[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 4 13:55:19 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b39e8869 by Salvatore Bonaccorso at 2026-09-04T14:54:43+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -270,9 +270,9 @@ CVE-2026-64196 (There is an out-of-bounds write vulnerability in DASYLabdue to i
 CVE-2026-64195 (There is an out-of-bounds write vulnerability in DASYLab due to lack o ...)
 	NOT-FOR-US: National Instruments
 CVE-2026-63376 (toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2 ...)
-	TODO: check
+	NOT-FOR-US: toml-node
 CVE-2026-62928 (XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthent ...)
-	TODO: check
+	NOT-FOR-US: XING CPTrans-ME-X
 CVE-2026-62916 (Authentication bypass using an alternate path or channel in Microsoft  ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-62906 (Improper neutralization of special elements in data query logic in Mic ...)
@@ -825,9 +825,9 @@ CVE-2026-66048
 CVE-2026-63694 (Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains  ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-63219 (GeoNetwork is a catalog application to manage spatially referenced res ...)
-	TODO: check
+	NOT-FOR-US: GeoNetwork
 CVE-2026-58400 (GeoNetwork is a catalog application to manage spatially referenced res ...)
-	TODO: check
+	NOT-FOR-US: GeoNetwork
 CVE-2026-57445 (Gardens v2 is a modular governance framework that enables communities  ...)
 	TODO: check
 CVE-2026-56128 (pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated user ...)
@@ -3653,7 +3653,7 @@ CVE-2026-66047 (ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 con
 CVE-2026-63083
 	REJECTED
 CVE-2026-5956 (Improper neutralization of special elements used in an SQL command ('S ...)
-	TODO: check
+	NOT-FOR-US: Site Management Panel
 CVE-2026-59111 (Improper neutralization of special elements used in an OS command ('OS ...)
 	TODO: check
 CVE-2026-58301 (When Apache Shiro is used with the Jakarta EE integration module, a lo ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b39e8869837deab04957e95c0e8cb4a44ab9d4b3

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b39e8869837deab04957e95c0e8cb4a44ab9d4b3
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/dae60ac3/attachment.htm>


More information about the debian-security-tracker-commits mailing list