[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Jul 29 22:47:49 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
eb9863a5 by Salvatore Bonaccorso at 2026-07-29T23:47:19+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -256,9 +256,9 @@ CVE-2026-55995 (A Double Free vulnerability in open-iscsi allows anunauthenticat
 CVE-2026-54735 (Prebid Server is an open-source solution for running real-time adverti ...)
 	NOT-FOR-US: Prebid Server
 CVE-2026-54727 (proot-distro is a utility for managing proot containers. Prior to vers ...)
-	TODO: check
+	NOT-FOR-US: proot-distro
 CVE-2026-54705 (MathLive provides web components for math display and input. Prior to  ...)
-	TODO: check
+	NOT-FOR-US: MathLive
 CVE-2026-54693 (ZITADEL is an open source identity management platform. From 2.43.0 th ...)
 	NOT-FOR-US: Zitadel
 CVE-2026-54680 (Logging operator automates the deployment and configuration of Kuberne ...)
@@ -276,7 +276,7 @@ CVE-2026-54661 (swagger-typescript-api generates API clients for Fetch or Axios
 CVE-2026-54660 (swagger-typescript-api generates API clients for Fetch or Axios from O ...)
 	NOT-FOR-US: swagger-typescript-api
 CVE-2026-54574 (proot-distro is a utility for managing proot containers. Prior to vers ...)
-	TODO: check
+	NOT-FOR-US: proot-distro
 CVE-2026-54082 (veraPDF validation model is an implementation of the veraPDF validatio ...)
 	NOT-FOR-US: veraPDF
 CVE-2026-54081 (veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1. ...)
@@ -292,13 +292,13 @@ CVE-2026-52791 (fuse-overlayfs is an implementation of overlayfs in FUSE for roo
 CVE-2026-51992 (SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8  ...)
 	NOT-FOR-US: ClickHouse Server
 CVE-2026-50642 (diff\u2011so\u2011fancy does not properly sanitize non\u2011SGR termin ...)
-	TODO: check
+	NOT-FOR-US: diff-so-fancy
 CVE-2026-50641 (Streamsoft Business Intelligence (BI) stores users' passwords in plain ...)
-	TODO: check
+	NOT-FOR-US: Streamsoft
 CVE-2026-50622 (Description: Missing Authorizationin Apache Atlas. A missing authoriza ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-50558 (Penelope Shell Handler is a post-exploitation shell handler for author ...)
-	TODO: check
+	NOT-FOR-US: Penelope Shell Handler
 CVE-2026-4604 (The Klubraum Membership Request plugin for WordPress is vulnerable to  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-44944 (An Incorrect Authorization vulnerability in open-iscsi allowsunprivili ...)
@@ -306,7 +306,7 @@ CVE-2026-44944 (An Incorrect Authorization vulnerability in open-iscsi allowsunp
 CVE-2026-44943 (An Improper Limitation of a Pathname to a Restricted Directory ('Path  ...)
 	TODO: check
 CVE-2026-41939 (Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vuln ...)
-	TODO: check
+	NOT-FOR-US: Care Everywhere Gateway
 CVE-2026-41920 (Improper Access Control vulnerability in Apache Traffic Server.  This  ...)
 	TODO: check
 CVE-2026-40272 (Improper Input Validation in the decode() function of the traceparser  ...)
@@ -316,7 +316,7 @@ CVE-2026-35226 (An out\u2011of\u2011bounds write vulnerability in the CODESYS PR
 CVE-2026-33930 (Apache Traffic Server copies the client Host header into a fixed-size  ...)
 	TODO: check
 CVE-2026-33385 (A Blind SQL injection vulnerability has been identified in Quick.CMS.  ...)
-	TODO: check
+	NOT-FOR-US: Quick.CMS
 CVE-2026-33267 (Improper Input Validation vulnerability in Apache Traffic Server.  Thi ...)
 	TODO: check
 CVE-2026-2482 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 i ...)
@@ -328,13 +328,13 @@ CVE-2026-23904 (Kyuubi Engine UI proxy accepts a host and port from the request
 CVE-2026-22068 (Regular Expression without Anchors vulnerability in Apache Traffic Ser ...)
 	TODO: check
 CVE-2026-20316 (A vulnerability in the web interface of Cisco Secure Firewall Manageme ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-18257 (Improper validity period check for root issuer certificate in CycloneC ...)
-	TODO: check
+	NOT-FOR-US: S2OPC library
 CVE-2026-18255 (A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_U ...)
-	TODO: check
+	NOT-FOR-US: Quay
 CVE-2026-18236 (A vulnerability in the Agent Development Kit (ADK) allows for continua ...)
-	TODO: check
+	NOT-FOR-US: adk-python
 CVE-2026-18220 (An out-of-bounds write vulnerability was found in the BFD library's DL ...)
 	TODO: check
 CVE-2026-18207 (A flaw was found in the client policy enforcement mechanism of Keycloa ...)
@@ -342,17 +342,17 @@ CVE-2026-18207 (A flaw was found in the client policy enforcement mechanism of K
 CVE-2026-18201 (Keycloak provides a way to manage identity providers and organizations ...)
 	TODO: check
 CVE-2026-18197 (Improper neutralization of input during web page generation ('cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress link library
 CVE-2026-18192 (VIN-DS783E-E6 developed by Vacron has an Arbitrary File Read vulnerabi ...)
