[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Sep 4 14:25:50 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7130adf6 by Moritz Muehlenhoff at 2026-09-04T15:25:33+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -228,7 +228,7 @@ CVE-2026-79631 (The WPFunnels  WordPress plugin before 3.13.0 does not restrict
 CVE-2026-79630 (The WPFunnels  WordPress plugin before 3.13.0 does not verify that the ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-77465 (toml-node is a TOML parser for Node.js and the browser. Prior to 4.2.0 ...)
-	NOT-FOR-US: toml-node
+	NOT-FOR-US: Node toml-node
 CVE-2026-75754 (Missing Authentication for Critical Function, Server-Side Request Forg ...)
 	NOT-FOR-US: ASUS
 CVE-2026-74853 (The Pods  WordPress plugin before 3.3.9.2 does not restrict which func ...)
@@ -270,7 +270,7 @@ CVE-2026-64196 (There is an out-of-bounds write vulnerability in DASYLabdue to i
 CVE-2026-64195 (There is an out-of-bounds write vulnerability in DASYLab due to lack o ...)
 	NOT-FOR-US: National Instruments
 CVE-2026-63376 (toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2 ...)
-	NOT-FOR-US: toml-node
+	NOT-FOR-US: Node toml-node
 CVE-2026-62928 (XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthent ...)
 	NOT-FOR-US: XING CPTrans-ME-X
 CVE-2026-62916 (Authentication bypass using an alternate path or channel in Microsoft  ...)
@@ -278,7 +278,7 @@ CVE-2026-62916 (Authentication bypass using an alternate path or channel in Micr
 CVE-2026-62906 (Improper neutralization of special elements in data query logic in Mic ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-53728 (Medplum is a developer platform that enables development of healthcare ...)
-	TODO: check
+	NOT-FOR-US: Medplum
 CVE-2026-49509 (Out-of-bounds read vulnerability in Samsung Opensource Escargot allows ...)
 	TODO: check
 CVE-2026-45200 (Software installed and run as a non-privileged user may conduct improp ...)
@@ -286,7 +286,7 @@ CVE-2026-45200 (Software installed and run as a non-privileged user may conduct
 CVE-2026-45197 (Kernel software installed and running inside a Guest VM may post impro ...)
 	NOT-FOR-US: Imagination Technologies
 CVE-2026-44506 (Medplum is a developer platform that enables development of healthcare ...)
-	TODO: check
+	NOT-FOR-US: Medplum
 CVE-2026-19795 (IBM Qiskit SDK 2.1.0 through 2.5.1 could allow a local attacker to cau ...)
 	NOT-FOR-US: IBM
 CVE-2026-19224 (The Hummingbird Performance  WordPress plugin before 3.21.2 does not r ...)
@@ -7361,7 +7361,7 @@ CVE-2026-47874 (The vulnerability occurs when a client sends HTTP/1.1 pipelined
 CVE-2026-47864 (SerializingHttpMessageConverter deserializes the body of incoming HTTP ...)
 	NOT-FOR-US: VMware
 CVE-2026-47863 (In Reactor Core, applications that use the Flux.bufferTimeout operator ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-47862 (An attacker who can set the file_name header on a message reaching a Z ...)
 	NOT-FOR-US: VMware
 CVE-2026-47861 (An unauthenticated remote attacker who can send a single UDP packet to ...)
@@ -7371,7 +7371,7 @@ CVE-2026-47860 (An attacker who can publish to a queue consumed by an applicatio
 CVE-2026-47859 (RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP i ...)
 	NOT-FOR-US: VMware
 CVE-2026-47857 (In Reactor Core, applications that use the Flux.windowTimeout operator ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-47856 (Spring Integration's JSON to object conversion uses the json__TypeId__ ...)
 	NOT-FOR-US: VMware
 CVE-2026-47852 (A local attacker on a multi-user host can pre-create the deterministic ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7130adf64f79c93a89be3a127457d6f8ab5e198d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7130adf64f79c93a89be3a127457d6f8ab5e198d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/c20c626c/attachment.htm>


More information about the debian-security-tracker-commits mailing list