[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 5 09:06:46 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
6fe799f9 by Salvatore Bonaccorso at 2026-09-05T10:06:21+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,5 +1,5 @@
 CVE-2026-9317 (Nango before 0.71.6 contains a missing authentication vulnerability in ...)
-	TODO: check
+	NOT-FOR-US: Nango
 CVE-2026-9186 (IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated atta ...)
 	NOT-FOR-US: IBM
 CVE-2026-9138 (IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenti ...)
@@ -39,13 +39,13 @@ CVE-2026-86137 (In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-b
 	NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1099
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/76fe08d97de88bfaef2f7d5cd27f11954cc5bee2 (v2.15.4)
 CVE-2026-86100 (Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect ta ...)
-	TODO: check
+	NOT-FOR-US: Camaleon CMS
 CVE-2026-86098 (ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerabi ...)
 	TODO: check
 CVE-2026-86097 (PX4 Autopilot through 1.17.0 contains a null pointer dereference vulne ...)
-	TODO: check
+	NOT-FOR-US: PX4 Autopilot
 CVE-2026-86096 (PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability i ...)
-	TODO: check
+	NOT-FOR-US: PX4 Autopilot
 CVE-2026-86095 (Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulner ...)
 	TODO: check
 CVE-2026-86091 (ntopng before 6.7.260717 fails to check user privileges in the pools b ...)
@@ -61,161 +61,161 @@ CVE-2026-85781 (Unverified ownership of a storage access point in the volume del
 CVE-2026-85769 (A flaw was found in libtpms, a library that provides software TPM 2.0  ...)
 	TODO: check
 CVE-2026-85730 (smol-toml is a small, fast, and correct TOML parser and serializer. Pr ...)
-	TODO: check
+	NOT-FOR-US: smol-toml
 CVE-2026-85704 (A security flaw has been discovered in ramon-victor freegpt-webui up t ...)
-	TODO: check
+	NOT-FOR-US: ramon-victor freegpt-webui
 CVE-2026-85703 (A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41 ...)
-	TODO: check
+	NOT-FOR-US: ramon-victor freegpt-webui
 CVE-2026-85702 (A security vulnerability has been detected in ramon-victor freegpt-web ...)
-	TODO: check
+	NOT-FOR-US: ramon-victor freegpt-webui
 CVE-2026-85701 (A vulnerability has been found in ramon-victor freegpt-webui up to 098 ...)
-	TODO: check
+	NOT-FOR-US: ramon-victor freegpt-webui
 CVE-2026-85700 (Onyx 4.6.6 fails to properly restrict access to custom tool credential ...)
-	TODO: check
+	NOT-FOR-US: Onyx
 CVE-2026-85699 (jina-ai reader contains a server-side request forgery vulnerability wh ...)
-	TODO: check
+	NOT-FOR-US: jina-ai reader
 CVE-2026-85698 (Turso through 0.8.0-pre.8 contains an out-of-bounds read vulnerability ...)
-	TODO: check
+	NOT-FOR-US: Turso
 CVE-2026-85697 (Documenso 2.17.0 contains an access control vulnerability in the PDF-s ...)
-	TODO: check
+	NOT-FOR-US: Documenso
 CVE-2026-85696 (SadTalker contains an OS command injection vulnerability in the video  ...)
-	TODO: check
+	NOT-FOR-US: SadTalker
 CVE-2026-85695 (FastChat contains an authentication bypass vulnerability in the /regis ...)
-	TODO: check
+	NOT-FOR-US: FastChat
 CVE-2026-85694 (LaVague 0.2.35 contains a remote code execution vulnerability in Pytho ...)
-	TODO: check
+	NOT-FOR-US: LaVague
 CVE-2026-85693 (Chatbot UI contains an authorization bypass vulnerability in the retri ...)
-	TODO: check
+	NOT-FOR-US: Chatbot UI
 CVE-2026-85692 (Nightingale (n9e), as of commit 8362cbe (main branch, confirmed 2026-0 ...)
-	TODO: check
+	NOT-FOR-US: Nightingale (n9e)
 CVE-2026-85691 (MegaParse 0.0.55 contains an unauthenticated server-side request forge ...)
-	TODO: check
+	NOT-FOR-US: MegaParse
 CVE-2026-85690 (Plandex 2.2.1 contains a path traversal vulnerability in the ApplyFile ...)
