[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Mar 6 09:48:14 GMT 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d4af56dd by Moritz Muehlenhoff at 2026-03-06T10:47:58+01:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,7 @@
+CVE-2026-3234
+	- libapache2-mod-cluster <itp> (bug #731410)
+CVE-2026-2603
+	- keycloak <itp> (bug #1088287)
 CVE-2026-2092
 	- keycloak <itp> (bug #1088287)
 CVE-2026-3616 (A vulnerability was detected in DefaultFuction Jeson Customer Relation ...)
@@ -65,19 +69,19 @@ CVE-2026-29059 (Windmill is an open-source developer platform for internal code:
 CVE-2026-29058 (AVideo is a video-sharing Platform software. Prior to version 7.0, an  ...)
 	NOT-FOR-US: AVideo
 CVE-2026-29049 (melange allows users to build apk packages using declarative pipelines ...)
-	TODO: check
+	NOT-FOR-US: melange
 CVE-2026-29048 (HumHub is an Open Source Enterprise Social Network. In version 1.18.0, ...)
-	TODO: check
+	NOT-FOR-US: HumHub
 CVE-2026-29046 (TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Pri ...)
-	TODO: check
+	NOT-FOR-US: TinyWeb
 CVE-2026-29042 (Nuclio is a "Serverless" framework for Real-Time Events and Data Proce ...)
-	TODO: check
+	NOT-FOR-US: Nuclio
 CVE-2026-29041 (Chamilo is a learning management system. Prior to version 1.11.34, Cha ...)
-	TODO: check
+	NOT-FOR-US: Chamilo LMS
 CVE-2026-29039 (changedetection.io is a free open source web page change detection too ...)
-	TODO: check
+	NOT-FOR-US: changedetection.io
 CVE-2026-29038 (changedetection.io is a free open source web page change detection too ...)
-	TODO: check
+	NOT-FOR-US: changedetection.io
 CVE-2026-28804 (pypdf is a free and open-source pure-python PDF library. Prior to vers ...)
 	TODO: check
 CVE-2026-28802 (Authlib is a Python library which builds OAuth and OpenID Connect serv ...)
@@ -89,13 +93,13 @@ CVE-2026-28800 (Natro Macro is an open-source Bee Swarm Simulator macro written
 CVE-2026-28799 (PJSIP is a free and open source multimedia communication library writt ...)
 	TODO: check
 CVE-2026-28795 (OpenChatBI is an intelligent chat-based BI tool powered by large langu ...)
-	TODO: check
+	NOT-FOR-US: OpenChatBI
 CVE-2026-28794 (oRPC is an tool that helps build APIs that are end-to-end type-safe an ...)
 	TODO: check
 CVE-2026-28787 (OneUptime is a solution for monitoring and managing online services. I ...)
 	TODO: check
 CVE-2026-28785 (Ghostfolio is an open source wealth management software. Prior to vers ...)
-	TODO: check
+	NOT-FOR-US: Ghostfolio
 CVE-2026-28727 (Local privilege escalation due to insecure Unix socket permissions. Th ...)
 	NOT-FOR-US: Acronis
 CVE-2026-28726 (Sensitive information disclosure due to improper access control. The f ...)
@@ -317,19 +321,19 @@ CVE-2025-70948 (A host header injection vulnerability in the mailer component of
 CVE-2025-70614 (OpenCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contain ...)
 	TODO: check
 CVE-2025-59544 (Chamilo is a learning management system. Prior to version 1.11.34, the ...)
-	TODO: check
+	NOT-FOR-US: Chamilo LMS
 CVE-2025-59543 (Chamilo is a learning management system. Prior to version 1.11.34, the ...)
-	TODO: check
+	NOT-FOR-US: Chamilo LMS
 CVE-2025-59542 (Chamilo is a learning management system. Prior to version 1.11.34, the ...)
-	TODO: check
+	NOT-FOR-US: Chamilo LMS
 CVE-2025-59541 (Chamilo is a learning management system. Prior to version 1.11.34, a C ...)
-	TODO: check
+	NOT-FOR-US: Chamilo LMS
 CVE-2025-59540 (Chamilo is a learning management system. Prior to version 1.11.34, a s ...)
-	TODO: check
+	NOT-FOR-US: Chamilo LMS
 CVE-2025-55289 (Chamilo is a learning management system. Prior to version 1.11.34, the ...)
-	TODO: check
+	NOT-FOR-US: Chamilo LMS
 CVE-2025-55208 (Chamilo is a learning management system. Versions prior to 1.11.34 hav ...)
-	TODO: check
+	NOT-FOR-US: Chamilo LMS
 CVE-2025-30413 (Credentials are not deleted from Acronis Agent after plan revocation.  ...)
 	NOT-FOR-US: Acronis
 CVE-2025-11792 (Local privilege escalation due to DLL hijacking vulnerability. The fol ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d4af56ddce64f105627aea551ec7101a8035699d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d4af56ddce64f105627aea551ec7101a8035699d
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260306/6806b7db/attachment.htm>


More information about the debian-security-tracker-commits mailing list