[Git][security-tracker-team/security-tracker][master] Process NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Sep 3 07:34:23 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4e729860 by Salvatore Bonaccorso at 2026-09-03T08:28:00+02:00
Process NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1425,7 +1425,7 @@ CVE-2026-79682 (Dell PowerStore contains a Command Injection vulnerability. An a
 CVE-2026-78363 (The MW WP Form WordPress plugin before 5.1.5 does not prevent shortcod ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-78012 (An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow  ...)
-	TODO: check
+	NOT-FOR-US: NetStaX
 CVE-2026-77194 (The Simple Membership plugin for WordPress is vulnerable to Authentica ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-76111 (Dell PowerStore contains an Incorrect Authorization vulnerability. An  ...)
@@ -1445,7 +1445,7 @@ CVE-2026-73276 (Gracefulness code ignored cases that should be rejected, resulti
 CVE-2026-73270 (Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inet ...)
 	TODO: check
 CVE-2026-71562 (Improper Validation of Specified Quantity in Input vulnerability in Er ...)
-	TODO: check
+	NOT-FOR-US: fosrl/pangolin
 CVE-2026-71380 (Missing Release of Resource after Effective Lifetime vulnerability in  ...)
 	TODO: check
 CVE-2026-70409 (Improper Validation of Specified Quantity in Input vulnerability in Er ...)
@@ -2400,9 +2400,9 @@ CVE-2026-75132 (WAPT Server versions 2.6.1.17834 and earlier contains a SQL inje
 CVE-2026-74010 (Missing Authorization vulnerability in John James Jacoby bbPress allow ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73819 (The affectedEbyte   product's vendor configuration utility permits acc ...)
-	TODO: check
+	NOT-FOR-US: Ebyte
 CVE-2026-72001 (Pangolin before 1.22.0 contains an authentication bypass vulnerability ...)
-	TODO: check
+	NOT-FOR-US: fosrl/pangolin
 CVE-2026-71378 (ResourceIsolationRequestCycleListener protects a Wicket application ag ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-71257 (Apache Wicket enforces the upload limits configured on a form or uploa ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e7298607869d4c756e175abdd4a5dc04c21abc4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e7298607869d4c756e175abdd4a5dc04c21abc4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260903/e1d1dee4/attachment.htm>


More information about the debian-security-tracker-commits mailing list