-	TODO: check
+	NOT-FOR-US: Plandex
 CVE-2026-85689 (llmware 0.4.6 contains an SQL injection vulnerability in the collectio ...)
-	TODO: check
+	NOT-FOR-US: llmware
 CVE-2026-85688 (TEN Framework 0.11.71 contains unauthenticated arbitrary file read and ...)
-	TODO: check
+	NOT-FOR-US: TEN Framework
 CVE-2026-85687 (surya 0.22.1 screenshot server contains an unauthenticated arbitrary f ...)
-	TODO: check
+	NOT-FOR-US: surya
 CVE-2026-85686 (ms-swift 4.5.2 contains a server-side request forgery vulnerability in ...)
-	TODO: check
+	NOT-FOR-US: ms-swift
 CVE-2026-85685 (AgentScope through 2.0.7.post1 contains a path traversal vulnerability ...)
-	TODO: check
+	NOT-FOR-US: AgentScope
 CVE-2026-85684 (marker through 2.0.0 contains a path traversal vulnerability in the Fa ...)
-	TODO: check
+	NOT-FOR-US: marker
 CVE-2026-85676 (Dub contains an open redirect vulnerability in the redir_url query par ...)
-	TODO: check
+	NOT-FOR-US: Dub
 CVE-2026-85675 (OWL's DocumentProcessingToolkit contains a server-side request forgery ...)
-	TODO: check
+	NOT-FOR-US: OWL
 CVE-2026-85674 (aider (aider-chat) automatically loads a .aider.conf.yml configuration ...)
-	TODO: check
+	NOT-FOR-US: aider (aider-chat)
 CVE-2026-85673 (LLaMA-Factory contains a server-side request forgery vulnerability in  ...)
-	TODO: check
+	NOT-FOR-US: LLaMA-Factory
 CVE-2026-85672 (zerox 1.1.20 contains an OS command injection vulnerability in the fil ...)
-	TODO: check
+	NOT-FOR-US: zerox
 CVE-2026-85671 (QAnything 2.0.0 contains an authentication bypass vulnerability in the ...)
-	TODO: check
+	NOT-FOR-US: QAnything
 CVE-2026-85670 (tokenizers (Hugging Face) is affected by an out-of-bounds buffer acces ...)
-	TODO: check
+	NOT-FOR-US: tokenizers (Hugging Face)
 CVE-2026-85669 (potpie through 2.0.0 fails to verify user ownership on the POST /conve ...)
-	TODO: check
+	NOT-FOR-US: potpie
 CVE-2026-85668 (Xinference (affected commit 4a94832, v3.x) contains an unauthenticated ...)
-	TODO: check
+	NOT-FOR-US: Xinference
 CVE-2026-85667 (xiaobei through 5.5.2 fails to implement authentication or signature v ...)
-	TODO: check
+	NOT-FOR-US: xiaobei
 CVE-2026-85666 (OGX (formerly Llama Stack, affected at commit fbe8e0f) contains an una ...)
-	TODO: check
+	NOT-FOR-US: OGX
 CVE-2026-85665 (Bruno versions through 3.4.2 fail to validate file paths in request bo ...)
-	TODO: check
+	NOT-FOR-US: Bruno
 CVE-2026-85664 (Chroma 1.5.9 fails to validate maximum bounds on HNSW index parameters ...)
-	TODO: check
+	NOT-FOR-US: Chroma
 CVE-2026-85663 (Aim 3.29.1 remote tracking server fails to authenticate requests and d ...)
-	TODO: check
+	NOT-FOR-US: Aim
 CVE-2026-85662 (Marqo 2.26.0 contains a server-side request forgery vulnerability in t ...)
-	TODO: check
+	NOT-FOR-US: Marqo
 CVE-2026-85661 (excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode ...)
-	TODO: check
+	NOT-FOR-US: excel-mcp-server
 CVE-2026-85660 (cli-mcp-server 0.2.5 contains a command allowlist bypass vulnerability ...)
-	TODO: check
+	NOT-FOR-US: cli-mcp-server
 CVE-2026-85656 (An OS command injection issue in the log4j-cve-2021-44228-hotpatch pac ...)
 	NOT-FOR-US: Amazon
 CVE-2026-85654 (Improper neutralization of special elements used in a template engine  ...)
 	NOT-FOR-US: Amazon
 CVE-2026-85651 (Trigger.dev versions before 4.5.2 fail to validate environment members ...)
