[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Sep 1 20:57:24 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9a1e3aa1 by Salvatore Bonaccorso at 2026-09-01T21:56:44+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -13,7 +13,7 @@ CVE-2026-9622 (A denial-of-service security issue exists within RSLinx\xae Class
 CVE-2026-9621 (A denial-of-service security issue exists within RSLinx\xae Classic. T ...)
 	NOT-FOR-US: Rockwell Automation
 CVE-2026-8712 (Wyoming before 1.10.2 contains a server-side request forgery vulnerabi ...)
-	TODO: check
+	NOT-FOR-US: Wyoming
 CVE-2026-84305 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
 	- sqlparse <unfixed>
 	NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-cfqr-cjx5-5jcm
@@ -62,71 +62,71 @@ CVE-2026-84235 (A denial-of-service security issue exists in the affected produc
 CVE-2026-84233 (A flaw was found in rpm. A local attacker could supply a specially cra ...)
 	TODO: check
 CVE-2026-84232 (A flaw was found in pulpcore's content serving application. Files uplo ...)
-	TODO: check
+	NOT-FOR-US: pulpcore
 CVE-2026-84218 (A flaw was found in Jolokia's JSR-160 proxy functionality where insuff ...)
-	TODO: check
+	NOT-FOR-US: Jolokia
 CVE-2026-84207 (Heym before 0.0.98 fails to apply SSRF egress guards to WebSocket Send ...)
-	TODO: check
+	NOT-FOR-US: Heym
 CVE-2026-84206 (Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the ass ...)
 	TODO: check
 CVE-2026-84205 (GROWI contains an access control vulnerability in the GET /_api/v3/rev ...)
-	TODO: check
+	NOT-FOR-US: GROWI
 CVE-2026-84204 (GROWI contains an access control vulnerability in the GET /_api/v3/att ...)
-	TODO: check
+	NOT-FOR-US: GROWI
 CVE-2026-84203 (Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens whe ...)
-	TODO: check
+	NOT-FOR-US: Memos
 CVE-2026-84202 (ModelScope uses PyYAML's unsafe yaml.Loader to parse model configurati ...)
-	TODO: check
+	NOT-FOR-US: ModelScope
 CVE-2026-84201 (appium-mcp-server through 0.1.61 fails to validate or normalize file p ...)
-	TODO: check
+	NOT-FOR-US: appium-mcp-server
 CVE-2026-84200 (Kyverno versions v1.9.0 through v1.12.7 contain a policy exception han ...)
-	TODO: check
+	NOT-FOR-US: Kyverno
 CVE-2026-84199 (Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vu ...)
-	TODO: check
+	NOT-FOR-US: Kyverno
 CVE-2026-84196 (Kyverno before 1.18.0 contains a server-side request forgery vulnerabi ...)
-	TODO: check
+	NOT-FOR-US: Kyverno
 CVE-2026-84195 (Kyverno before 1.16.4 automatically attaches the admission controller' ...)
-	TODO: check
+	NOT-FOR-US: Kyverno
 CVE-2026-84194 (LibreNMS versions >= 23.10.0 and < 26.2.0 (fixed in 26.4.0) contain an ...)
-	TODO: check
+	NOT-FOR-US: LibreNMS
 CVE-2026-84193 (LibreNMS through 26.2.0 contains a stored cross-site scripting vulnera ...)
-	TODO: check
+	NOT-FOR-US: LibreNMS
 CVE-2026-84192 (LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerab ...)
-	TODO: check
+	NOT-FOR-US: LibreNMS
 CVE-2026-84191 (LibreNMS before 26.5.0 contains stored cross-site scripting vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: LibreNMS
 CVE-2026-84190 (LibreNMS versions before 26.5.0 contain a remote code execution vulner ...)
-	TODO: check
+	NOT-FOR-US: LibreNMS
 CVE-2026-84189 (LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author,  ...)
-	TODO: check
+	NOT-FOR-US: LibreNMS
 CVE-2026-84188 (LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vuln ...)
-	TODO: check
+	NOT-FOR-US: LibreNMS
 CVE-2026-84187 (AVideo contains a missing authentication vulnerability in plugin/Live/ ...)
-	TODO: check
+	NOT-FOR-US: WWBN AVideo
 CVE-2026-84165 (A vulnerability relating to incorrect access control in OpenNebula by  ...)
 	TODO: check
 CVE-2026-84153 (A vulnerability was determined in Xinhu Rainrock RockOA up to 2.3.2. T ...)
-	TODO: check
+	NOT-FOR-US: Xinhu Rainrock RockOA
 CVE-2026-84149 (This vulnerability exists in the ERP system due to exposure of reposit ...)
-	TODO: check
+	NOT-FOR-US: Multi-tenant ERP System
 CVE-2026-84148 (This vulnerability exists in the ERP system due to improper authentica ...)
-	TODO: check
+	NOT-FOR-US: Multi-tenant ERP System
 CVE-2026-84147 (This vulnerability exists in the ERP system due to improper authentica ...)
-	TODO: check
+	NOT-FOR-US: Multi-tenant ERP System
 CVE-2026-84115 (A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected ...)
-	TODO: check
+	NOT-FOR-US: Cleo Harmony
 CVE-2026-84114 (A vulnerability has been found in Cleo Harmony up to 5.8.1.10. Impacte ...)
-	TODO: check
+	NOT-FOR-US: Cleo Harmony
 CVE-2026-84111 (A flaw has been found in Chanjet CRM up to 20260707. This issue affect ...)
-	TODO: check
+	NOT-FOR-US: Chanjet CRM
 CVE-2026-84110 (A vulnerability was detected in Releasit Releasit COD Form & Upsells v ...)
-	TODO: check
+	NOT-FOR-US: Releasit Releasit COD Form & Upsells
 CVE-2026-84109 (A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.6. A ...)
-	TODO: check
+	NOT-FOR-US: Xinhu Rainrock RockOA
 CVE-2026-84061 (A security flaw has been discovered in zhongyu09 OpenChatBI up to 0.3. ...)
-	TODO: check
+	NOT-FOR-US: zhongyu09 OpenChatBI
 CVE-2026-84059 (A flaw has been found in ICP DAS UA-2200 and UA-5200 up to 20260704. T ...)
-	TODO: check
+	NOT-FOR-US: ICP DAS UA-2200 and UA-5200
 CVE-2026-83619 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
 	TODO: check
 CVE-2026-83618 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9a1e3aa1d6b2308b2e14b56d304a8eb2570dfdcd

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9a1e3aa1d6b2308b2e14b56d304a8eb2570dfdcd
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260901/c07066de/attachment.htm>


More information about the debian-security-tracker-commits mailing list