[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Jul 30 09:30:52 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
dc65c13e by Salvatore Bonaccorso at 2026-07-30T10:30:20+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -7,27 +7,27 @@ CVE-2026-6336 (GitLab has remediated an issue in GitLab CE/EE affecting all vers
CVE-2026-6267 (GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-6102 (MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalat ...)
- TODO: check
+ NOT-FOR-US: MSI Center
CVE-2026-67595 (VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated Ja ...)
- TODO: check
+ NOT-FOR-US: VaahCMS
CVE-2026-67439 (OliveTin gives safe and simple access to predefined shell commands fro ...)
- TODO: check
+ NOT-FOR-US: OliveTin
CVE-2026-67438 (OliveTin gives access to predefined shell commands from a web interfac ...)
- TODO: check
+ NOT-FOR-US: OliveTin
CVE-2026-67437 (OliveTin gives access to predefined shell commands from a web interfac ...)
- TODO: check
+ NOT-FOR-US: OliveTin
CVE-2026-67436 (Linuxfabrik monitoring-plugins provides Python monitoring plugins for ...)
- TODO: check
+ NOT-FOR-US: Linuxfabrik monitoring-plugins (different from src:monitoring-plugins)
CVE-2026-67435 (linuxfabrik-lib provides Python modules for database access, caching, ...)
- TODO: check
+ NOT-FOR-US: linuxfabrik-lib
CVE-2026-67433 (Linuxfabrik monitoring-plugins provides Python monitoring plugins for ...)
- TODO: check
+ NOT-FOR-US: Linuxfabrik monitoring-plugins (different from src:monitoring-plugins)
CVE-2026-67432 (MCP Ruby SDK is the official Ruby SDK for Model Context Protocol serve ...)
- TODO: check
+ NOT-FOR-US: MCP Ruby SDK
CVE-2026-67431 (MCP Ruby SDK is the official Ruby SDK for Model Context Protocol serve ...)
- TODO: check
+ NOT-FOR-US: MCP Ruby SDK
CVE-2026-67430 (MCP Ruby SDK is the official Ruby SDK for Model Context Protocol serve ...)
- TODO: check
+ NOT-FOR-US: MCP Ruby SDK
CVE-2026-67248 (A stack-based buffer overflow vulnerability was found in the File Expl ...)
NOT-FOR-US: Asustor
CVE-2026-67247 (A path traversal vulnerability was found in the IHM Log handling of AD ...)
@@ -39,17 +39,17 @@ CVE-2026-67245 (A path traversal vulnerability was found in the VPN Clients on t
CVE-2026-67244 (A format string vulnerability was found in the Notification OAuth sett ...)
NOT-FOR-US: Asustor
CVE-2026-65975 (Pydantic AI is a Python agent framework for building applications and ...)
- TODO: check
+ NOT-FOR-US: Pydantic AI
CVE-2026-64685 (ImageMagick is free and open-source software used for editing and mani ...)
- imagemagick 8:7.1.2.27+dfsg1-1
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7rgw-xg25-prjm
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/093f476e985d61557ea75ad0ef30d491dff816f3 (7.1.2-27)
CVE-2026-64635 (Improper handling of the returnUrl parameter in the Forgot Password fu ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2026-63119 (MCP Ruby SDK is the official Ruby SDK for Model Context Protocol serve ...)
- TODO: check
+ NOT-FOR-US: MCP Ruby SDK
CVE-2026-63118 (MCP Ruby SDK is the official Ruby SDK for Model Context Protocol serve ...)
- TODO: check
+ NOT-FOR-US: MCP Ruby SDK
CVE-2026-62946 (ImageMagick is free and open-source software used for editing and mani ...)
- imagemagick 8:7.1.2.27+dfsg1-1
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-h22j-f9xw-xjjm
@@ -66,19 +66,19 @@ CVE-2026-62343 (ImageMagick is free and open-source software used for editing an
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/9acf93f66b0f8495fa222e1a27c3db534cd78864 (7.1.2-26)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/b3a93f501011a8882ec4962dd6db9f0a71e6f050 (6.9.13-51)
CVE-2026-5492 (DriveLock Directory Traversal Information Disclosure Vulnerability. Th ...)
- TODO: check
+ NOT-FOR-US: DriveLock
CVE-2026-5491 (DriveLock Directory Traversal Information Disclosure Vulnerability. Th ...)
- TODO: check
+ NOT-FOR-US: DriveLock
CVE-2026-5490 (DriveLock SQL Injection Privilege Escalation Vulnerability. This vulne ...)
- TODO: check
+ NOT-FOR-US: DriveLock
CVE-2026-5489 (DriveLock Directory Traversal Information Disclosure Vulnerability. Th ...)
- TODO: check
+ NOT-FOR-US: DriveLock
CVE-2026-5487 (DriveLock Directory Traversal Information Disclosure Vulnerability. Th ...)
