[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Sep 3 20:13:39 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
248af3ce by security tracker role at 2026-09-03T19:13:32+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,9 +1,9 @@
 CVE-2026-9854 (A vulnerability exists in SYS600 RBAC mechanism where users having acc ...)
-	TODO: check
+	NOT-FOR-US: Hitachi Energy
 CVE-2026-9853 (A vulnerability exists in SYS600 which allows any user authenticated t ...)
-	TODO: check
+	NOT-FOR-US: Hitachi Energy
 CVE-2026-9852 (A CSV injection vulnerability exists in SYS600. Injected malicious for ...)
-	TODO: check
+	NOT-FOR-US: Hitachi Energy
 CVE-2026-85396 (rubyzip versions before 3.4.0 contain a path traversal vulnerability i ...)
 	TODO: check
 CVE-2026-85395 (UnoPim before 2.1.3 fails to include integration store, update, and ke ...)
@@ -23,21 +23,21 @@ CVE-2026-85389 (Worklenz before 3.0.0 fails to verify task ownership by organiza
 CVE-2026-85388 (Worklenz through 3.0.0 fails to properly validate the sort-field query ...)
 	TODO: check
 CVE-2026-85309 (Missing Authorization vulnerability in Supsystic Ultimate Maps by Sups ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-85308 (Authorization Bypass Through User-Controlled Key vulnerability in Brai ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-85307 (Insertion of Sensitive Information Into Sent Data vulnerability in Kev ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-85306 (Missing Authorization vulnerability in Cascadia Web Services MountDev  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-85305 (Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Se ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-85304 (Missing Authorization vulnerability in Unlimited Elements Unlimited El ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-85303 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-85302 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-85242 (PlaywrightCapture contains a server-side request forgery (SSRF) vulner ...)
 	TODO: check
 CVE-2026-85239 (A vulnerability in MISP's event template handling allowed an authentic ...)
@@ -69,13 +69,13 @@ CVE-2026-85211 (Label Studio fails to apply organization filters when resolving
 CVE-2026-85210 (Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is  ...)
 	TODO: check
 CVE-2026-85205 (A vulnerability was determined in itsourcecode Online Medicine Deliver ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-85199 (Eclipse aeriOS Self-orchestrator versions prior to 1.2.1 contain a pat ...)
 	TODO: check
 CVE-2026-85187 (A security vulnerability has been detected in itsourcecode Online Medi ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-85186 (A weakness has been identified in itsourcecode Online Medicine Deliver ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-85183 (Taipy configures its socket.io server with wildcard CORS origin and cr ...)
 	TODO: check
 CVE-2026-85182 (vhr through commit 03abbd3 fails to verify that the account ID in PUT  ...)
@@ -93,27 +93,27 @@ CVE-2026-85177 (CRMEB through 6.0.0 fails to validate message ownership in the e
 CVE-2026-85176 (DbGate fails to validate jslid parameters in the jsldata controller, a ...)
 	TODO: check
 CVE-2026-85175 (SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an incomplete block ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-85174 (SiYuan before v3.8.2 logs API tokens from query parameters in plaintex ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-85173 (n8n versions before 2.36.2 contain a missing per-project authorization ...)
-	TODO: check
+	NOT-FOR-US: n8n
 CVE-2026-85172 (n8n versions before 2.34.1 contain a server-side request forgery vulne ...)
-	TODO: check
+	NOT-FOR-US: n8n
 CVE-2026-85171 (n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential exposure ...)
-	TODO: check
+	NOT-FOR-US: n8n
 CVE-2026-85170 (n8n versions before 1.123.73, 2.35.4, and 2.36.2 pass message content  ...)
-	TODO: check
+	NOT-FOR-US: n8n
 CVE-2026-85169 (n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain an expression ...)
-	TODO: check
+	NOT-FOR-US: n8n
 CVE-2026-85168 (n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain a remote code ...)
-	TODO: check
+	NOT-FOR-US: n8n
 CVE-2026-85167 (n8n before 2.35.4 and 2.36.x before 2.36.2 contain a query injection v ...)
