[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Sep 1 20:57:24 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
9a1e3aa1 by Salvatore Bonaccorso at 2026-09-01T21:56:44+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -13,7 +13,7 @@ CVE-2026-9622 (A denial-of-service security issue exists within RSLinx\xae Class
CVE-2026-9621 (A denial-of-service security issue exists within RSLinx\xae Classic. T ...)
NOT-FOR-US: Rockwell Automation
CVE-2026-8712 (Wyoming before 1.10.2 contains a server-side request forgery vulnerabi ...)
- TODO: check
+ NOT-FOR-US: Wyoming
CVE-2026-84305 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
- sqlparse <unfixed>
NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-cfqr-cjx5-5jcm
@@ -62,71 +62,71 @@ CVE-2026-84235 (A denial-of-service security issue exists in the affected produc
CVE-2026-84233 (A flaw was found in rpm. A local attacker could supply a specially cra ...)
TODO: check
CVE-2026-84232 (A flaw was found in pulpcore's content serving application. Files uplo ...)
- TODO: check
+ NOT-FOR-US: pulpcore
CVE-2026-84218 (A flaw was found in Jolokia's JSR-160 proxy functionality where insuff ...)
- TODO: check
+ NOT-FOR-US: Jolokia
CVE-2026-84207 (Heym before 0.0.98 fails to apply SSRF egress guards to WebSocket Send ...)
- TODO: check
+ NOT-FOR-US: Heym
CVE-2026-84206 (Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the ass ...)
TODO: check
CVE-2026-84205 (GROWI contains an access control vulnerability in the GET /_api/v3/rev ...)
- TODO: check
+ NOT-FOR-US: GROWI
CVE-2026-84204 (GROWI contains an access control vulnerability in the GET /_api/v3/att ...)
- TODO: check
+ NOT-FOR-US: GROWI
CVE-2026-84203 (Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens whe ...)
- TODO: check
+ NOT-FOR-US: Memos
CVE-2026-84202 (ModelScope uses PyYAML's unsafe yaml.Loader to parse model configurati ...)
- TODO: check
+ NOT-FOR-US: ModelScope
CVE-2026-84201 (appium-mcp-server through 0.1.61 fails to validate or normalize file p ...)
- TODO: check
+ NOT-FOR-US: appium-mcp-server
CVE-2026-84200 (Kyverno versions v1.9.0 through v1.12.7 contain a policy exception han ...)
- TODO: check
+ NOT-FOR-US: Kyverno
CVE-2026-84199 (Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vu ...)
- TODO: check
+ NOT-FOR-US: Kyverno
CVE-2026-84196 (Kyverno before 1.18.0 contains a server-side request forgery vulnerabi ...)
- TODO: check
+ NOT-FOR-US: Kyverno
CVE-2026-84195 (Kyverno before 1.16.4 automatically attaches the admission controller' ...)
- TODO: check
+ NOT-FOR-US: Kyverno
CVE-2026-84194 (LibreNMS versions >= 23.10.0 and < 26.2.0 (fixed in 26.4.0) contain an ...)
- TODO: check
+ NOT-FOR-US: LibreNMS
CVE-2026-84193 (LibreNMS through 26.2.0 contains a stored cross-site scripting vulnera ...)
- TODO: check
+ NOT-FOR-US: LibreNMS
CVE-2026-84192 (LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerab ...)
- TODO: check
+ NOT-FOR-US: LibreNMS
CVE-2026-84191 (LibreNMS before 26.5.0 contains stored cross-site scripting vulnerabil ...)
- TODO: check
+ NOT-FOR-US: LibreNMS
CVE-2026-84190 (LibreNMS versions before 26.5.0 contain a remote code execution vulner ...)
- TODO: check
+ NOT-FOR-US: LibreNMS
CVE-2026-84189 (LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, ...)
- TODO: check
+ NOT-FOR-US: LibreNMS
CVE-2026-84188 (LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vuln ...)
- TODO: check
+ NOT-FOR-US: LibreNMS
CVE-2026-84187 (AVideo contains a missing authentication vulnerability in plugin/Live/ ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-84165 (A vulnerability relating to incorrect access control in OpenNebula by ...)
TODO: check
CVE-2026-84153 (A vulnerability was determined in Xinhu Rainrock RockOA up to 2.3.2. T ...)
- TODO: check
+ NOT-FOR-US: Xinhu Rainrock RockOA
CVE-2026-84149 (This vulnerability exists in the ERP system due to exposure of reposit ...)
- TODO: check
+ NOT-FOR-US: Multi-tenant ERP System
CVE-2026-84148 (This vulnerability exists in the ERP system due to improper authentica ...)
- TODO: check
+ NOT-FOR-US: Multi-tenant ERP System
CVE-2026-84147 (This vulnerability exists in the ERP system due to improper authentica ...)
- TODO: check
+ NOT-FOR-US: Multi-tenant ERP System
CVE-2026-84115 (A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected ...)
- TODO: check
+ NOT-FOR-US: Cleo Harmony
CVE-2026-84114 (A vulnerability has been found in Cleo Harmony up to 5.8.1.10. Impacte ...)
- TODO: check
+ NOT-FOR-US: Cleo Harmony
CVE-2026-84111 (A flaw has been found in Chanjet CRM up to 20260707. This issue affect ...)
- TODO: check
+ NOT-FOR-US: Chanjet CRM
CVE-2026-84110 (A vulnerability was detected in Releasit Releasit COD Form & Upsells v ...)
- TODO: check
+ NOT-FOR-US: Releasit Releasit COD Form & Upsells
CVE-2026-84109 (A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.6. A ...)
- TODO: check
+ NOT-FOR-US: Xinhu Rainrock RockOA
CVE-2026-84061 (A security flaw has been discovered in zhongyu09 OpenChatBI up to 0.3. ...)
- TODO: check
+ NOT-FOR-US: zhongyu09 OpenChatBI
CVE-2026-84059 (A flaw has been found in ICP DAS UA-2200 and UA-5200 up to 20260704. T ...)
- TODO: check
+ NOT-FOR-US: ICP DAS UA-2200 and UA-5200
CVE-2026-83619 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) ...)
TODO: check
CVE-2026-83618 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9a1e3aa1d6b2308b2e14b56d304a8eb2570dfdcd
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9a1e3aa1d6b2308b2e14b56d304a8eb2570dfdcd
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260901/c07066de/attachment.htm>
More information about the debian-security-tracker-commits
mailing list