- TODO: check
+ NOT-FOR-US: DriveLock
CVE-2026-5057 (ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulne ...)
- TODO: check
+ NOT-FOR-US: ATEN
CVE-2026-59952 (Valibot helps validate data using a schema. Versions prior to 1.4.2 ca ...)
- TODO: check
+ NOT-FOR-US: Valibot
CVE-2026-59328 (Spring Tools for Eclipse renders Spring Boot starter wizard dependency ...)
TODO: check
CVE-2026-59327 (Spring Tools for Eclipse stores the Spring Boot DevTools remote secret ...)
@@ -86,9 +86,9 @@ CVE-2026-59327 (Spring Tools for Eclipse stores the Spring Boot DevTools remote
CVE-2026-59326 (The Spring Boot language server logs the raw value of the https_proxy/ ...)
TODO: check
CVE-2026-58066 (Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3 ...)
- TODO: check
+ NOT-FOR-US: Rocket.Chat
CVE-2026-58046 (Improper neutralization in the Plesk XML-RPC API allows a remote authe ...)
- TODO: check
+ NOT-FOR-US: Plesk
CVE-2026-58043 (A flaw in Node.js Permission Model enforcement can over-grant filesyst ...)
TODO: check
CVE-2026-58040 (An incomplete fix has been identified in Node.js: HTTPS Agent TLS sess ...)
@@ -98,9 +98,9 @@ CVE-2026-56850 (A flaw in Node.js HTTPS Agent connection reuse can cause PFX obj
CVE-2026-56847 (A flaw in Node.js Permission Model enforcement allows `trace_events.cr ...)
TODO: check
CVE-2026-54249 (Pydantic AI is a Python agent framework for building Generative AI app ...)
- TODO: check
+ NOT-FOR-US: Pydantic AI
CVE-2026-50782 (Jinher OA C6 contains an XML External Entity (XXE) injection vulnerabi ...)
- TODO: check
+ NOT-FOR-US: Jinher OA
CVE-2026-4672 (GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-48449 (Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization ...)
@@ -114,7 +114,7 @@ CVE-2026-47873 (The Boot Dashboard Docker integration in Spring Tools publishes
CVE-2026-47858 (Starting Spring Boot applications in the Spring Tools with the live in ...)
TODO: check
CVE-2026-46678 (Pydantic AI is a Python agent framework for building Generative AI app ...)
- TODO: check
+ NOT-FOR-US: Pydantic AI
CVE-2026-3093 (GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-1982 (The Persian Elementor (\u0627\u0644\u0645\u0646\u062a\u0648\u0631 \u06 ...)
@@ -122,7 +122,7 @@ CVE-2026-1982 (The Persian Elementor (\u0627\u0644\u0645\u0646\u062a\u0648\u0631
CVE-2026-1360 (The BuddyPress plugin for WordPress is vulnerable to Deserialization o ...)
NOT-FOR-US: WordPress plugin
CVE-2026-18266 (Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability. This ...)
- TODO: check
+ NOT-FOR-US: Dify
CVE-2026-18188 (A format string vulnerability was found in the Rsync Backup on the ADM ...)
NOT-FOR-US: Asustor
CVE-2026-18187 (A format string vulnerability was found in the Internal Backup on the ...)
@@ -1270,7 +1270,7 @@ CVE-2026-16092 (The Improved Save Button plugin for WordPress is vulnerable to s
CVE-2026-15975 (GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-15929 (Improper neutralization of special elements used in an SQL command ('S ...)
- TODO: check
+ NOT-FOR-US: LG
CVE-2026-15831 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-15382 (The Ultimate Addons for WPBakery Page Builder WordPress plugin before ...)
@@ -1340,15 +1340,15 @@ CVE-2026-13344 (The Essential Addons for Elementor WordPress plugin before 6.6.
CVE-2026-13330 (The Animation Addons for Elementor WordPress plugin before 2.7.0 does ...)
NOT-FOR-US: WordPress plugin
CVE-2026-13309 (Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitr ...)
- TODO: check
+ NOT-FOR-US: Autel
CVE-2026-13308 (Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Co ...)
- TODO: check
+ NOT-FOR-US: Autel
CVE-2026-13307 (Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitra ...)
- TODO: check
+ NOT-FOR-US: Autel
CVE-2026-13306 (Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: Autel
CVE-2026-13305 (Autel MaxiCharger AC Elite Home Software Update Improper Verification ...)
- TODO: check
+ NOT-FOR-US: Autel
CVE-2026-13268 (G DATA Total Security Backup Service Link Following Local Privilege Es ...)
TODO: check
CVE-2026-13178 (The Eventin WordPress plugin before 4.1.16 does not properly authoriz ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dc65c13edfecc9cd04c5b294f5623a8024da8652
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dc65c13edfecc9cd04c5b294f5623a8024da8652
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260730/c9e86a77/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list