-	TODO: check
+	NOT-FOR-US: Vacron
 CVE-2026-18191 (VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerabi ...)
-	TODO: check
+	NOT-FOR-US: Vacron
 CVE-2026-18174 (@fastify/forwarded resolves client addresses from the X-Forwarded-For  ...)
-	TODO: check
+	NOT-FOR-US: fastify/forwarded
 CVE-2026-17550 (A maliciously crafted DWG or DXF file, when parsed through Autodesk Au ...)
 	NOT-FOR-US: Autodesk
 CVE-2026-16751 (Authorization Bypass in the emergency recovery approval component in E ...)
-	TODO: check
+	NOT-FOR-US: Ente Technologies Ente Museum Server
 CVE-2026-16729 (undici's setCookie function does not fully sanitize cookie attributes. ...)
 	TODO: check
 CVE-2026-16655 (The Fluent Forms \u2013 Customizable Contact Forms, Survey, Quiz, & Co ...)
@@ -360,19 +360,19 @@ CVE-2026-16655 (The Fluent Forms \u2013 Customizable Contact Forms, Survey, Quiz
 CVE-2026-16597 (The GTM4WP \u2013 A Google Tag Manager (GTM) plugin for WordPress plug ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-16543 (Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allo ...)
-	TODO: check
+	NOT-FOR-US: Kong Kubernetes Ingress Controller (KIC)
 CVE-2026-16465 (A maliciously crafted DWG or DXF file, when parsed through Autodesk Au ...)
 	NOT-FOR-US: Autodesk
 CVE-2026-16463 (A maliciously crafted DXF file, when parsed through Autodesk AutoCAD,  ...)
 	NOT-FOR-US: Autodesk
 CVE-2026-16328 (In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how  ...)
-	TODO: check
+	NOT-FOR-US: consul-mcp-server
 CVE-2026-16326 (In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isol ...)
-	TODO: check
+	NOT-FOR-US: consul-mcp-server
 CVE-2026-15228 (Kong Kubernetes Ingress Controller (KIC) allows a user with namespace- ...)
-	TODO: check
+	NOT-FOR-US: Kong Kubernetes Ingress Controller (KIC)
 CVE-2026-15144 (@fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verba ...)
-	TODO: check
+	NOT-FOR-US: fastify/rate-limit
 CVE-2026-14900 (The Cost Calculator Builder PRO plugin for WordPress is vulnerable to  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-14529 (IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Applic ...)
@@ -384,7 +384,7 @@ CVE-2026-14354 (CWE-522 Insufficiently Protected Credentials vulnerability exist
 CVE-2026-14270 (The Extra Checkout Options (addon for Extra Product Options & Add-Ons  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-13723 (A vulnerability in the `zipx.Unzip` extraction routine of Develar's ap ...)
-	TODO: check
+	NOT-FOR-US: Develar app-builder
 CVE-2026-13697 (undici's cache interceptor mishandles malformed Cache-Control private  ...)
 	TODO: check
 CVE-2026-13425 (The Database for CF7 plugin for WordPress is vulnerable to Stored Cros ...)
@@ -396,7 +396,7 @@ CVE-2026-12935 (The TL-WR940N v6 router contains a vulnerability in its RTSP con
 CVE-2026-12927 (CWE-787 Out-of-bounds write vulnerability exists that could cause loss ...)
 	NOT-FOR-US: Schneider Electric
 CVE-2026-12895 (SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frapp ...)
-	TODO: check
+	NOT-FOR-US: Frappe ERPNext
 CVE-2026-12703 (TeamViewer Full Client and Hostfor macOS before version 15.80containa  ...)
 	NOT-FOR-US: TeamViewer
 CVE-2026-11973 (The WP-Lister Lite for eBay plugin for WordPress is vulnerable to gene ...)
@@ -406,7 +406,7 @@ CVE-2026-10684 (In subsys/debug/coredump/coredump_shell.c, print_coredump_hdr()
 CVE-2026-0667 (CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerab ...)
 	NOT-FOR-US: Schneider Electric
 CVE-2025-60931 (An Insecure Direct Object Reference (IDOR) in the Employee Compensatio ...)
-	TODO: check
+	NOT-FOR-US: Infor Global HR
 CVE-2025-10656 (The Spreadsheet Price Changer for WooCommerce and WP E-commerce \u2013 ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-64560 (In the Linux kernel, the following vulnerability has been resolved:  p ...)
@@ -562,7 +562,7 @@ CVE-2026-17162 (The WowStore \u2013 Store Builder & Product Blocks for WooCommer
 CVE-2026-17161 (The WowStore \u2013 Store Builder & Product Blocks for WooCommerce plu ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-16581 (In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclus ...)
-	TODO: check
+	NOT-FOR-US: igloohome Smart Lock Mobile App
 CVE-2026-16347 (MikroTik RouterOS contains a weakness in its API authentication handli ...)
 	NOT-FOR-US: MikroTik
 CVE-2026-16192 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 i ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eb9863a59c5cc102264368b0b40f7c7bb0ed3f5e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eb9863a59c5cc102264368b0b40f7c7bb0ed3f5e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260729/98b840a5/attachment.htm>


More information about the debian-security-tracker-commits mailing list