[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Wed Sep 2 14:11:26 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
6af17666 by Moritz Muehlenhoff at 2026-09-02T15:11:08+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -94,17 +94,17 @@ CVE-2026-84370 (SVGO, short for SVG Optimizer, is a Node.js library and command-
CVE-2026-84369 (SVGO, short for SVG Optimizer, is a Node.js library and command-line a ...)
- node-svgo <itp> (bug #887376)
CVE-2026-84368 (joi is a schema description language and data validator for JavaScript ...)
- TODO: check
+ NOT-FOR-US: Node joi
CVE-2026-84367 (joi is a schema description language and data validator for JavaScript ...)
- TODO: check
+ NOT-FOR-US: Node joi
CVE-2026-84366 (Scrapy is a high-level web crawling and scraping framework for Python. ...)
TODO: check
CVE-2026-84365 (Hono is a Web application framework that provides support for any Java ...)
- TODO: check
+ NOT-FOR-US: Hono
CVE-2026-84364 (Hono is a Web application framework that provides support for any Java ...)
- TODO: check
+ NOT-FOR-US: Hono
CVE-2026-84363 (Hono is a Web application framework that provides support for any Java ...)
- TODO: check
+ NOT-FOR-US: Hono
CVE-2026-84361 (Composer is a dependency Manager for the PHP language. From 1.0 until ...)
TODO: check
CVE-2026-84309 (pypdf is a free and open-source pure-python PDF library. Prior to 6.16 ...)
@@ -112,23 +112,23 @@ CVE-2026-84309 (pypdf is a free and open-source pure-python PDF library. Prior t
CVE-2026-84308 (phpseclib is a PHP secure communications library. Prior to 3.0.57 and ...)
TODO: check
CVE-2026-84307 (Filament is a collection of full-stack components for accelerated Lara ...)
- TODO: check
+ NOT-FOR-US: Filament
CVE-2026-84306 (Filament is a collection of full-stack components for accelerated Lara ...)
- TODO: check
+ NOT-FOR-US: Filament
CVE-2026-84289 (A vulnerability was found in NousResearch hermes-agent up to 0.18.2. T ...)
- TODO: check
+ NOT-FOR-US: NousResearch hermes-agent
CVE-2026-84288 (A vulnerability has been found in NousResearch hermes-agent up to 0.18 ...)
- TODO: check
+ NOT-FOR-US: NousResearch hermes-agent
CVE-2026-84287 (A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by ...)
- TODO: check
+ NOT-FOR-US: NousResearch hermes-agent
CVE-2026-84208 (AVideo through version 29.0 contains an unauthenticated SQL injection ...)
- TODO: check
+ NOT-FOR-US: AVideo
CVE-2026-83549 (Post-authentication Improper Neutralization of Special Elements used i ...)
NOT-FOR-US: SonicWall
CVE-2026-83548 (A Pre-authentication SSRF vulnerability exists in the SMA1000 Applianc ...)
NOT-FOR-US: SonicWall
CVE-2026-82968 (A flaw was found in the first-broker-login flow of the Keycloak identi ...)
- TODO: check
+ - keycloak <itp> (bug #1088287)
CVE-2026-82883 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-82183 (The OAuth Single Sign On WordPress plugin before 7.0.1 does not verif ...)
@@ -136,7 +136,7 @@ CVE-2026-82183 (The OAuth Single Sign On WordPress plugin before 7.0.1 does not
CVE-2026-82182 (The WPvivid \u2014 Backup, Migration & Staging WordPress plugin before ...)
NOT-FOR-US: WordPress plugin
CVE-2026-81846 (An authorization bypass in the runZero Platform MCP service has been r ...)
- TODO: check
+ NOT-FOR-US: runZero Platform MCP
CVE-2026-81807 (The Simple Ajax Chat WordPress plugin before 20260827 does not escape ...)
NOT-FOR-US: WordPress plugin
CVE-2026-81737 (The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or ...)
@@ -170,19 +170,19 @@ CVE-2026-79621 (The CatalogX WordPress plugin before 6.1.3 does not sanitise or
CVE-2026-78657 (The SigmaForms Pro \u2013 AI Generated Forms plugin for WordPress is v ...)
NOT-FOR-US: WordPress plugin
CVE-2026-78608 (Missing Authorization (CWE-862) in Kibana can lead to information disc ...)
- TODO: check
+ - kibana <itp> (bug #700337)
CVE-2026-78607 (Missing Authorization (CWE-862) in the Elasticsearch custom inference ...)
NOT-FOR-US: Elasticsearch
CVE-2026-78606 (Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized d ...)
- TODO: check
+ - kibana <itp> (bug #700337)
CVE-2026-78605 (Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling' ...)
NOT-FOR-US: Elasticsearch
CVE-2026-78603 (Missing Authorization (CWE-862) in Kibana can lead to information disc ...)