-	TODO: check
+	NOT-FOR-US: n8n
 CVE-2026-85166 (n8n before 2.35.4 and 2.36.x before 2.36.2 does not validate credentia ...)
-	TODO: check
+	NOT-FOR-US: n8n
 CVE-2026-85165 (n8n versions before 2.36.2 contain an expression sandbox bypass vulner ...)
-	TODO: check
+	NOT-FOR-US: n8n
 CVE-2026-85164 (WWBN AVideo through commit c91b5975d contains a server-side request fo ...)
 	TODO: check
 CVE-2026-85163 (AVideo through commit c91b5975d contains a server-side request forgery ...)
@@ -147,9 +147,9 @@ CVE-2026-85135 (A security flaw has been discovered in ILIAS up to 9.21/10.9/11.
 CVE-2026-85124 (@fastify/http-proxy versions before 11.6.2 do not validate proxied HTT ...)
 	TODO: check
 CVE-2026-85110 (A vulnerability was identified in Tenda HG10 300001138. Impacted is th ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-85109 (A vulnerability was determined in Tenda HG10 300001138. This issue aff ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-85107 (A vulnerability was found in NousResearch hermes-agent 0.18.0. This vu ...)
 	TODO: check
 CVE-2026-85106 (A vulnerability has been found in NousResearch hermes-agent 0.18.0. Th ...)
@@ -173,17 +173,17 @@ CVE-2026-85084 (Out-of-bounds Write and Improper Validation of Array Index vulne
 CVE-2026-85040 (A weakness has been identified in ZhongBangKeJi CRMEB up to 6.0.0. Aff ...)
 	TODO: check
 CVE-2026-85031 (A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted elemen ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-85030 (A vulnerability has been found in HKUDS AI-Trader up to d03ff6c056b32c ...)
 	TODO: check
 CVE-2026-85028 (Creation of a temporary file in a directory with insecure permissions  ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-85022 (A vulnerability was identified in langgenius dify 1.13.0. Affected by  ...)
 	TODO: check
 CVE-2026-85021 (A vulnerability was determined in langgenius dify 1.13.0. Affected is  ...)
 	TODO: check
 CVE-2026-85012 (Improper neutralization of special elements used in an OS command (CWE ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-84989 (ntopng is a web-based network traffic monitoring application. In versi ...)
 	TODO: check
 CVE-2026-84971 (Improper handling of an unexpected value size in the decryption path o ...)
@@ -217,21 +217,21 @@ CVE-2026-84885 (A vulnerability has been found in simular-ai Agent-S 0.3.1/0.3.2
 CVE-2026-84857 (A flaw has been found in sigoden aichat up to 0.30.4. This affects an  ...)
 	TODO: check
 CVE-2026-84856 (A vulnerability was detected in rowboatlabs rowboat up to 0.9.1. The i ...)
-	TODO: check
+	NOT-FOR-US: Next.js
 CVE-2026-84852 (A security vulnerability has been detected in Reader Tools PDF Reader  ...)
 	TODO: check
 CVE-2026-84851 (An uncontrolled recursion issue exists in Amazon Ion-C versions before ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-84849 (Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <=  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84848 (Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84847 (Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 v ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84836 (Subscriber Insecure Direct Object References (IDOR) in WC Ukraine Ship ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84834 (Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84832 (SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-cont ...)
 	TODO: check
 CVE-2026-84831 (SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged ...)
@@ -239,55 +239,55 @@ CVE-2026-84831 (SEPPmail Secure Email Gateway before 15.0.7 creates a fully priv
 CVE-2026-84830 (SEPPmail Secure Email Gateway before 15.0.7 contains a command injecti ...)
