[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Sep 3 20:56:10 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
8e6e6726 by Salvatore Bonaccorso at 2026-09-03T21:55:42+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -18,7 +18,7 @@ CVE-2026-85396 (rubyzip versions before 3.4.0 contain a path traversal vulnerabi
NOTE: https://github.com/rubyzip/rubyzip/issues/664
NOTE: Fixed by: https://github.com/rubyzip/rubyzip/commit/17edfbf4423b83211b075acc23a7d8640da63449 (v3.4.0)
CVE-2026-85395 (UnoPim before 2.1.3 fails to include integration store, update, and ke ...)
- TODO: check
+ NOT-FOR-US: UnoPim
CVE-2026-85394 (python-jose through 3.5.0 fails to properly validate asymmetric keys i ...)
- python-jose <not-affected> (Incomplete fix for CVE-2024-33663 not applied)
NOTE: https://github.com/mpdavis/python-jose/issues/414
@@ -26,15 +26,15 @@ CVE-2026-85394 (python-jose through 3.5.0 fails to properly validate asymmetric
CVE-2026-85393 (node-forge through 1.4.0 fails to validate element count in nested Dig ...)
TODO: check
CVE-2026-85392 (Peppermint through 0.5.5 contains an authorization bypass vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: Peppermint Lab Peppermint
CVE-2026-85391 (Peppermint through 0.5.5 contains a hardcoded JWT signing secret in do ...)
- TODO: check
+ NOT-FOR-US: Peppermint Lab Peppermint
CVE-2026-85390 (Checkmate through 3.11.0 omits the isAllowed role guard middleware on ...)
- TODO: check
+ NOT-FOR-US: Checkmate
CVE-2026-85389 (Worklenz before 3.0.0 fails to verify task ownership by organization w ...)
- TODO: check
+ NOT-FOR-US: Worklenz
CVE-2026-85388 (Worklenz through 3.0.0 fails to properly validate the sort-field query ...)
- TODO: check
+ NOT-FOR-US: Worklenz
CVE-2026-85309 (Missing Authorization vulnerability in Supsystic Ultimate Maps by Sups ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-85308 (Authorization Bypass Through User-Controlled Key vulnerability in Brai ...)
@@ -52,7 +52,7 @@ CVE-2026-85303 (Improper Neutralization of Input During Web Page Generation ('Cr
CVE-2026-85302 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-85242 (PlaywrightCapture contains a server-side request forgery (SSRF) vulner ...)
- TODO: check
+ NOT-FOR-US: PlaywrightCapture
CVE-2026-85239 (A vulnerability in MISP's event template handling allowed an authentic ...)
TODO: check
CVE-2026-85238 (MISP contains a session fixation vulnerability in the CustomAuth authe ...)
@@ -72,39 +72,39 @@ CVE-2026-85221 (MISP contains an improper TLS certificate validation vulnerabili
CVE-2026-85216 (MISP contains an authentication bypass vulnerability in its LDAP and L ...)
TODO: check
CVE-2026-85214 (vhr fails to validate user authorization in the PUT /hr/info endpoint, ...)
- TODO: check
+ NOT-FOR-US: vhr
CVE-2026-85213 (Kill Bill through 0.24.21 fails to enforce permission annotations on s ...)
- TODO: check
+ NOT-FOR-US: Kill Bill
CVE-2026-85212 (CRMEB contains an authentication bypass vulnerability in the verifyAut ...)
- TODO: check
+ NOT-FOR-US: CRMEB
CVE-2026-85211 (Label Studio fails to apply organization filters when resolving storag ...)
- TODO: check
+ NOT-FOR-US: Label Studio
CVE-2026-85210 (Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is ...)
- TODO: check
+ NOT-FOR-US: Oppia
CVE-2026-85205 (A vulnerability was determined in itsourcecode Online Medicine Deliver ...)
NOT-FOR-US: itsourcecode System
CVE-2026-85199 (Eclipse aeriOS Self-orchestrator versions prior to 1.2.1 contain a pat ...)
- TODO: check
+ NOT-FOR-US: Eclipse aeriOS Self-orchestrator
CVE-2026-85187 (A security vulnerability has been detected in itsourcecode Online Medi ...)
NOT-FOR-US: itsourcecode System
CVE-2026-85186 (A weakness has been identified in itsourcecode Online Medicine Deliver ...)
NOT-FOR-US: itsourcecode System
CVE-2026-85183 (Taipy configures its socket.io server with wildcard CORS origin and cr ...)
- TODO: check
+ NOT-FOR-US: Taipy
CVE-2026-85182 (vhr through commit 03abbd3 fails to verify that the account ID in PUT ...)
- TODO: check
+ NOT-FOR-US: vhr
CVE-2026-85181 (CAT uses Java String.hashCode as the sole integrity check for session ...)
- TODO: check
+ NOT-FOR-US: CAT
CVE-2026-85180 (Ollama fails to validate redirect destinations when pulling tensor-lay ...)
TODO: check
CVE-2026-85179 (Label Studio through 1.23.0 fails to validate webhook URLs, allowing a ...)
- TODO: check
+ NOT-FOR-US: Label Studio
CVE-2026-85178 (Helicone's VaultManager.getDecryptedProviderKeyById() function in the ...)
- TODO: check
+ NOT-FOR-US: Helicone
CVE-2026-85177 (CRMEB through 6.0.0 fails to validate message ownership in the edit_me ...)
- TODO: check
+ NOT-FOR-US: CRMEB
CVE-2026-85176 (DbGate fails to validate jslid parameters in the jsldata controller, a ...)
- TODO: check
+ NOT-FOR-US: DbGate
CVE-2026-85175 (SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an incomplete block ...)
NOT-FOR-US: SiYuan
CVE-2026-85174 (SiYuan before v3.8.2 logs API tokens from query parameters in plaintex ...)
@@ -128,27 +128,27 @@ CVE-2026-85166 (n8n before 2.35.4 and 2.36.x before 2.36.2 does not validate cre
CVE-2026-85165 (n8n versions before 2.36.2 contain an expression sandbox bypass vulner ...)
NOT-FOR-US: n8n
CVE-2026-85164 (WWBN AVideo through commit c91b5975d contains a server-side request fo ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-85163 (AVideo through commit c91b5975d contains a server-side request forgery ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-85162 (AVideo through commit c91b5975d contains a cross-site request forgery ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-85161 (AVideo through commit c91b5975d contains a cross-site request forgery ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-85160 (AVideo through commit c91b5975d contains a cross-site request forgery ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-85159 (AVideo through commit c91b5975d contains a reflected cross-site script ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-85158 (AVideo through commit c91b5975d contains a reflected cross-site script ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-85157 (WWBN AVideo contains a broken access control vulnerability in the unau ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-85156 (WWBN AVideo fails to properly validate access controls on the public c ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-85155 (WWBN AVideo contains a SQL injection vulnerability in the sort column ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-85154 (WWBN AVideo contains an authentication failure vulnerability where the ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-85150 (A NULL pointer dereference flaw was found in GStreamer's RTSP support ...)
TODO: check
CVE-2026-85138 (A vulnerability was detected in SeaCMS up to 13.6. Affected is the fun ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8e6e672608a6bf97c4e6f5e5b2c7aedd92700d6e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8e6e672608a6bf97c4e6f5e5b2c7aedd92700d6e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260903/97093d84/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list