remote attacker can gain administrator privileges due ...)
- TODO: check
+ NOT-FOR-US: ads-tec Industrial IT
CVE-2026-14167 (A low privileged remote attacker can perform privileged configuration ...)
- TODO: check
+ NOT-FOR-US: ads-tec Industrial IT
CVE-2026-13440 (The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, ...)
NOT-FOR-US: WordPress plugin
CVE-2026-13161 (The TrueBooker \u2013 Appointment Booking and Scheduler System plugin ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fe98afbc40b9254be41ed0b0d6600f8c1f0768f6
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fe98afbc40b9254be41ed0b0d6600f8c1f0768f6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260728/d868f98e/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list