 	TODO: check
 CVE-2026-84815 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84814 (Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84813 (Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84812 (Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84779 (Subscriber Broken Access Control in Agentimus \u2013 AI SEO, llms.txt  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84778 (Unauthenticated Denial of Service Attack in Migrate Guru \u2013 Site M ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84777 (Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 ve ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84776 (Unauthenticated Denial of Service Attack in MalCare Security <= 6.69 v ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84774 (Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.1 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84773 (Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <=  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84769 (Unauthenticated Insecure Direct Object References (IDOR) in Business D ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84768 (Unauthenticated SQL Injection in VikAppointments Services Booking Cale ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84767 (Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84766 (Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 ver ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84765 (Unauthenticated Cross Site Scripting (XSS) in Breadcrumb NavXT <= 7.5. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84763 (Unauthenticated Cross Site Scripting (XSS) in RTMKit <= 2.1.5 versions ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84762 (Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84761 (Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84758 (Unauthenticated Broken Access Control in Business Directory <= 6.4.26  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84757 (Unauthenticated Settings Change in WP Compress <= 7.21.28 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84756 (Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84755 (Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84754 (Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84753 (Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84752 (Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84736 (In the current development version of Eclipse aeriOS, for which no off ...)
 	TODO: check
 CVE-2026-84452 (Windows ML CLI is a command line tool for building portable, performan ...)
@@ -297,13 +297,13 @@ CVE-2026-84394 (fast-uri accepts a host that contains an unbalanced or misplaced
 CVE-2026-84292 (fast-uri serializes the port component of a URI without validating it. ...)
 	TODO: check
 CVE-2026-84238 (Unauthenticated Broken Access Control in YITH Request a Quote for WooC ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84215 (Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-83961 (ColdFusion is affected by an Improper Authentication vulnerability tha ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-83959 (Substance3D - Sampler is affected by a Heap-based Buffer Overflow vuln ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-82918 (XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporat ...)
 	TODO: check
 CVE-2026-82526 (R2R through 3.6.6 contains a stacked SQL injection vulnerability that  ...)
@@ -325,29 +325,29 @@ CVE-2026-82024 (LearnPress WordPress Plugin before 4.4.6 contains a stored cross
 CVE-2026-82023 (LearnPress WordPress Plugin before 4.4.6 contains a broken object-leve ...)
 	TODO: check
 CVE-2026-81776 (Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 v ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81773 (Unauthenticated Cross Site Scripting (XSS) in  Ninja Forms File Upload ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81300 (Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81295 (Unauthenticated Cross Site Scripting (XSS) in Under Construction <= 5. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81292 (Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81282 (Subscriber Cross Site Scripting (XSS) in Product Variations Swatches f ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81281 (Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-80515 (In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-autho ...)
 	TODO: check
 CVE-2026-80465 (A vulnerability has been identified in Mendix SAML (Mendix 10 compatib ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2026-80254 (Authorization bypass through user-controlled key issue exists in Shize ...)
 	TODO: check
 CVE-2026-80253 (An improper physical access control issue exists in ShizenBox2 (dev-co ...)
 	TODO: check
 CVE-2026-79679 (Use of Weak Credentials vulnerability in B&R Industrial Automation Gmb ...)
-	TODO: check
+	NOT-FOR-US: ABB group
 CVE-2026-78596 (Missing Authorization in Kibana Leading to Unauthorized Modification o ...)
 	TODO: check
 CVE-2026-78595 (Missing Authorization in Kibana Leading to Information Disclosure / Mi ...)
@@ -359,17 +359,17 @@ CVE-2026-78583 (Incorrect Authorization (CWE-863) in Kibana can lead to privileg
 CVE-2026-78304
 	REJECTED
 CVE-2026-78080 (Joomla Extension - feenders.de - Unauthenticated SQL injection in JooD ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-78069 (Joomla Extension - j2commerce.com - Missing authorization on Apps cont ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-78065 (Joomla Extension - j2commerce.com - Guest checkout address disclosure  ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-78064 (Joomla Extension - j2commerce.com - Anonymous cart-record tampering vi ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-78000 (Joomla Extension - j2commerce.com - Reflected XSS via `filter_tag`, `p ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-77999 (Joomla Extension - j2commerce.com - Unauthenticated PayPal callback fo ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-76178 (A stored Cross-Site Scripting (XSS) vulnerability in the notification  ...)
 	TODO: check
 CVE-2026-76177 (Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?f ...)
@@ -399,11 +399,11 @@ CVE-2026-75034 (A flaw was found in Rancher Manager. The SAML assertion replay p
 CVE-2026-75033 (A flaw was found in Rancher Manager. Project Secrets were propagated i ...)