-	TODO: check
+	NOT-FOR-US: Trigger.dev
 CVE-2026-85650 (Trigger.dev before 4.5.2 contains a server-side request forgery vulner ...)
-	TODO: check
+	NOT-FOR-US: Trigger.dev
 CVE-2026-85649 ((Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fa ...)
-	TODO: check
+	NOT-FOR-US: (Holloway) Chew software-actualizer
 CVE-2026-85643 (A flaw has been found in code-projects Online Shopping System 1.0. Imp ...)
 	NOT-FOR-US: code-projects
 CVE-2026-85639 (A security vulnerability has been detected in jofpin trape 2.0. This v ...)
-	TODO: check
+	NOT-FOR-US: jofpin trape
 CVE-2026-85638 (A weakness has been identified in jofpin trape 2.0. This affects an un ...)
-	TODO: check
+	NOT-FOR-US: jofpin trape
 CVE-2026-85637 (A security flaw has been discovered in jofpin trape 1.0.0/2.0. Affecte ...)
-	TODO: check
+	NOT-FOR-US: jofpin trape
 CVE-2026-85636 (A vulnerability was identified in jofpin trape 1.0.0. Affected by this ...)
-	TODO: check
+	NOT-FOR-US: jofpin trape
 CVE-2026-85626 (git-mcp-server 2.15.1 contains an argument injection vulnerability in  ...)
-	TODO: check
+	NOT-FOR-US: git-mcp-server
 CVE-2026-85625 (sift (sift.js) 17.1.3 enumerates query keys with for...in, which walks ...)
-	TODO: check
+	NOT-FOR-US: sift (sift.js)
 CVE-2026-85624 (Blinko 1.8.7 contains a cross-user private note disclosure vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: Blinko
 CVE-2026-85623 (goose 1.37.0 executes arbitrary commands from recipe stdio extensions  ...)
-	TODO: check
+	NOT-FOR-US: goose
 CVE-2026-85622 (AppFlowy-Cloud through 0.9.64 fails to validate workspace membership w ...)
-	TODO: check
+	NOT-FOR-US: AppFlowy-Cloud
 CVE-2026-85621 (LobeChat (LobeHub) 2.2.1 does not properly verify inbound chat-platfor ...)
-	TODO: check
+	NOT-FOR-US: LobeChat (LobeHub)
 CVE-2026-85620 (Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability ...)
-	TODO: check
+	NOT-FOR-US: Postgres MCP Pro
 CVE-2026-85619 (AppFlowy-Cloud 0.9.64 fails to verify that requested collab objects be ...)
-	TODO: check
+	NOT-FOR-US: AppFlowy-Cloud
 CVE-2026-85618 (ConvertX 0.17.0 contains an arbitrary file read vulnerability in the x ...)
-	TODO: check
+	NOT-FOR-US: ConvertX
 CVE-2026-85617 (snipe-it versions before 8.6.3 contain an authorization bypass vulnera ...)
 	TODO: check
 CVE-2026-85616 (Snipe-IT versions before 8.6.2 contain an authorization bypass vulnera ...)
 	TODO: check
 CVE-2026-85615 (Openpanel before 2.3.0 contains an insecure direct object reference vu ...)
-	TODO: check
+	NOT-FOR-US: Openpanel
 CVE-2026-85614 (OpenPanel before 2.3.0 contains an unauthenticated server-side request ...)
-	TODO: check
+	NOT-FOR-US: Openpanel
 CVE-2026-85613 (OpenPanel before 2.3.0 contains a cross-site scripting vulnerability i ...)
-	TODO: check
+	NOT-FOR-US: Openpanel
 CVE-2026-85612 (OpenPanel before 2.3.0 contains an unauthenticated server-side request ...)
-	TODO: check
+	NOT-FOR-US: Openpanel
 CVE-2026-85611 (OpenPanel before 2.3.0 contains a cross-tenant broken object level aut ...)
-	TODO: check
+	NOT-FOR-US: Openpanel
 CVE-2026-85610 (OpenPanel before 2.3.0 fails to properly validate chart formula expres ...)
-	TODO: check
+	NOT-FOR-US: Openpanel
 CVE-2026-85609 (Openpanel before 2.3.0 contains an unauthenticated full-read server-si ...)
-	TODO: check
+	NOT-FOR-US: Openpanel
 CVE-2026-85608 (Douyin_TikTok_Download_API through 4.1.2 contains a server-side reques ...)
-	TODO: check
+	NOT-FOR-US: Douyin_TikTok_Download_API
 CVE-2026-85607 (Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in  ...)
