[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Jul 29 06:57:45 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
ace661af by Salvatore Bonaccorso at 2026-07-29T07:57:13+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -95,7 +95,7 @@ CVE-2026-66746 (Rouille 0.4.0 through 3.6.2 contains an HTTP response splitting
CVE-2026-66745 (Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 202607 ...)
NOT-FOR-US: Artica Proxy
CVE-2026-66713 (Deserialization of Untrusted Data (CWE-502) in the Tribes-based cluste ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-66299 (Uncontrolled Resource Consumption vulnerability in Apache Tomcat's Web ...)
- tomcat11 <unfixed> (unimportant)
- tomcat10 <unfixed> (unimportant)
@@ -288,7 +288,7 @@ CVE-2026-47726 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh
CVE-2026-47725 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtu ...)
NOT-FOR-US: Nebula Mesh
CVE-2026-47483 (NVIDIA DCGM Exporter for all platforms contains a vulnerability in the ...)
- TODO: check
+ NOT-FOR-US: NVIDIA DCGM Exporter
CVE-2026-47427 (GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the ...)
NOT-FOR-US: GitHub MCP Server
CVE-2026-45293 (WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) ...)
@@ -52763,7 +52763,7 @@ CVE-2026-24193 (NVIDIA Display Driver for Windows and Linux contains a vulnerabi
CVE-2026-24192 (NVIDIA Display Driver for Linux contains a vulnerability where an atta ...)
TODO: check
CVE-2026-24191 (NVIDIA Display Driver for Windows contains a vulnerability where an at ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-24190 (NVIDIA Display Driver for Windows and Linux contains a vulnerability i ...)
TODO: check
CVE-2026-24187 (NVIDIA Display Driver for Linux contains a vulnerability where an atta ...)
@@ -58127,7 +58127,7 @@ CVE-2026-44440 (ERPNext is a free and open source Enterprise Resource Planning t
CVE-2026-44439 (PlaywrightCapture is a simple replacement for splash using playwright. ...)
NOT-FOR-US: PlaywrightCapture
CVE-2026-44437 (The Angular SSR is a server-rise rendering tool for Angular applicatio ...)
- TODO: check
+ NOT-FOR-US: Angular SSR
CVE-2026-44432 (urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7 ...)
- python-urllib3 2.7.0-1 (bug #1136654)
[trixie] - python-urllib3 <not-affected> (Vulnerable code introduced later)
@@ -87543,7 +87543,7 @@ CVE-2026-33413 (etcd is a distributed key-value store for the data of a distribu
CVE-2026-33402 (Sakai is a Collaboration and Learning Environment (CLE). In versions 2 ...)
NOT-FOR-US: Sakai
CVE-2026-33397 (The Angular SSR is a server-rise rendering tool for Angular applicatio ...)
- TODO: check
+ NOT-FOR-US: Angular SSR
CVE-2026-33396 (OneUptime is an open-source monitoring and observability platform. Pri ...)
NOT-FOR-US: OneUptime
CVE-2026-33343 (etcd is a distributed key-value store for the data of a distributed sy ...)
@@ -102530,9 +102530,9 @@ CVE-2026-27795 (LangChain is a framework for building LLM-powered applications.
CVE-2026-27794 (LangGraph Checkpoint defines the base interface for LangGraph checkpoi ...)
NOT-FOR-US: LangGraph Checkpoint
CVE-2026-27739 (The Angular SSR is a server-rise rendering tool for Angular applicatio ...)
- TODO: check
+ NOT-FOR-US: Angular SSR
CVE-2026-27738 (The Angular SSR is a server-rise rendering tool for Angular applicatio ...)
- TODO: check
+ NOT-FOR-US: Angular SSR
CVE-2026-27736 (BigBlueButton is an open-source virtual classroom. In versions on the ...)
NOT-FOR-US: BigBlueButton
CVE-2026-27730 (esm.sh is a no-build content delivery network (CDN) for web developmen ...)
@@ -102546,7 +102546,7 @@ CVE-2026-27706 (Plane is an an open-source project management tool. Prior to ver
CVE-2026-27705 (Plane is an an open-source project management tool. Prior to version 1 ...)
NOT-FOR-US: Plane
CVE-2026-27704 (The Dart and Flutter SDKs provide software development kits for the Da ...)
- TODO: check
+ NOT-FOR-US: Dart and Flutter SDKs
CVE-2026-27702 (Budibase is a low code platform for creating internal tools, workflows ...)
NOT-FOR-US: Budibase
CVE-2026-27701 (LiveCode is an open-source, client-side code playground. Prior to comm ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ace661afaf74c6b53d9b5a6c2e02ecaa9bd8771b
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ace661afaf74c6b53d9b5a6c2e02ecaa9bd8771b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260729/ca695707/attachment.htm>
More information about the debian-security-tracker-commits
mailing list