[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Jul 30 21:25:49 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
27064b5a by Salvatore Bonaccorso at 2026-07-30T22:25:23+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,73 +1,73 @@
 CVE-2026-9322 (IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Applic ...)
 	NOT-FOR-US: IBM
 CVE-2026-7849 (Due to improper neutralization of special elements, an unauthenticated ...)
-	TODO: check
+	NOT-FOR-US: Phoenix Contact
 CVE-2026-6540 (Calico's Application Layer Policy (disabled by default), which enforce ...)
-	TODO: check
+	NOT-FOR-US: Calico
 CVE-2026-67596 (CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak e ...)
-	TODO: check
+	NOT-FOR-US: CSL 1010 M2M 3G WiFi Module firmware
 CVE-2026-67351 (Serendipity before 2.6.1 contains an authentication context confusion  ...)
 	TODO: check
 CVE-2026-67349 (OpenCost before 1.121.0 fails to authenticate the GET /helmValues endp ...)
-	TODO: check
+	NOT-FOR-US: OpenCost
 CVE-2026-67348 (Julep contains an insecure direct object reference vulnerability in th ...)
-	TODO: check
+	NOT-FOR-US: Julep
 CVE-2026-67347 (Vendure through 3.7.1, fixed in commit f67ef5f, contains a cross-chann ...)
-	TODO: check
+	NOT-FOR-US: Vendure
 CVE-2026-67346 (Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side  ...)
-	TODO: check
+	NOT-FOR-US: Swarms
 CVE-2026-67345 (MaxKey through 4.1.12, fixed in commit ddbb72f, contains an insufficie ...)
-	TODO: check
+	NOT-FOR-US: Dromara MaxKey
 CVE-2026-66416 (Leantime 3.6.2 contains a cross-site request forgery vulnerability tha ...)
-	TODO: check
+	NOT-FOR-US: Leantime
 CVE-2026-66415 (Leantime 3.6.2 contains a server-side request forgery and local file i ...)
-	TODO: check
+	NOT-FOR-US: Leantime
 CVE-2026-66414 (Leantime 3.6.2 contains an open redirect vulnerability in the Login co ...)
-	TODO: check
+	NOT-FOR-US: Leantime
 CVE-2026-65635 (Improper Isolation or Compartmentalization vulnerability in malach-it  ...)
-	TODO: check
+	NOT-FOR-US: malach-it boruta (Elixir.Boruta.Openid module)
 CVE-2026-64870 (MaxKB is an open-source AI assistant for enterprise. In versions 2.0.0 ...)
-	TODO: check
+	NOT-FOR-US: MaxKB
 CVE-2026-62663 (Banks generates meaningful LLM prompts using a simple template languag ...)
-	TODO: check
+	NOT-FOR-US: Banks
 CVE-2026-61536 (Banks generates meaningful LLM prompts using a simple template languag ...)
-	TODO: check
+	NOT-FOR-US: Banks
 CVE-2026-5582 (The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Fo ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-5219 (Cross-Site request forgery (CSRF) vulnerability in Softtr Information  ...)
-	TODO: check
+	NOT-FOR-US: E-Commerce Pack
 CVE-2026-59881 (AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...)
 	TODO: check
 CVE-2026-59310 (VMware vCenter contains a directory traversal vulnerability in the Sys ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-59309 (VMware vCenter contains an authentication bypass vulnerability in the  ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-57862 (Kanboard 1.2.52 and prior contains a server-side request forgery vulne ...)
 	TODO: check
 CVE-2026-57859 (e107 prior to version 2.3.8 contains a code execution vulnerability in ...)
-	TODO: check
+	NOT-FOR-US: e107
 CVE-2026-56428 (The SSH service on BSH ELP (Electronic Platform) modules contains a pl ...)
 	NOT-FOR-US: Bosch
 CVE-2026-54885 (Server-Side Request Forgery vulnerability in malach-it Boruta allows a ...)
-	TODO: check
+	NOT-FOR-US: malach-it Boruta
 CVE-2026-54722 (DSSRF is a Node.js library that provides a wide range of utilities and ...)
-	TODO: check
+	NOT-FOR-US: DSSRF
 CVE-2026-54522 (MessagePack for Ruby is an implementation of the MessagePack binary se ...)
 	TODO: check
 CVE-2026-54368 (CentreStack before 17.4 contains a SQL injection vulnerability in Glad ...)
-	TODO: check
+	NOT-FOR-US: CentreStack
 CVE-2026-54367 (CentreStack before 17.2 contains an authentication bypass vulnerabilit ...)
