[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Sun Sep 6 22:15:23 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
1f7d492a by Moritz Muehlenhoff at 2026-09-06T23:15:03+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,45 +1,45 @@
CVE-2026-86283 (MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collection ...)
- TODO: check
+ - misp <itp> (bug #1144317)
CVE-2026-86259 (OpenMAIC before 1.0.1 skips server-side request forgery validation in ...)
- TODO: check
+ NOT-FOR-US: OpenMAIC
CVE-2026-86258 (nbviewer through 1.0.1 contains a path traversal vulnerability in Loca ...)
- TODO: check
+ NOT-FOR-US: nbviewer
CVE-2026-86257 (wger before 2.6 fails to sanitize first_name and last_name fields in t ...)
- TODO: check
+ NOT-FOR-US: wger
CVE-2026-86256 (wger before 2.6 (affected versions <= 2.5.0) contains an open redirect ...)
- TODO: check
+ NOT-FOR-US: wger
CVE-2026-86255 (wger before 2.5 fails to validate the maximum duration of routine date ...)
- TODO: check
+ NOT-FOR-US: wger
CVE-2026-86254 (wger versions through master contain an incomplete authorization bypas ...)
- TODO: check
+ NOT-FOR-US: wger
CVE-2026-86253 (h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vuln ...)
- TODO: check
+ NOT-FOR-US: Node h3
CVE-2026-86252 (h3 versions before 1.15.9 fail to sanitize carriage return characters ...)
- TODO: check
+ NOT-FOR-US: Node h3
CVE-2026-86251 (h3 versions before 1.15.9 contain a path traversal vulnerability in th ...)
- TODO: check
+ NOT-FOR-US: Node h3
CVE-2026-86250 (h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed ...)
- TODO: check
+ NOT-FOR-US: Node h3
CVE-2026-86242 (Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin w ...)
- TODO: check
+ NOT-FOR-US: Bifrost
CVE-2026-86221 (A flaw has been found in SourceCodester Class and Exam Timetabling Sys ...)
NOT-FOR-US: SourceCodester
CVE-2026-86220 (A vulnerability was detected in SourceCodester Class and Exam Timetabl ...)
NOT-FOR-US: SourceCodester
CVE-2026-86217 (A vulnerability was detected in code-projects Hotel and Tourism Reserv ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-86216 (A security vulnerability has been detected in code-projects Hotel and ...)
NOT-FOR-US: code-projects
CVE-2026-86215 (A vulnerability was identified in Mstfakts College-Management-System. ...)
- TODO: check
+ NOT-FOR-US: Mstfakts College-Management-System
CVE-2026-86214 (A vulnerability was determined in Mstfakts College-Management-System. ...)
- TODO: check
+ NOT-FOR-US: Mstfakts College-Management-System
CVE-2026-86213 (A vulnerability was found in Mstfakts College-Management-System. This ...)
- TODO: check
+ NOT-FOR-US: Mstfakts College-Management-System
CVE-2026-86212 (A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerabil ...)
- TODO: check
+ - open5gs <itp> (bug #1094791)
CVE-2026-86211 (A flaw has been found in rabindralamsal inventory-management-system 1. ...)
- TODO: check
+ NOT-FOR-US: inventory-management-system
CVE-2026-86210 (A security vulnerability has been detected in SourceCodester Class and ...)
NOT-FOR-US: SourceCodester
CVE-2026-86209 (A weakness has been identified in SourceCodester Class and Exam Timeta ...)
@@ -47,25 +47,25 @@ CVE-2026-86209 (A weakness has been identified in SourceCodester Class and Exam
CVE-2026-86208 (A security flaw has been discovered in SourceCodester Class and Exam T ...)
NOT-FOR-US: SourceCodester
CVE-2026-86205 (h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability ...)
- TODO: check
+ NOT-FOR-US: Node h3
CVE-2026-86183 (A vulnerability was identified in diem-project diem up to 5.1.3. This ...)
- TODO: check
+ NOT-FOR-US: diem-project diem
CVE-2026-86182 (A vulnerability was determined in diem-project diem up to 5.1.3. This ...)
- TODO: check
+ NOT-FOR-US: diem-project diem
CVE-2026-86181 (A vulnerability was found in code-projects Task Management System 1.0. ...)
NOT-FOR-US: code-projects
CVE-2026-86180 (A vulnerability has been found in code-projects Task Management System ...)
NOT-FOR-US: code-projects
CVE-2026-86179 (A flaw has been found in code-projects Daily Expense Manager 1.0. Affe ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-86172 (A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts ...)
- TODO: check
+ NOT-FOR-US: DefaultFuction CRM
CVE-2026-83534 (PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_d ...)
- TODO: check
+ NOT-FOR-US: PostgreSQL Anonymizer
CVE-2026-82751 (Improper Validation of Specified Quantity in Input in ZenHive mpp allo ...)
- TODO: check
+ NOT-FOR-US: ZenHive mpp
CVE-2026-82750 (Improper Validation of Specified Quantity in Input in ZenHive mpp allo ...)
- TODO: check
+ NOT-FOR-US: ZenHive mpp
CVE-2026-80439 (The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before ...)
NOT-FOR-US: WordPress plugin
CVE-2026-80437 (The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not p ...)
@@ -75,19 +75,19 @@ CVE-2026-19862 (The JetFormBuilder WordPress plugin before 3.6.5.2 does not vali
CVE-2026-19859 (The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a ...)
NOT-FOR-US: WordPress plugin
CVE-2026-19634 (PostgreSQL Anonymizer contains a SQL injection vulnerability in two im ...)
- TODO: check
+ NOT-FOR-US: PostgreSQL Anonymizer
CVE-2026-19633 (PostgreSQL Anonymizer contains a vulnerability that allows unprivilege ...)
- TODO: check
+ NOT-FOR-US: PostgreSQL Anonymizer
CVE-2022-51009 (PocketMine-MP before 4.7.2 fails to properly handle exceptions from th ...)
- TODO: check
+ NOT-FOR-US: PocketMine-MP
CVE-2022-51008 (PocketMine-MP before 4.12.3 fails to limit unauthenticated sessions, a ...)
- TODO: check
+ NOT-FOR-US: PocketMine-MP
CVE-2021-48007 (PocketMine-MP versions before 3.18.1 fail to validate NaN or INF value ...)
- TODO: check
+ NOT-FOR-US: PocketMine-MP
CVE-2021-48006 (PocketMine-MP before 4.0.3 does not perform case-insensitive matching ...)
- TODO: check
+ NOT-FOR-US: PocketMine-MP
CVE-2020-37277 (PocketMine-MP versions before 3.15.4 contain a denial of service vulne ...)
- TODO: check
+ NOT-FOR-US: PocketMine-MP
CVE-2026-86219 (Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept ...)
- libauthen-sasl-perl <unfixed>
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43326063/
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1f7d492a124057be13daa14bfd0bda996c50409c
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1f7d492a124057be13daa14bfd0bda996c50409c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260906/63f65e23/attachment.htm>
More information about the debian-security-tracker-commits
mailing list