-	TODO: check
+	NOT-FOR-US: Blinko
 CVE-2026-85606 (firecrawl-mcp-server 3.20.2 contains an arbitrary local file read vuln ...)
-	TODO: check
+	NOT-FOR-US: firecrawl-mcp-server
 CVE-2026-85605 (Slink before 1.12.3 fails to properly authorize access to image commen ...)
-	TODO: check
+	NOT-FOR-US: Slink
 CVE-2026-85604 (Grav before 2.0.19 (affected versions <= 2.0.17) contains a remote cod ...)
-	TODO: check
+	NOT-FOR-US: Grav CMS
 CVE-2026-85603 (Grav versions before 1.10.55 contain a path traversal vulnerability in ...)
-	TODO: check
+	NOT-FOR-US: Grav CMS
 CVE-2026-85602 (The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through ...)
-	TODO: check
+	NOT-FOR-US: Grav CMS plugin
 CVE-2026-85601 (Grav Admin before 2.0.20 fails to sanitize output from marked.parse()  ...)
-	TODO: check
+	NOT-FOR-US: Grav plugin
 CVE-2026-85600 (Grav Admin (getgrav/grav-plugin-admin2) versions <= 2.0.19 contain a s ...)
-	TODO: check
+	NOT-FOR-US: Grav plugin
 CVE-2026-85599 (Grav Shortcode Core before 6.2.5 contains stored cross-site scripting  ...)
-	TODO: check
+	NOT-FOR-US: Grav plugin
 CVE-2026-85598 (Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detecti ...)
-	TODO: check
+	NOT-FOR-US: Grav CMS
 CVE-2026-85597 (Traefik before v2.11.55 contains a TLS option conflict resolution vuln ...)
 	TODO: check
 CVE-2026-85596 (Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication by ...)
@@ -225,21 +225,21 @@ CVE-2026-85595 (Traefik versions before v2.11.55 contain an authentication bypas
 CVE-2026-85594 (Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces r ...)
 	TODO: check
 CVE-2026-85593 (phpMyFAQ versions before 4.1.8 contain a stored cross-site scripting v ...)
-	TODO: check
+	NOT-FOR-US: phpMyFAQ
 CVE-2026-85592 (phpMyFAQ before 4.1.8 contains an authorization bypass vulnerability i ...)
-	TODO: check
+	NOT-FOR-US: phpMyFAQ
 CVE-2026-85591 (phpMyFAQ versions before 4.1.8 contain an authentication bypass vulner ...)
-	TODO: check
+	NOT-FOR-US: phpMyFAQ
 CVE-2026-85590 (phpMyFAQ before 4.1.8 contains an authentication bypass vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: phpMyFAQ
 CVE-2026-85589 (phpMyFAQ before 4.2.0-alpha.2 contains a missing authorization vulnera ...)
-	TODO: check
+	NOT-FOR-US: phpMyFAQ
 CVE-2026-85588 (phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in pla ...)
-	TODO: check
+	NOT-FOR-US: phpMyFAQ
 CVE-2026-85587 (phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin co ...)
-	TODO: check
+	NOT-FOR-US: phpMyFAQ
 CVE-2026-85586 (phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store ...)
-	TODO: check
+	NOT-FOR-US: phpMyFAQ
 CVE-2026-85585 (SiYuan before v3.8.2 contains an unbounded resource consumption vulner ...)
 	NOT-FOR-US: SiYuan
 CVE-2026-85584 (SiYuan versions before v3.8.2 contain a denial of service vulnerabilit ...)
@@ -257,15 +257,15 @@ CVE-2026-85579 (SiYuan is affected by an information disclosure vulnerability (c
 CVE-2026-85578 (SiYuan through 3.8.1 contains an authorization bypass vulnerability in ...)
 	NOT-FOR-US: SiYuan
 CVE-2026-85577 (AVideo through commit c91b5975d contains a reflected cross-site script ...)
-	TODO: check
+	NOT-FOR-US: WWBN AVideo
 CVE-2026-85547 (A cross-site request forgery (CSRF) vulnerability exists in MISP due t ...)
 	TODO: check
 CVE-2026-85546 (MISP contains a cross-site request forgery (CSRF) vulnerability in the ...)
 	TODO: check
 CVE-2026-85541 (DreamMaker developed by Interinfo has a Reflected Cross-site Scripting ...)
