[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Sep 8 08:53:44 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4bb897d8 by Salvatore Bonaccorso at 2026-09-08T09:53:22+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -43,25 +43,25 @@ CVE-2026-86437 (Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/
 CVE-2026-86436 (Lara Dashboard before 1.3.2 fails to authorize access to the post-buil ...)
 	NOT-FOR-US: Lara Dashboard
 CVE-2026-82758 (Improper Authentication vulnerability in ash-project ash_authenticatio ...)
-	TODO: check
+	NOT-FOR-US: ash-project
 CVE-2026-82757 (Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_au ...)
-	TODO: check
+	NOT-FOR-US: ash-project
 CVE-2026-82756 (Improper Encoding or Escaping of Output vulnerability in ash-project a ...)
-	TODO: check
+	NOT-FOR-US: ash-project
 CVE-2026-82755 (Use of Cache Containing Sensitive Information vulnerability in ash-pro ...)
-	TODO: check
+	NOT-FOR-US: ash-project
 CVE-2026-82754 (Improper Protection of Alternate Path vulnerability in ash-project ash ...)
-	TODO: check
+	NOT-FOR-US: ash-project
 CVE-2026-82753 (Allocation of Resources Without Limits or Throttling vulnerability in  ...)
-	TODO: check
+	NOT-FOR-US: ash-project
 CVE-2026-82710 (Improper Neutralization of Escape, Meta, or Control Sequences vulnerab ...)
-	TODO: check
+	NOT-FOR-US: ash-project
 CVE-2026-82586 (Improper Protection of Alternate Path vulnerability in ash-project ash ...)
-	TODO: check
+	NOT-FOR-US: ash-project
 CVE-2026-82584 (Improper Neutralization of Escape, Meta, or Control Sequences vulnerab ...)
-	TODO: check
+	NOT-FOR-US: ash-project
 CVE-2026-81638 (Improper Handling of Alternate Encoding vulnerability in ash-project a ...)
-	TODO: check
+	NOT-FOR-US: ash-project
 CVE-2026-76977 (SAP UI5 does not sufficiently validate the parent frame's origin again ...)
 	NOT-FOR-US: SAP
 CVE-2026-76971 (Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manuf ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4bb897d8c8e6293da2733a811e5ed5fcc5e5ce13

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4bb897d8c8e6293da2733a811e5ed5fcc5e5ce13
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260908/26d8c3c4/attachment.htm>


More information about the debian-security-tracker-commits mailing list