-	TODO: check
+	NOT-FOR-US: CentreStack
 CVE-2026-54366 (CentreStack before 17.4 contains an XML external entity (XXE) injectio ...)
-	TODO: check
+	NOT-FOR-US: CentreStack
 CVE-2026-54365 (CentreStack before 17.3 contains an unauthenticated deserialization vu ...)
-	TODO: check
+	NOT-FOR-US: CentreStack
 CVE-2026-54364 (CentreStack before 17.4 contains a session variable injection vulnerab ...)
-	TODO: check
+	NOT-FOR-US: CentreStack
 CVE-2026-54363 (CentreStack before 17.5 contains a hardcoded cryptographic key vulnera ...)
-	TODO: check
+	NOT-FOR-US: CentreStack
 CVE-2026-53431 (Authentication Bypass by Capture-replay vulnerability in malach-it Bor ...)
-	TODO: check
+	NOT-FOR-US: malach-it Boruta
 CVE-2026-51295 (SQLite 3.41 is vulnerable to use after free in the jsonExtractFunc fun ...)
 	TODO: check
 CVE-2026-51294 (SQLite 3.41 is vulnerable to use after free in the jsonArrayLengthFunc ...)
@@ -81,61 +81,61 @@ CVE-2026-51291 (sqlite 3.41 is vulnerable to use after free in the json.c jsonCa
 CVE-2026-51290 (SQLite 3.41 has a use-after-free vulnerability in the shared cache loc ...)
 	TODO: check
 CVE-2026-51272 (In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vul ...)
-	TODO: check
+	NOT-FOR-US: schreibfaul1 ESP32-audioI2S
 CVE-2026-4978 (Improper neutralization of special elements used in an SQL command ('S ...)
-	TODO: check
+	NOT-FOR-US: Traffic Analysis System
 CVE-2026-48910 (A carefully crafted editing request could trigger an XSS vulnerability ...)
 	TODO: check
 CVE-2026-48499 (Activepieces is an open source AI workflow automation platform. Prior  ...)
-	TODO: check
+	NOT-FOR-US: Activepieces
 CVE-2026-47876 (VMware ESX contains an out-of-bounds write vulnerability in the VMXNET ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-44108 (Due to a flaw in the execution order of scripts during shutdown, the f ...)
-	TODO: check
+	NOT-FOR-US: Phoenix Contact
 CVE-2026-44107 (A reboot of the charging controller can be triggered via Modbus TCP wi ...)
-	TODO: check
+	NOT-FOR-US: Phoenix Contact
 CVE-2026-44106 (A privilege escalation vulnerability in the init-script for user-appli ...)
-	TODO: check
+	NOT-FOR-US: Phoenix Contact
 CVE-2026-44105 (The credentials for the local user "user-app" may be exposed in log fi ...)
-	TODO: check
+	NOT-FOR-US: Phoenix Contact
 CVE-2026-44104 (The firmware update process for the basemodule of the charging control ...)
-	TODO: check
+	NOT-FOR-US: Phoenix Contact
 CVE-2026-44103 (An unauthenticated remote attacker can inject malicious firmware into  ...)
-	TODO: check
+	NOT-FOR-US: Phoenix Contact
 CVE-2026-44102 (An unauthenticated remote attacker can trigger a firmware update downl ...)
-	TODO: check
+	NOT-FOR-US: Phoenix Contact
 CVE-2026-44101 (Due to missing authentication the CHARX OCPP Agent service allows an u ...)
-	TODO: check
+	NOT-FOR-US: Phoenix Contact
 CVE-2026-44100 (The CHARX JupiCore service allows an unauthenticated remote attacker t ...)
-	TODO: check
+	NOT-FOR-US: Phoenix Contact
 CVE-2026-44099 (A privilege escalation vulnerability in the system configuration allow ...)
-	TODO: check
+	NOT-FOR-US: Phoenix Contact
 CVE-2026-44098 (This vulnerability allows an unauthenticated remote attacker with cont ...)
-	TODO: check
+	NOT-FOR-US: Phoenix Contact
 CVE-2026-44097 (A low-privileged remote attacker with "operator" access can upload arb ...)
-	TODO: check
+	NOT-FOR-US: Phoenix Contact
 CVE-2026-44096 (A privilege escalation vulnerability in udhcpc allows a local user "ch ...)
-	TODO: check
+	NOT-FOR-US: Phoenix Contact
 CVE-2026-44095 (A privilege escalation vulnerability in a script used for network conf ...)
