[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu May 7 10:07:05 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d4cb9013 by Salvatore Bonaccorso at 2026-05-07T11:06:11+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -208,23 +208,23 @@ CVE-2026-40982 (Spring Cloud Config allows applications to serve arbitrary text
 CVE-2026-40981 (When using Google Secrets Manager as a backend for the Spring Cloud Co ...)
 	TODO: check
 CVE-2026-40332 (Masa CMS is affected by an Open Redirect vulnerability due to improper ...)
-	TODO: check
+	NOT-FOR-US: Masa CMS
 CVE-2026-40326 (Masa CMS is a content management system forked from Mura CMS. In versi ...)
-	TODO: check
+	NOT-FOR-US: Masa CMS
 CVE-2026-40325 (Masa CMS is a content management system forked from Mura CMS. In versi ...)
-	TODO: check
+	NOT-FOR-US: Masa CMS
 CVE-2026-40309 (Masa CMS is a content management system forked from Mura CMS. In versi ...)
-	TODO: check
+	NOT-FOR-US: Masa CMS
 CVE-2026-40296 (PhpSpreadsheet is a pure PHP library for reading and writing spreadshe ...)
-	TODO: check
+	NOT-FOR-US: PhpSpreadsheet
 CVE-2026-40281 (Gotenberg is a Docker-powered stateless API for PDF files. In versions ...)
-	TODO: check
+	NOT-FOR-US: Gotenberg
 CVE-2026-40174 (Masa CMS is a content management system forked from Mura CMS. In versi ...)
-	TODO: check
+	NOT-FOR-US: Masa CMS
 CVE-2026-40171 (In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions  ...)
 	TODO: check
 CVE-2026-40076 (OpenMRS Core is an open source electronic medical record system platfo ...)
-	TODO: check
+	NOT-FOR-US: OpenMRS
 CVE-2026-40004 (There exists an openssl.cnf privilege escalation vulnerability in ZTE  ...)
 	NOT-FOR-US: ZTE
 CVE-2026-40003 (ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d4cb901314f71b02d72fe31837285beb0aa63edb

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d4cb901314f71b02d72fe31837285beb0aa63edb
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260507/ca76cba8/attachment.htm>


More information about the debian-security-tracker-commits mailing list