 	TODO: check
 CVE-2026-74769 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-74768 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-73600 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-71963 (Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains  ...)
 	TODO: check
 CVE-2026-71404 (A flaw was found in Rancher Manager. The GlobalRole controller derived ...)
@@ -421,15 +421,15 @@ CVE-2026-71220 (A stack out-of-bounds write vulnerability was found in gfs2-util
 CVE-2026-71219 (A stack overflow vulnerability was found in gfs2-utils. The hash table ...)
 	TODO: check
 CVE-2026-6071 (A remote code execution security issue exists in the affected products ...)
-	TODO: check
+	NOT-FOR-US: Rockwell Automation
 CVE-2026-68860 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-66049
 	REJECTED
 CVE-2026-66048
 	REJECTED
 CVE-2026-63694 (Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains  ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-63219 (GeoNetwork is a catalog application to manage spatially referenced res ...)
 	TODO: check
 CVE-2026-58400 (GeoNetwork is a catalog application to manage spatially referenced res ...)
@@ -457,23 +457,23 @@ CVE-2026-49455 (Waku is the minimal React framework. Prior to version 1.0.0-beta
 CVE-2026-48486 (Signum Node is a HDD-mined cryptocurrency using an energy efficient an ...)
 	TODO: check
 CVE-2026-3852 (The Divi theme for WordPress is vulnerable to Stored Cross-Site Script ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-3416 (The API Publisher component previously used a non-cryptographic pseudo ...)
-	TODO: check
+	NOT-FOR-US: WSO2
 CVE-2026-35160 (Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains  ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-2573 (The GutenKit \u2013 Page Builder Blocks, Patterns, and Templates for G ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-17539 (RTU500 has a vulnerability, where high-load scenarios, such as sending ...)
-	TODO: check
+	NOT-FOR-US: Hitachi Energy
 CVE-2026-15933 (OptimiDoc Server (On-Premise) stores credentials for external services ...)
 	TODO: check
 CVE-2026-15926
 	REJECTED
 CVE-2026-15431 (A potential security vulnerability has been identified in the HP Suppo ...)
-	TODO: check
+	NOT-FOR-US: HP
 CVE-2025-12737 (The administrative operations within the Carbon Console do not adequat ...)
-	TODO: check
+	NOT-FOR-US: WSO2
 CVE-2026-XXXX [Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') and Use After Free and Double Free in libde265]
 	- libde265 1.1.2-1
 	NOTE: https://github.com/strukturag/libde265/security/advisories/GHSA-xp3h-6f5r-8cxp
@@ -549832,9 +549832,9 @@ CVE-2021-43616 (The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds wit
 CVE-2021-43615 (An issue was discovered in HddPassword in Insyde InsydeH2O with kernel ...)
 	NOT-FOR-US: Insyde
 CVE-2021-43614 (Error in handling the PlatformLangCodes UEFI variable could cause a bu ...)
-	TODO: check
+	NOT-FOR-US: Insyde
 CVE-2021-43613 (An issue was discovered in SysPasswordDxe in Insyde InsydeH2O. User an ...)
-	TODO: check
+	NOT-FOR-US: Insyde
 CVE-2021-43612 (In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decod ...)
 	{DLA-3389-1}
 	- lldpd 1.0.13-1
@@ -565466,7 +565466,7 @@ CVE-2021-38491 (Mixed-content checks were unable to analyze opaque origins which
 CVE-2021-38490 (Altova MobileTogether Server before 7.3 SP1 allows XML exponential ent ...)
 	NOT-FOR-US: Altova MobileTogether Server
 CVE-2021-38489 (HDD password plaintext is stored in a UEFI variable.)
-	TODO: check
+	NOT-FOR-US: Insyde
 CVE-2021-38488 (Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to  ...)
 	NOT-FOR-US: Delta Electronics DIALink
 CVE-2021-38487 (RTI Connext Professional versions 4.1 to 6.1.0, and Connext Micro vers ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/248af3ce3f802a7907daa9024bd0a9b8eec75238

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/248af3ce3f802a7907daa9024bd0a9b8eec75238
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260903/48af458a/attachment.htm>


More information about the debian-security-tracker-commits mailing list