-	TODO: check
+	NOT-FOR-US: Phoenix Contact
 CVE-2026-44094 (An unauthenticated remote attacker can enforce the system to fall back ...)
-	TODO: check
+	NOT-FOR-US: Phoenix Contact
 CVE-2026-44093 (A local privilege escalation vulnerability in the init-script for user ...)
-	TODO: check
+	NOT-FOR-US: Phoenix Contact
 CVE-2026-44092 (An unauthenticated remote attacker can inject malicious input into the ...)
-	TODO: check
+	NOT-FOR-US: Phoenix Contact
 CVE-2026-44091 (An unauthenticated remote attacker can post a malicious ID to the MQTT ...)
-	TODO: check
+	NOT-FOR-US: Phoenix Contact
 CVE-2026-44090 (Due to missing authentication, an unauthenticated remote attacker may  ...)
-	TODO: check
+	NOT-FOR-US: Phoenix Contact
 CVE-2026-41709 (VMware ESX contains an insufficient logging vulnerability.A malicious  ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-41703 (VMware ESX,Workstation, and Fusioncontain an out-of-bounds read vulner ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-41187 (Calico's apiserver wraps tier-scoped resources so that every operation ...)
-	TODO: check
+	NOT-FOR-US: Calico
 CVE-2026-41186 (When Calico's shared debug server is enabled (disabled by default), th ...)
-	TODO: check
+	NOT-FOR-US: Calico
 CVE-2026-28814 (Arbitrary Wiki Markup rendering due to lack of authentication in Apach ...)
 	TODO: check
 CVE-2026-28813 (Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which l ...)
@@ -153,21 +153,21 @@ CVE-2026-22621 (Improper input validation in one of the session management inter
 CVE-2026-22620 (Improper input validation in the authentication component ofEaton's Tr ...)
 	NOT-FOR-US: Eaton
 CVE-2026-18382 (A flaw was found in koku-metrics-operator. The operator's CostManageme ...)
-	TODO: check
+	NOT-FOR-US: koku-metrics-operator
 CVE-2026-18381 (A flaw was found in the koku-metrics-operator for Red Hat OpenShift. T ...)
-	TODO: check
+	NOT-FOR-US: koku-metrics-operator
 CVE-2026-18378 (A flaw was found in koku-metrics-operator. The operator's CostManageme ...)
-	TODO: check
+	NOT-FOR-US: koku-metrics-operator
 CVE-2026-18369 (A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 chal ...)
 	TODO: check
 CVE-2026-18363 (A logic vulnerability in the password reset token validation routine i ...)
-	TODO: check
+	NOT-FOR-US: osTicket
 CVE-2026-18362 (The IRIS web application in version 2.4.26 and possibly others does no ...)
-	TODO: check
+	NOT-FOR-US: IRIS web application
 CVE-2026-18361 (The IRIS web application in version 2.4.26 and possibly others is vuln ...)
-	TODO: check
+	NOT-FOR-US: IRIS web application
 CVE-2026-18360 (The IRIS web application in version 2.4.26 and possibly others is vuln ...)
-	TODO: check
+	NOT-FOR-US: IRIS web application
 CVE-2026-18353 (PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and checks  ...)
 	NOT-FOR-US: Eclipse
 CVE-2026-18245 (Improper control of code generation in Amazon @aws-amplify/codegen-ui- ...)
@@ -175,29 +175,29 @@ CVE-2026-18245 (Improper control of code generation in Amazon @aws-amplify/codeg
 CVE-2026-18140 (Uncontrolled recursion in the unknown-key skip path of the aws-smithy- ...)
 	NOT-FOR-US: Amazon
 CVE-2026-16971 (The IRIS web application in version 2.4.26 and possibly others does no ...)
-	TODO: check
+	NOT-FOR-US: IRIS web application
 CVE-2026-16970 (The IRIS web application in version 2.4.26 and possibly others contain ...)
-	TODO: check
+	NOT-FOR-US: IRIS web application
 CVE-2026-16969 (The IRIS web application in version 2.4.26 and possibly others is vuln ...)
-	TODO: check
+	NOT-FOR-US: IRIS web application
 CVE-2026-16308 (IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1  ...)
 	NOT-FOR-US: IBM
 CVE-2026-15978 (SGLang contains a model weight exfiltration vulnerability when no API  ...)
-	TODO: check
+	NOT-FOR-US: SGLang
 CVE-2026-15977 (SGLang contains a credential leakage vulnerability in the /server_info ...)
-	TODO: check
+	NOT-FOR-US: SGLang
 CVE-2026-15976 (SGLang contains a RCE vulnerability when attempting to load model weig ...)