-	TODO: check
+	NOT-FOR-US: Interinfo
 CVE-2026-85540 (DreamMaker developed by Interinfo has a SQL Injection vulnerability. A ...)
-	TODO: check
+	NOT-FOR-US: Interinfo
 CVE-2026-85538 (An incorrect authorization vulnerability in MISP allowed authenticated ...)
 	TODO: check
 CVE-2026-85534 (A flaw was found in libsoup. When a client sends an HTTP/2 request bod ...)
@@ -273,9 +273,9 @@ CVE-2026-85534 (A flaw was found in libsoup. When a client sends an HTTP/2 reque
 CVE-2026-85533 (An authorization flaw in MISP allowed an authenticated user to submit  ...)
 	TODO: check
 CVE-2026-85528 (Improper input validation of the auto-configuration account identifier ...)
-	TODO: check
+	NOT-FOR-US: Snowflake JDBC Driver
 CVE-2026-85525 (Improper OCSP response validation in the Snowflake Python, Go, JDBC, a ...)
-	TODO: check
+	NOT-FOR-US: Snowflake Drivers
 CVE-2026-85522 (A vulnerability was detected in valkey-io valkey up to 9.5.4/9.1.0. Af ...)
 	TODO: check
 CVE-2026-85517 (A flaw has been found in code-projects Vehicle Management System 1.0.  ...)
@@ -283,9 +283,9 @@ CVE-2026-85517 (A flaw has been found in code-projects Vehicle Management System
 CVE-2026-85516 (A vulnerability was detected in code-projects Vehicle Management Syste ...)
 	NOT-FOR-US: code-projects
 CVE-2026-85514 (A security vulnerability has been detected in StackStorm st2 up to 3.9 ...)
-	TODO: check
+	NOT-FOR-US: StackStorm
 CVE-2026-85513 (A weakness has been identified in StackStorm st2 up to 3.9.0. This iss ...)
-	TODO: check
+	NOT-FOR-US: StackStorm
 CVE-2026-85512 (A security flaw has been discovered in SourceCodester Class and Exam T ...)
 	NOT-FOR-US: SourceCodester
 CVE-2026-85311 (Missing Authorization vulnerability in Kings Plugins MarketKing allows ...)
@@ -295,7 +295,7 @@ CVE-2026-85229 (** UNSUPPORTED WHEN ASSIGNED **Improper neutralization of input
 CVE-2026-85197 (A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the ...)
 	TODO: check
 CVE-2026-85184 (@fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to r ...)
-	TODO: check
+	NOT-FOR-US: fastify/middie
 CVE-2026-85152 (undici 8.10.0 omits the destination origin from the cache and request- ...)
 	TODO: check
 CVE-2026-85024 (undici bundles a WebSocket client whose permessage-deflate size-limit  ...)
@@ -339,11 +339,11 @@ CVE-2026-84890 (undici's decompress interceptor decompresses response bodies acc
 CVE-2026-84745 (The Events Calendar WordPress plugin before 6.17.3.1 does not restrict ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-84504 (fastify versions before 5.12.2 treat the object resolved by a successf ...)
-	TODO: check
+	NOT-FOR-US: fastify
 CVE-2026-84469 (fastify versions before 5.12.2 decide whether to compile a request sch ...)
-	TODO: check
+	NOT-FOR-US: fastify
 CVE-2026-84428 (fastify versions before 5.12.2 implement the case-insensitive nature o ...)
-	TODO: check
+	NOT-FOR-US: fastify
 CVE-2026-84225 (The Kirki  WordPress plugin before 6.3.0 does not check that a user is ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-84221 (The Kirki  WordPress plugin before 6.3.0 does not escape a user-suppli ...)
@@ -369,7 +369,7 @@ CVE-2026-83543 (The Greenshift  WordPress plugin before 13.2.0 does not validate
 CVE-2026-82923 (The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-82911 (Cross-Site Request Forgery (CSRF) in the OrderConfirmController at GET ...)
-	TODO: check
+	NOT-FOR-US: Roskus Prospero Flow CRM
 CVE-2026-82846 (The Masteriyo LMS  WordPress plugin before 3.4.0 does not sanitise and ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-82729 (Inefficient Algorithmic Complexity vulnerability in elixir-mint mint a ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6fe799f91d16a3ff9c4df9ecd10bcbd4b81dcf87

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6fe799f91d16a3ff9c4df9ecd10bcbd4b81dcf87
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260905/2c7793ed/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list