[Git][security-tracker-team/security-tracker][master] Process two NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat May 23 08:37:14 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4b521b6c by Salvatore Bonaccorso at 2026-05-23T09:34:28+02:00
Process two NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -31,7 +31,7 @@ CVE-2026-41148 (Mermaid is a JavaScript tool that uses Markdown-inspired text to
 	NOTE: Fixed by: https://github.com/mermaid-js/mermaid/commit/e9b0f34d8d82a6260077764ee45e1d7d90957a0f (mermaid at 11.15.0)
 	NOTE: Fixed by: https://github.com/mermaid-js/mermaid/commit/8fead23c59166b7bab6a39eac81acebee2859102 (v10.9.6)
 CVE-2026-41147 (NukeViet CMS is a multi Content Management System. Versions 4.5.07 and ...)
-	TODO: check
+	NOT-FOR-US: NukeViet CMS
 CVE-2026-41104 (Deserialization of untrusted data in Microsoft Planetary Computer Pro  ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-41090 (Improper neutralization of special elements used in a command ('comman ...)
@@ -45,7 +45,7 @@ CVE-2026-41069 (libheif is a HEIF and AVIF file format decoder and encoder. In v
 CVE-2026-40864 (JupyterHub is software that allows users to create a multi-user server ...)
 	TODO: check
 CVE-2026-40610 (BentoML is a Python library for building online serving systems optimi ...)
-	TODO: check
+	NOT-FOR-US: BentoML
 CVE-2026-40607 (Mantis Bug Tracker (MantisBT) is an open source issue tracker. In vers ...)
 	- mantis <removed>
 CVE-2026-40598 (Mantis Bug Tracker (MantisBT) is an open source issue tracker. In vers ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4b521b6cf5aaa57287ca4359b88c4ed748d10b95

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4b521b6cf5aaa57287ca4359b88c4ed748d10b95
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260523/e3e6332c/attachment.htm>


More information about the debian-security-tracker-commits mailing list