[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Mar 30 08:15:17 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e84ffcde by security tracker role at 2026-03-30T07:15:08+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3,27 +3,27 @@ CVE-2026-5119 (A flaw was found in libsoup. When establishing HTTPS tunnels thro
 CVE-2026-5107 (A vulnerability has been found in FRRouting FRR up to 10.5.1. This aff ...)
 	TODO: check
 CVE-2026-5106 (A flaw has been found in code-projects Exam Form Submission 1.0. The i ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2026-5105 (A vulnerability was detected in Totolink A3300R 17.0.0cu.557_b20221024 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-5104 (A security vulnerability has been detected in Totolink A3300R 17.0.0cu ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-5103 (A weakness has been identified in Totolink A3300R 17.0.0cu.557_b202210 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-5102 (A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b2 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-5101 (A vulnerability was identified in Totolink A3300R 17.0.0cu.557_b202210 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-4946 (Ghidra versions prior to 12.0.3 improperly process annotation directiv ...)
 	TODO: check
 CVE-2026-3124 (The Download Monitor plugin for WordPress is vulnerable to Insecure Di ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-2370 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
 	TODO: check
 CVE-2025-7741 (Hardcoded Password Vulnerability have been found in CENTUM.Affected pr ...)
-	TODO: check
+	NOT-FOR-US: Yokogawa
 CVE-2025-15036 (A path traversal vulnerability exists in the `extract_archive_to_dir`  ...)
-	TODO: check
+	NOT-FOR-US: mlflow
 CVE-2026-33691 [Whitespace padding in filenames bypasses file upload extension checks]
 	- modsecurity-crs 3.3.9-1
 	NOTE: https://github.com/coreruleset/coreruleset/security/advisories/GHSA-rw5f-9w43-gv2w



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e84ffcded9dd356114670204a7bbec7df895446f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e84ffcded9dd356114670204a7bbec7df895446f
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260330/403fa812/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list