[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Sun Sep 6 11:02:17 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
9d3c4cf7 by Moritz Muehlenhoff at 2026-09-06T12:01:57+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -948,19 +948,19 @@ CVE-2026-19283 (IBM Observability with Instana (Agent) Build 1.0.303 through 1.0
CVE-2026-19274 (IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 I ...)
NOT-FOR-US: IBM
CVE-2026-19205 (Observable response discrepancy vulnerability in GastroMenum GastroMen ...)
- TODO: check
+ NOT-FOR-US: GastroMenum
CVE-2026-19081 (Missing Authorization vulnerability in Gastromenum Gastromenum Ticket ...)
- TODO: check
+ NOT-FOR-US: GastroMenum
CVE-2026-19080 (Observable response discrepancy vulnerability in Menulux Software Inc. ...)
- TODO: check
+ NOT-FOR-US: Menulux
CVE-2026-19057 (Improper neutralization of input during web page generation ('cross-si ...)
- TODO: check
+ NOT-FOR-US: GastroMenum
CVE-2026-19051 (Plaintext storage of a password vulnerability in Menulux Software Inc. ...)
- TODO: check
+ NOT-FOR-US: Menulux
CVE-2026-19043 (Missing Authorization vulnerability in Menulux Software Inc. Menulux P ...)
- TODO: check
+ NOT-FOR-US: Menulux
CVE-2026-18957 (Improper neutralization of input during web page generation ('cross-si ...)
- TODO: check
+ NOT-FOR-US: Menulux
CVE-2026-18905 (IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MC ...)
NOT-FOR-US: IBM
CVE-2026-18887 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to ...)
@@ -991,7 +991,7 @@ CVE-2026-18341 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated
CVE-2026-18221 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain una ...)
NOT-FOR-US: IBM
CVE-2026-18198 (Improper neutralization of special elements used in an SQL command ('S ...)
- TODO: check
+ NOT-FOR-US: GOLDENHORN ONEIT
CVE-2026-18175 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipula ...)
NOT-FOR-US: IBM
CVE-2026-18149 (undici's retry handler can leave an already-exposed response body pend ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9d3c4cf7216824c888d22ed00bf8e8cf9531a7a0
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9d3c4cf7216824c888d22ed00bf8e8cf9531a7a0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260906/26e739c4/attachment.htm>
More information about the debian-security-tracker-commits
mailing list