[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sun Sep 6 22:15:23 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1f7d492a by Moritz Muehlenhoff at 2026-09-06T23:15:03+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,45 +1,45 @@
 CVE-2026-86283 (MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collection ...)
-	TODO: check
+	- misp <itp> (bug #1144317)
 CVE-2026-86259 (OpenMAIC before 1.0.1 skips server-side request forgery validation in  ...)
-	TODO: check
+	NOT-FOR-US: OpenMAIC
 CVE-2026-86258 (nbviewer through 1.0.1 contains a path traversal vulnerability in Loca ...)
-	TODO: check
+	NOT-FOR-US: nbviewer
 CVE-2026-86257 (wger before 2.6 fails to sanitize first_name and last_name fields in t ...)
-	TODO: check
+	NOT-FOR-US: wger
 CVE-2026-86256 (wger before 2.6 (affected versions <= 2.5.0) contains an open redirect ...)
-	TODO: check
+	NOT-FOR-US: wger
 CVE-2026-86255 (wger before 2.5 fails to validate the maximum duration of routine date ...)
-	TODO: check
+	NOT-FOR-US: wger
 CVE-2026-86254 (wger versions through master contain an incomplete authorization bypas ...)
-	TODO: check
+	NOT-FOR-US: wger
 CVE-2026-86253 (h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vuln ...)
-	TODO: check
+	NOT-FOR-US: Node h3
 CVE-2026-86252 (h3 versions before 1.15.9 fail to sanitize carriage return characters  ...)
-	TODO: check
+	NOT-FOR-US: Node h3
 CVE-2026-86251 (h3 versions before 1.15.9 contain a path traversal vulnerability in th ...)
-	TODO: check
+	NOT-FOR-US: Node h3
 CVE-2026-86250 (h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed ...)
-	TODO: check
+	NOT-FOR-US: Node h3
 CVE-2026-86242 (Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin w ...)
-	TODO: check
+	NOT-FOR-US: Bifrost
 CVE-2026-86221 (A flaw has been found in SourceCodester Class and Exam Timetabling Sys ...)
 	NOT-FOR-US: SourceCodester
 CVE-2026-86220 (A vulnerability was detected in SourceCodester Class and Exam Timetabl ...)
 	NOT-FOR-US: SourceCodester
 CVE-2026-86217 (A vulnerability was detected in code-projects Hotel and Tourism Reserv ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2026-86216 (A security vulnerability has been detected in code-projects Hotel and  ...)
 	NOT-FOR-US: code-projects
 CVE-2026-86215 (A vulnerability was identified in Mstfakts College-Management-System.  ...)
-	TODO: check
+	NOT-FOR-US: Mstfakts College-Management-System
 CVE-2026-86214 (A vulnerability was determined in Mstfakts College-Management-System.  ...)
-	TODO: check
+	NOT-FOR-US: Mstfakts College-Management-System
 CVE-2026-86213 (A vulnerability was found in Mstfakts College-Management-System. This  ...)
-	TODO: check
+	NOT-FOR-US: Mstfakts College-Management-System
 CVE-2026-86212 (A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerabil ...)
-	TODO: check
+	- open5gs <itp> (bug #1094791)
 CVE-2026-86211 (A flaw has been found in rabindralamsal inventory-management-system 1. ...)
-	TODO: check
+	NOT-FOR-US: inventory-management-system
 CVE-2026-86210 (A security vulnerability has been detected in SourceCodester Class and ...)
 	NOT-FOR-US: SourceCodester
 CVE-2026-86209 (A weakness has been identified in SourceCodester Class and Exam Timeta ...)
@@ -47,25 +47,25 @@ CVE-2026-86209 (A weakness has been identified in SourceCodester Class and Exam
 CVE-2026-86208 (A security flaw has been discovered in SourceCodester Class and Exam T ...)
 	NOT-FOR-US: SourceCodester
 CVE-2026-86205 (h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: Node h3
 CVE-2026-86183 (A vulnerability was identified in diem-project diem up to 5.1.3. This  ...)
-	TODO: check
+	NOT-FOR-US: diem-project diem
 CVE-2026-86182 (A vulnerability was determined in diem-project diem up to 5.1.3. This  ...)
-	TODO: check
+	NOT-FOR-US: diem-project diem
 CVE-2026-86181 (A vulnerability was found in code-projects Task Management System 1.0. ...)
 	NOT-FOR-US: code-projects
 CVE-2026-86180 (A vulnerability has been found in code-projects Task Management System ...)
 	NOT-FOR-US: code-projects
 CVE-2026-86179 (A flaw has been found in code-projects Daily Expense Manager 1.0. Affe ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2026-86172 (A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts ...)
-	TODO: check
+	NOT-FOR-US: DefaultFuction CRM
 CVE-2026-83534 (PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_d ...)
-	TODO: check
+	NOT-FOR-US: PostgreSQL Anonymizer
 CVE-2026-82751 (Improper Validation of Specified Quantity in Input in ZenHive mpp allo ...)
-	TODO: check
+	NOT-FOR-US: ZenHive mpp
 CVE-2026-82750 (Improper Validation of Specified Quantity in Input in ZenHive mpp allo ...)
-	TODO: check
+	NOT-FOR-US: ZenHive mpp
 CVE-2026-80439 (The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-80437 (The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not p ...)
@@ -75,19 +75,19 @@ CVE-2026-19862 (The JetFormBuilder WordPress plugin before 3.6.5.2 does not vali
 CVE-2026-19859 (The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-19634 (PostgreSQL Anonymizer contains a SQL injection vulnerability in two im ...)
-	TODO: check
+	NOT-FOR-US: PostgreSQL Anonymizer
 CVE-2026-19633 (PostgreSQL Anonymizer contains a vulnerability that allows unprivilege ...)
-	TODO: check
+	NOT-FOR-US: PostgreSQL Anonymizer
 CVE-2022-51009 (PocketMine-MP before 4.7.2 fails to properly handle exceptions from th ...)
-	TODO: check
+	NOT-FOR-US: PocketMine-MP
 CVE-2022-51008 (PocketMine-MP before 4.12.3 fails to limit unauthenticated sessions, a ...)
-	TODO: check
+	NOT-FOR-US: PocketMine-MP
 CVE-2021-48007 (PocketMine-MP versions before 3.18.1 fail to validate NaN or INF value ...)
-	TODO: check
+	NOT-FOR-US: PocketMine-MP
 CVE-2021-48006 (PocketMine-MP before 4.0.3 does not perform case-insensitive matching  ...)
-	TODO: check
+	NOT-FOR-US: PocketMine-MP
 CVE-2020-37277 (PocketMine-MP versions before 3.15.4 contain a denial of service vulne ...)
-	TODO: check
+	NOT-FOR-US: PocketMine-MP
 CVE-2026-86219 (Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept  ...)
 	- libauthen-sasl-perl <unfixed>
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/43326063/



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1f7d492a124057be13daa14bfd0bda996c50409c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1f7d492a124057be13daa14bfd0bda996c50409c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260906/63f65e23/attachment.htm>


More information about the debian-security-tracker-commits mailing list