[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Jul 29 21:43:22 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
662a5a78 by Salvatore Bonaccorso at 2026-07-29T22:43:00+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
 CVE-2026-9720 (The Facturaci\xf3n Electr\xf3nica Costa Rica plugin for WordPress is v ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-9177 (A Server-Side Template Injection (SSTI) vulnerability was identified   ...)
-	TODO: check
+	NOT-FOR-US: Axway
 CVE-2026-8791 (The Booking System Trafft plugin for WordPress is vulnerable to Stored ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-8497 (Improper certificate validation in the Devolutions Server connection h ...)
@@ -15,17 +15,17 @@ CVE-2026-7436 (The WPC Badge Management for WooCommerce plugin for WordPress is
 CVE-2026-6089 (The WP CTA plugin for WordPress is vulnerable to Server-Side Request F ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-67429 (Flyto2 Core is an execution kernel for automation and AI-agent workflo ...)
-	TODO: check
+	NOT-FOR-US: Flyto2 Core
 CVE-2026-67428 (Flyto2 Core is an execution kernel for automation and AI-agent workflo ...)
-	TODO: check
+	NOT-FOR-US: Flyto2 Core
 CVE-2026-67427 (Flyto2 Core is an execution kernel for automation and AI-agent workflo ...)
-	TODO: check
+	NOT-FOR-US: Flyto2 Core
 CVE-2026-67426 (Flyto2 Core is an execution kernel for automation and AI-agent workflo ...)
-	TODO: check
+	NOT-FOR-US: Flyto2 Core
 CVE-2026-67425 (Flyto2 Core is an execution kernel for automation and AI-agent workflo ...)
-	TODO: check
+	NOT-FOR-US: Flyto2 Core
 CVE-2026-67424 (Flyto2 Core is an execution kernel for automation and AI-agent workflo ...)
-	TODO: check
+	NOT-FOR-US: Flyto2 Core
 CVE-2026-67217 (cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomic ...)
 	TODO: check
 CVE-2026-67216 (cJSON through 1.7.19 contains an inefficient algorithmic complexity fl ...)
@@ -41,19 +41,19 @@ CVE-2026-67201 (V through 0.5.2, fixed in commit 85859f0, contains a server-side
 CVE-2026-67194 (Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow a ...)
 	TODO: check
 CVE-2026-67193 (Xlight FTP Server before 3.9.5 contains an information disclosure vuln ...)
-	TODO: check
+	NOT-FOR-US: Xlight FTP Server
 CVE-2026-67192 (Xlight FTP Server before 3.9.5 contains a pre-authentication stack buf ...)
-	TODO: check
+	NOT-FOR-US: Xlight FTP Server
 CVE-2026-67191 (Xlight FTP Server before 3.9.5 contains a pre-authentication heap buff ...)
-	TODO: check
+	NOT-FOR-US: Xlight FTP Server
 CVE-2026-67188
 	REJECTED
 CVE-2026-66737
 	REJECTED
 CVE-2026-66724 (MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization ...)
-	TODO: check
+	NOT-FOR-US: MWDB Core
 CVE-2026-66723 (MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization ...)
-	TODO: check
+	NOT-FOR-US: MWDB Core
 CVE-2026-66490 (Joomla Extension - balbooa.com - Stored cross-site scripting via a com ...)
 	NOT-FOR-US: Joomla
 CVE-2026-66489 (Joomla Extension - balbooa.com - Various unauthenticated file system d ...)
@@ -61,7 +61,7 @@ CVE-2026-66489 (Joomla Extension - balbooa.com - Various unauthenticated file sy
 CVE-2026-66488 (Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2)
 	NOT-FOR-US: Joomla
 CVE-2026-66400 (Grav Login Plugin versions before 3.8.13 contain an insufficient sessi ...)
-	TODO: check
+	NOT-FOR-US: Grav Login Plugin
 CVE-2026-66051
 	REJECTED
 CVE-2026-65947 (Joomla Extension - balbooa.com - Various CSRF vectors in the admin int ...)
@@ -107,9 +107,9 @@ CVE-2026-64556 (In the Linux kernel, the following vulnerability has been resolv
 CVE-2026-62995 (joserfc is a Python library that provides an implementation of several ...)
 	TODO: check
 CVE-2026-60113 (AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface befo ...)
-	TODO: check
+	NOT-FOR-US: AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface
 CVE-2026-60112 (AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing aut ...)
