[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Jun 10 21:59:14 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c82d848b by Salvatore Bonaccorso at 2026-06-10T22:58:45+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -165,61 +165,61 @@ CVE-2026-48556
 CVE-2026-48096 (OpenFGA is an authorization/permission engine built for developers. Pr ...)
 	NOT-FOR-US: OpenFGA
 CVE-2026-46642 (draw.io is a configurable diagramming and whiteboarding application. P ...)
-	TODO: check
+	NOT-FOR-US: jgraph/drawio
 CVE-2026-46618 (Fission is an open-source, Kubernetes-native serverless framework that ...)
-	TODO: check
+	NOT-FOR-US: Fission
 CVE-2026-46617 (Fission is an open-source, Kubernetes-native serverless framework that ...)
-	TODO: check
+	NOT-FOR-US: Fission
 CVE-2026-46616 (Umbraco is an ASP.NET CMS. Prior to versions 13.14.0 and 17.4.0, some  ...)
 	NOT-FOR-US: Umbraco CMS
 CVE-2026-46614 (Fission is an open-source, Kubernetes-native serverless framework that ...)
-	TODO: check
+	NOT-FOR-US: Fission
 CVE-2026-46612 (Fission is an open-source, Kubernetes-native serverless framework that ...)
-	TODO: check
+	NOT-FOR-US: Fission
 CVE-2026-46609 (Umbraco is an ASP.NET CMS. From version 14.0.0 to before version 17.4. ...)
 	NOT-FOR-US: Umbraco CMS
 CVE-2026-46558 (Plane is an open-source project management tool. Prior to version 1.3. ...)
-	TODO: check
+	NOT-FOR-US: Plane
 CVE-2026-46497 (Crawlee is a web scraping and browser automation library. From version ...)
 	TODO: check
 CVE-2026-45569 (Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Kee ...)
-	TODO: check
+	NOT-FOR-US: Roxy-WI
 CVE-2026-45567 (Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Kee ...)
-	TODO: check
+	NOT-FOR-US: Roxy-WI
 CVE-2026-45566 (Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Kee ...)
-	TODO: check
+	NOT-FOR-US: Roxy-WI
 CVE-2026-45565 (Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Kee ...)
-	TODO: check
+	NOT-FOR-US: Roxy-WI
 CVE-2026-45564 (Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Kee ...)
-	TODO: check
+	NOT-FOR-US: Roxy-WI
 CVE-2026-45563 (Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Kee ...)
-	TODO: check
+	NOT-FOR-US: Roxy-WI
 CVE-2026-45561 (Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Kee ...)
-	TODO: check
+	NOT-FOR-US: Roxy-WI
 CVE-2026-45560 (Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Kee ...)
-	TODO: check
+	NOT-FOR-US: Roxy-WI
 CVE-2026-45559 (Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Kee ...)
-	TODO: check
+	NOT-FOR-US: Roxy-WI
 CVE-2026-45558 (Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Kee ...)
-	TODO: check
+	NOT-FOR-US: Roxy-WI
 CVE-2026-45556 (Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Kee ...)
-	TODO: check
+	NOT-FOR-US: Roxy-WI
 CVE-2026-45552 (Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Kee ...)
-	TODO: check
+	NOT-FOR-US: Roxy-WI
 CVE-2026-45550 (Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Kee ...)
-	TODO: check
+	NOT-FOR-US: Roxy-WI
 CVE-2026-45549 (Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Kee ...)
-	TODO: check
+	NOT-FOR-US: Roxy-WI
 CVE-2026-45062 (FrankenPHP is a modern application server for PHP. From version 1.11.2 ...)
-	TODO: check
+	NOT-FOR-US: FrankenPHP
 CVE-2026-3018 (The Newsletters plugin for WordPress is vulnerable to time-based SQL I ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-25700 (Improper Restriction of Security Token Assignment vulnerability in Apa ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-24067 (Slate Digital Connect 1.37.0 for macOS installs a privileged helper to ...)
-	TODO: check
+	NOT-FOR-US: Slate Digital Connect
 CVE-2026-24066 (Slate Digital Connect 1.37.0 for macOS installs a privileged helper to ...)
-	TODO: check
+	NOT-FOR-US: Slate Digital Connect
 CVE-2026-20260 (In Splunk SOAR (Security Orchestration, Automation, and Response) vers ...)
 	NOT-FOR-US: Cisco
 CVE-2026-20259 (In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Clou ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c82d848b8008194022aa8d54cfcc579a39802890

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c82d848b8008194022aa8d54cfcc579a39802890
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260610/00796aea/attachment.htm>


More information about the debian-security-tracker-commits mailing list