[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Jul 30 20:14:26 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5236899e by security tracker role at 2026-07-30T19:14:20+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,5 +1,5 @@
 CVE-2026-9322 (IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Applic ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-7849 (Due to improper neutralization of special elements, an unauthenticated ...)
 	TODO: check
 CVE-2026-6540 (Calico's Application Layer Policy (disabled by default), which enforce ...)
@@ -33,7 +33,7 @@ CVE-2026-62663 (Banks generates meaningful LLM prompts using a simple template l
 CVE-2026-61536 (Banks generates meaningful LLM prompts using a simple template languag ...)
 	TODO: check
 CVE-2026-5582 (The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Fo ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-5219 (Cross-Site request forgery (CSRF) vulnerability in Softtr Information  ...)
 	TODO: check
 CVE-2026-59881 (AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...)
@@ -47,7 +47,7 @@ CVE-2026-57862 (Kanboard 1.2.52 and prior contains a server-side request forgery
 CVE-2026-57859 (e107 prior to version 2.3.8 contains a code execution vulnerability in ...)
 	TODO: check
 CVE-2026-56428 (The SSH service on BSH ELP (Electronic Platform) modules contains a pl ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2026-54885 (Server-Side Request Forgery vulnerability in malach-it Boruta allows a ...)
 	TODO: check
 CVE-2026-54722 (DSSRF is a Node.js library that provides a wide range of utilities and ...)
@@ -145,13 +145,13 @@ CVE-2026-28812 (UserManager lack of checks allows impersonation in Apache JSPWik
 CVE-2026-28811 (Debug Messages Revealing Unnecessary Information in Apache JSPWiki up  ...)
 	TODO: check
 CVE-2026-28323 (SolarWinds Web Help Desk is found to be affected by a SAML authenticat ...)
-	TODO: check
+	NOT-FOR-US: SolarWinds
 CVE-2026-22622 (Improper input validation in one of the session management interface o ...)
-	TODO: check
+	NOT-FOR-US: Eaton
 CVE-2026-22621 (Improper input validation in one of the session management interface o ...)
-	TODO: check
+	NOT-FOR-US: Eaton
 CVE-2026-22620 (Improper input validation in the authentication component ofEaton's Tr ...)
-	TODO: check
+	NOT-FOR-US: Eaton
 CVE-2026-18382 (A flaw was found in koku-metrics-operator. The operator's CostManageme ...)
 	TODO: check
 CVE-2026-18381 (A flaw was found in the koku-metrics-operator for Red Hat OpenShift. T ...)
@@ -169,11 +169,11 @@ CVE-2026-18361 (The IRIS web application in version 2.4.26 and possibly others i
 CVE-2026-18360 (The IRIS web application in version 2.4.26 and possibly others is vuln ...)
 	TODO: check
 CVE-2026-18353 (PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and checks  ...)
-	TODO: check
+	NOT-FOR-US: Eclipse
 CVE-2026-18245 (Improper control of code generation in Amazon @aws-amplify/codegen-ui- ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-18140 (Uncontrolled recursion in the unknown-key skip path of the aws-smithy- ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-16971 (The IRIS web application in version 2.4.26 and possibly others does no ...)
 	TODO: check
 CVE-2026-16970 (The IRIS web application in version 2.4.26 and possibly others contain ...)
@@ -181,7 +181,7 @@ CVE-2026-16970 (The IRIS web application in version 2.4.26 and possibly others c
 CVE-2026-16969 (The IRIS web application in version 2.4.26 and possibly others is vuln ...)
 	TODO: check
 CVE-2026-16308 (IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-15978 (SGLang contains a model weight exfiltration vulnerability when no API  ...)
 	TODO: check
 CVE-2026-15977 (SGLang contains a credential leakage vulnerability in the /server_info ...)
@@ -199,75 +199,75 @@ CVE-2026-15658 (A vulnerability in the foreUP customer REST API allows any authe
 CVE-2026-15657 (A vulnerability in the foreUP customer REST API allows any authenticat ...)
 	TODO: check
 CVE-2026-15435 (IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 thr ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-15397 (The Subscriptions for WooCommerce plugin for WordPress is vulnerable t ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14980 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 i ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-14522 (IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 thr ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-14519 (IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 thr ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-14227 (An API session\u2011management flaw in products with the MikroTik Rout ...)
-	TODO: check
+	NOT-FOR-US: MikroTik
 CVE-2026-13584 (Improper Enforcement of Message Integrity During Transmission in a Com ...)
-	TODO: check
+	NOT-FOR-US: Mitsubishi
 CVE-2026-13444 (IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-13435 (IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input valid ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-13379 (The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 al ...)
 	TODO: check
 CVE-2026-12947 (IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 thr ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-12945 (IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to ac ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-12943 (IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 thro ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-12942 (IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-12940 (IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticate ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-12733 (IBM DataPower Gateway could allow a remote attacker to cause a denial  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-12722 (Missing authentication for critical function vulnerability in FTC Soft ...)
 	TODO: check
 CVE-2026-12118 (IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unaut ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-11980 (IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code e ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-11904 (IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-11897 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 i ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-11885 (IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-11707 (IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-11383 (IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-10842 (IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Applic ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-10700 (IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access c ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-10695 (IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a deni ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-10545 (IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-10535 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2025-36431 (IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2025-36374 (IBM DataPower Gateway is vulnerable to an XML external entity injectio ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2025-36298 (IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2025-0152 (IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7 ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2024-40683 (IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3 ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2024-25039 (IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7 ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-60075 (Date::Manip versions through 6.99 for Perl allow CPU exhaustion via qu ...)
 	- libdate-manip-perl <unfixed> (bug #1143125)
 	[trixie] - libdate-manip-perl <no-dsa> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5236899e23a0ee5eaae7cbebdb9e3e131876f1e9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5236899e23a0ee5eaae7cbebdb9e3e131876f1e9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260730/21281101/attachment.htm>


More information about the debian-security-tracker-commits mailing list