-	TODO: check
+	NOT-FOR-US: AMMOS Instrument Toolkit (AIT) GUI
 CVE-2026-5060 (The MasterStudy LMS WordPress Plugin \u2013 for Online Courses and Edu ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-59920 (Netty is an asynchronous, event-driven network application framework.  ...)
@@ -127,7 +127,7 @@ CVE-2026-59898 (Netty is an asynchronous, event-driven network application frame
 CVE-2026-59247 (Insufficient Verification of Data Authenticity vulnerability in Gleam  ...)
 	TODO: check
 CVE-2026-59243 (The FAB auth manager's Azure AD OAuth login defaulted `verify_signatur ...)
-	TODO: check
+	NOT-FOR-US: Apache Airflow FAB provider
 CVE-2026-58189 (Apache Traffic Server allows redirect-limit bypass when plugins reset  ...)
 	TODO: check
 CVE-2026-58188 (Several Apache Traffic Server experimental plugins have memory-safety  ...)
@@ -195,43 +195,43 @@ CVE-2026-56389 (GNU Bison allows for an execution of an arbitrary program during
 CVE-2026-55995 (A Double Free vulnerability in open-iscsi allows anunauthenticatedMITM ...)
 	TODO: check
 CVE-2026-54735 (Prebid Server is an open-source solution for running real-time adverti ...)
-	TODO: check
+	NOT-FOR-US: Prebid Server
 CVE-2026-54727 (proot-distro is a utility for managing proot containers. Prior to vers ...)
 	TODO: check
 CVE-2026-54705 (MathLive provides web components for math display and input. Prior to  ...)
 	TODO: check
 CVE-2026-54693 (ZITADEL is an open source identity management platform. From 2.43.0 th ...)
-	TODO: check
+	NOT-FOR-US: Zitadel
 CVE-2026-54680 (Logging operator automates the deployment and configuration of Kuberne ...)
-	TODO: check
+	NOT-FOR-US: Kubernetes Logging operator
 CVE-2026-54666 (swagger-typescript-api generates API clients for Fetch or Axios from a ...)
-	TODO: check
+	NOT-FOR-US: swagger-typescript-api
 CVE-2026-54664 (swagger-typescript-api generates API clients for Fetch or Axios from a ...)
-	TODO: check
+	NOT-FOR-US: swagger-typescript-api
 CVE-2026-54663 (swagger-typescript-api generates API clients for Fetch or Axios from O ...)
-	TODO: check
+	NOT-FOR-US: swagger-typescript-api
 CVE-2026-54662 (swagger-typescript-api generates API clients for Fetch or Axios from O ...)
-	TODO: check
+	NOT-FOR-US: swagger-typescript-api
 CVE-2026-54661 (swagger-typescript-api generates API clients for Fetch or Axios from a ...)
-	TODO: check
+	NOT-FOR-US: swagger-typescript-api
 CVE-2026-54660 (swagger-typescript-api generates API clients for Fetch or Axios from O ...)
-	TODO: check
+	NOT-FOR-US: swagger-typescript-api
 CVE-2026-54574 (proot-distro is a utility for managing proot containers. Prior to vers ...)
 	TODO: check
 CVE-2026-54082 (veraPDF validation model is an implementation of the veraPDF validatio ...)
-	TODO: check
+	NOT-FOR-US: veraPDF
 CVE-2026-54081 (veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1. ...)
-	TODO: check
+	NOT-FOR-US: veraPDF
 CVE-2026-54080 (veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1. ...)
-	TODO: check
+	NOT-FOR-US: veraPDF
 CVE-2026-54079 (veraPDF validation provides PDF/A and PDF/UA validation, feature repor ...)
-	TODO: check
+	NOT-FOR-US: veraPDF
 CVE-2026-54078 (veraPDF validation model is an implementation of the veraPDF validatio ...)
-	TODO: check
+	NOT-FOR-US: veraPDF
 CVE-2026-52791 (fuse-overlayfs is an implementation of overlayfs in FUSE for rootless  ...)
 	TODO: check
 CVE-2026-51992 (SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8  ...)
-	TODO: check
+	NOT-FOR-US: ClickHouse Server
 CVE-2026-50642 (diff\u2011so\u2011fancy does not properly sanitize non\u2011SGR termin ...)
 	TODO: check
 CVE-2026-50641 (Streamsoft Business Intelligence (BI) stores users' passwords in plain ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/662a5a787ade0ee33c5ef247962e5c336c73e0c3

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/662a5a787ade0ee33c5ef247962e5c336c73e0c3
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260729/f8da34da/attachment.htm>


More information about the debian-security-tracker-commits mailing list