[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Sep 9 21:25:55 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
c6b05d9c by Salvatore Bonaccorso at 2026-09-09T22:24:47+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -43,9 +43,9 @@ CVE-2026-87823 (zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on
CVE-2026-87822 (t-digest versions 3.1 through 3.3 fail to validate centroid means duri ...)
TODO: check
CVE-2026-87821 (Lara Dashboard through 1.3.1 contains a server-side request forgery vu ...)
- TODO: check
+ NOT-FOR-US: Lara Dashboard
CVE-2026-87820 (CyberPanel versions 2.4.3 through 2.4.5 expose unauthenticated AI Scan ...)
- TODO: check
+ NOT-FOR-US: CyberPanel
CVE-2026-87819 (GitPython before 3.1.60 contains a regular expression denial of servic ...)
TODO: check
CVE-2026-87818 (GitPython 3.1.59 fails to restrict the --no-index option in the high-l ...)
@@ -53,7 +53,7 @@ CVE-2026-87818 (GitPython 3.1.59 fails to restrict the --no-index option in the
CVE-2026-87817 (GitPython before 3.1.60 fails to properly validate the git directory l ...)
TODO: check
CVE-2026-87816 (PasswordPusher before 2.11.1 contains a time-of-check-to-time-of-use r ...)
- TODO: check
+ NOT-FOR-US: PasswordPusher
CVE-2026-87815 (SiYuan versions before v3.8.2 contain a path traversal vulnerability i ...)
NOT-FOR-US: SiYuan
CVE-2026-87814 (SiYuan before v3.8.2 contains a stored cross-site scripting vulnerabil ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c6b05d9c4c447f272c90422f8e4cd40129662895
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c6b05d9c4c447f272c90422f8e4cd40129662895
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260909/af3571ca/attachment.htm>
More information about the debian-security-tracker-commits
mailing list