-	TODO: check
+	NOT-FOR-US: SGLang
 CVE-2026-15974 (SGLang contains an SSRF and local file read in the multimodal generati ...)
-	TODO: check
+	NOT-FOR-US: SGLang
 CVE-2026-15971 (SGLang contains an RCE vulnerability when the optional dumper subsyste ...)
-	TODO: check
+	NOT-FOR-US: SGLang
 CVE-2026-15969 (SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tens ...)
-	TODO: check
+	NOT-FOR-US: SGLang
 CVE-2026-15658 (A vulnerability in the foreUP customer REST API allows any authenticat ...)
-	TODO: check
+	NOT-FOR-US: foreUP customer REST API
 CVE-2026-15657 (A vulnerability in the foreUP customer REST API allows any authenticat ...)
-	TODO: check
+	NOT-FOR-US: foreUP customer REST API
 CVE-2026-15435 (IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 thr ...)
 	NOT-FOR-US: IBM
 CVE-2026-15397 (The Subscriptions for WooCommerce plugin for WordPress is vulnerable t ...)
@@ -231,7 +231,7 @@ CVE-2026-12940 (IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthen
 CVE-2026-12733 (IBM DataPower Gateway could allow a remote attacker to cause a denial  ...)
 	NOT-FOR-US: IBM
 CVE-2026-12722 (Missing authentication for critical function vulnerability in FTC Soft ...)
-	TODO: check
+	NOT-FOR-US: FTC E-Commerce Management Panel
 CVE-2026-12118 (IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unaut ...)
 	NOT-FOR-US: IBM
 CVE-2026-11980 (IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code e ...)
@@ -1731,7 +1731,7 @@ CVE-2026-13306 (Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulner
 CVE-2026-13305 (Autel MaxiCharger AC Elite Home Software Update Improper Verification  ...)
 	NOT-FOR-US: Autel
 CVE-2026-13268 (G DATA Total Security Backup Service Link Following Local Privilege Es ...)
-	TODO: check
+	NOT-FOR-US: G DATA
 CVE-2026-13178 (The Eventin  WordPress plugin before 4.1.16 does not properly authoriz ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-13145 (The WP Travel  WordPress plugin before 11.8.1 does not verify that the ...)
@@ -1747,7 +1747,7 @@ CVE-2026-12500 (The WP Travel Engine  WordPress plugin before 6.8.2 does not per
 CVE-2026-12436 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-12357 (Heimdall Data Database Proxy generateFileContent CRLF Injection Remote ...)
-	TODO: check
+	NOT-FOR-US: Heimdall
 CVE-2026-11881 (The Fluent Forms  WordPress plugin before 6.2.6 does not sanitise and  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-11870 (The WP Ghost (Hide My WP Ghost)  WordPress plugin before 7.0.05 does n ...)
@@ -1757,15 +1757,15 @@ CVE-2026-11867 (The Frontend Admin by DynamiApps WordPress plugin before 3.29.7
 CVE-2026-11782 (The Points and Rewards for WooCommerce WordPress plugin before 2.10.1  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2025-69949 (kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injecti ...)
-	TODO: check
+	NOT-FOR-US: kishan0725 Hospital Management System
 CVE-2025-69945 (kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injecti ...)
-	TODO: check
+	NOT-FOR-US: kishan0725 Hospital Management System
 CVE-2025-69944 (kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injecti ...)
-	TODO: check
+	NOT-FOR-US: kishan0725 Hospital Management System
 CVE-2025-69943 (kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injectio ...)
-	TODO: check
+	NOT-FOR-US: kishan0725 Hospital Management System
 CVE-2025-69942 (kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injecti ...)
-	TODO: check
+	NOT-FOR-US: kishan0725 Hospital Management System
 CVE-2025-67408 (Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to  ...)
 	NOT-FOR-US: SourceCodester
 CVE-2025-67407 (Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to  ...)
@@ -1779,7 +1779,7 @@ CVE-2025-67404 (Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerab
 CVE-2025-67403 (Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to  ...)
 	NOT-FOR-US: SourceCodester
 CVE-2025-65340 (kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injecti ...)
-	TODO: check
+	NOT-FOR-US: kishan0725 Hospital Management System
 CVE-2025-65337 (Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross Site Scri ...)
 	NOT-FOR-US: SourceCodester
 CVE-2025-14562 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/27064b5af6cdc145a7598c9611edd89f2e02828c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/27064b5af6cdc145a7598c9611edd89f2e02828c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260730/f49006ae/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list