- TODO: check
+ - kibana <itp> (bug #700337)
CVE-2026-78597 (Missing Authorization (CWE-862) in the Kibana Entity Store feature can ...)
- TODO: check
+ - kibana <itp> (bug #700337)
CVE-2026-78592 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
- TODO: check
+ - kibana <itp> (bug #700337)
CVE-2026-78151 (The FormLayer WordPress plugin before 1.0.9 does not perform any autho ...)
NOT-FOR-US: WordPress plugin
CVE-2026-77792 (The RegistrationMagic WordPress plugin before 6.0.9.9 does not escape ...)
@@ -384,31 +384,31 @@ CVE-2026-73701 (An unauthenticated remote code execution vulnerability exists in
CVE-2026-73700 (A vulnerability in the web-based management interface of HPE Networkin ...)
NOT-FOR-US: HPE
CVE-2026-73524 (Cypht before 2.12.2 contains a cross-site scripting vulnerability in t ...)
- TODO: check
+ NOT-FOR-US: Cypht
CVE-2026-72682 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
- TODO: check
+ - kibana <itp> (bug #700337)
CVE-2026-72654 (Execution with Unnecessary Privileges (CWE-250) in the Kibana machine ...)
- TODO: check
+ - kibana <itp> (bug #700337)
CVE-2026-72652 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
- TODO: check
+ - kibana <itp> (bug #700337)
CVE-2026-72649 (Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machi ...)
NOT-FOR-US: Elasticsearch
CVE-2026-72644 (Uncaught Exception (CWE-248) in Kibana can lead to a denial of service ...)
- TODO: check
+ - kibana <itp> (bug #700337)
CVE-2026-72641 (Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized m ...)
- TODO: check
+ - kibana <itp> (bug #700337)
CVE-2026-72633 (Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead ...)
- TODO: check
+ - kibana <itp> (bug #700337)
CVE-2026-72628 (Improper Handling of Highly Compressed Data (CWE-409) in Kibana can le ...)
- TODO: check
+ - kibana <itp> (bug #700337)
CVE-2026-71981 (Cypht before 2.12.2 contains a PHP object injection vulnerability that ...)
- TODO: check
+ NOT-FOR-US: Cypht
CVE-2026-63435 (Mail is an internet library for Ruby designed to handle email generati ...)
TODO: check
CVE-2026-63138 (Improper Neutralization of Special Elements in Data Query Logic (CWE-9 ...)
- TODO: check
+ - kibana <itp> (bug #700337)
CVE-2026-63137 (Incorrect Authorization (CWE-863) in Kibana can lead to privilege esca ...)
- TODO: check
+ - kibana <itp> (bug #700337)
CVE-2026-56143 (Allocation of Resources Without Limits or Throttling (CWE-770) in Elas ...)
NOT-FOR-US: Elasticsearch
CVE-2026-45221 (Konga before 2.1.0 contains a privilege escalation vulnerability that ...)
@@ -418,7 +418,7 @@ CVE-2026-3851 (The Divi theme for WordPress is vulnerable to Stored Cross-Site S
CVE-2026-3850 (The Divi theme for WordPress is vulnerable to Stored Cross-Site Script ...)
NOT-FOR-US: WordPress plugin
CVE-2026-33465 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
- TODO: check
+ - kibana <itp> (bug #700337)
CVE-2026-19766 (An authentication bypass vulnerability exists in the underlying operat ...)
NOT-FOR-US: HPE
CVE-2026-19754 (Baserow 2.3.3 contains a SQL injection vulnerability in the index() fo ...)
@@ -456,15 +456,15 @@ CVE-2026-12865 (The Photo Gallery by 10Web WordPress plugin before 1.8.44 does
CVE-2026-12526 (The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 d ...)
NOT-FOR-US: WordPress plugin
CVE-2025-46418 (Westermo WeOS 5.x starting from 5.24 allows OS command injection via a ...)
- TODO: check
+ NOT-FOR-US: Westermo WeOS
CVE-2025-15664 (The Ultimate Before After Image Slider & Gallery WordPress plugin bef ...)
NOT-FOR-US: WordPress plugin
CVE-2025-15663 (The Ultimate Before After Image Slider & Gallery WordPress plugin bef ...)
NOT-FOR-US: WordPress plugin
CVE-2024-35585 (Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP ad ...)
- TODO: check
+ NOT-FOR-US: Oxford Nanopore MinKNOW
CVE-2023-54391 (Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentic ...)
- TODO: check
+ NOT-FOR-US: Proxmox Virtual Environment
CVE-2026-82209
- curl 8.22.0-1
NOTE: https://curl.se/docs/CVE-2026-82209.html
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6af176667311ab2e855dcf23373f28371edcc65e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6af176667311ab2e855dcf23373f28371edcc65e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260902/396bcd16/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list