[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Sep 10 04:48:34 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
60aba674 by Salvatore Bonaccorso at 2026-09-10T05:46:52+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -28,7 +28,7 @@ CVE-2026-87872 (A flaw was found in the OCAPI modules (ocapi_command, ocapi_info
 CVE-2026-87853 (A flaw was found in SSSD's IdP authentication provider. The eval_acces ...)
 	TODO: check
 CVE-2026-87827 (Certain KGUARD DVR devices running vulnerable firmware expose a system ...)
-	TODO: check
+	NOT-FOR-US: KGUARD DVR devices
 CVE-2026-87825 (zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where ...)
 	- zstd-jni-java <unfixed>
 	NOTE: https://github.com/luben/zstd-jni/security/advisories/GHSA-947w-pxjj-c7m9
@@ -43,7 +43,7 @@ CVE-2026-87823 (zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on
 	NOTE: https://github.com/luben/zstd-jni/security/advisories/GHSA-jfr6-9xqw-2g2q
 	NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/d7a1c99322d5e1fc71932e722c0b5bb2fc525d3f (v1.5.7-14)
 CVE-2026-87822 (t-digest versions 3.1 through 3.3 fail to validate centroid means duri ...)
-	TODO: check
+	NOT-FOR-US: t-digest
 CVE-2026-87821 (Lara Dashboard through 1.3.1 contains a server-side request forgery vu ...)
 	NOT-FOR-US: Lara Dashboard
 CVE-2026-87820 (CyberPanel versions 2.4.3 through 2.4.5 expose unauthenticated AI Scan ...)
@@ -84,13 +84,13 @@ CVE-2026-87795 (zstd-jni versions before 1.5.7-14 fail to validate offset and le
 	NOTE: https://github.com/luben/zstd-jni/security/advisories/GHSA-ff36-7w3w-g8rm
 	NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/0d64de4dee6606ff506be36c7f2e714ad0c80fdb (v1.5.7-14)
 CVE-2026-87794 (bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnera ...)
-	TODO: check
+	NOT-FOR-US: bestzip Node.js module
 CVE-2026-86777 (AlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to authori ...)
-	TODO: check
+	NOT-FOR-US: AlchemyCMS
 CVE-2026-86776 (KeePass versions 2.35 through 2.61.1 fail to validate KDBX header fiel ...)
 	TODO: check
 CVE-2026-86775 (knowns (npm package) versions <= 0.29.1 contain a path traversal vulne ...)
-	TODO: check
+	NOT-FOR-US: knowns-dev/knowns
 CVE-2026-86774 (Snipe-IT versions before 8.7.0 contain a broken access control vulnera ...)
 	- snipe-it <itp> (bug #1005172)
 CVE-2026-86773 (Snipe-IT through version 8.6.3 fails to perform object-level authoriza ...)
@@ -166,39 +166,39 @@ CVE-2026-86739 (Snipe-IT 8.6.3 and earlier do not check the return value of Stor
 CVE-2026-86547 (mrubyc through 4.0.0 contains a null pointer dereference vulnerability ...)
 	TODO: check
 CVE-2026-86204 (PocketMine-MP versions before 5.39.2 fail to limit JSON payload size i ...)
-	TODO: check
+	NOT-FOR-US: PocketMine-MP
 CVE-2026-86203 (PocketMine-MP versions before 5.39.2 fail to validate entity despawn s ...)
-	TODO: check
+	NOT-FOR-US: PocketMine-MP
 CVE-2026-86202 (PocketMine-MP versions before 5.39.2 contain a network amplification v ...)
-	TODO: check
+	NOT-FOR-US: PocketMine-MP
 CVE-2026-86201 (PocketMine-MP before 5.41.1 contains a denial of service vulnerability ...)
-	TODO: check
+	NOT-FOR-US: PocketMine-MP
 CVE-2026-86200 (PocketMine-MP versions before 5.42.1 contain a denial of service vulne ...)
-	TODO: check
+	NOT-FOR-US: PocketMine-MP
 CVE-2026-86199 (PocketMine-MP versions before 5.43.1 fail to properly validate the Cer ...)
-	TODO: check
+	NOT-FOR-US: PocketMine-MP
 CVE-2026-86198 (PocketMine-MP versions before 5.44.2 fail to properly validate multipl ...)
-	TODO: check
+	NOT-FOR-US: PocketMine-MP
 CVE-2026-86099 (Chainlit through 2.12.0 fails to validate the client-supplied socket.i ...)
-	TODO: check
+	NOT-FOR-US: Chainlit
 CVE-2026-85978 (An unauthenticated remote code execution vulnerability exists in the P ...)
-	TODO: check
+	NOT-FOR-US: Akana API Platform
 CVE-2026-85788 (Incomplete list of disallowed inputs in the mutable SQL detector compo ...)
 	NOT-FOR-US: Amazon
 CVE-2026-85103 (A heap-based buffer overflow in VPN certificate ASN.1 decoding may all ...)
-	TODO: check
+	NOT-FOR-US: Check Point
 CVE-2026-85102 (Improper certificate trust validation during VPN negotiation in Check  ...)
-	TODO: check
+	NOT-FOR-US: Check Point
 CVE-2026-83530 (A user could provide an expression whose string length is longer than  ...)
 	TODO: check
 CVE-2026-82563 (An attacker could impersonate the camera and place themselves in a man ...)
 	TODO: check
 CVE-2026-82530 (IP2Location Country Blocker plugin for WordPress before 2.45.0 contain ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-81640 (An attacker could derive the camera's Wi-Fi password and connect to it ...)
 	TODO: check
 CVE-2026-81330 (The C6 ear camera transmits live video to the EarVision Android applic ...)
-	TODO: check
+	NOT-FOR-US: C6 ear camera
 CVE-2026-80239 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 A ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-80177 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 A ...)
@@ -290,7 +290,7 @@ CVE-2026-79728 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG
 CVE-2026-79727 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 A ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-79696 (A Code Injection vulnerability in adk web in Google Cloud Agent Develo ...)
-	TODO: check
+	NOT-FOR-US: Google Cloud Agent Development Kit (ADK) for Python
 CVE-2026-79695 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 A ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-79694 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 A ...)
@@ -316,11 +316,11 @@ CVE-2026-79636 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG
 CVE-2026-79635 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 A ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-79617 (Incorrect Permission Assignment for Critical Resource vulnerability in ...)
-	TODO: check
+	NOT-FOR-US: Pardus LightDM Greeter
 CVE-2026-79323 (Information disclosure in the blogComments GraphQL query in Magefan Bl ...)
-	TODO: check
+	NOT-FOR-US: Magefan Blog GraphQL for Magento 2 (magefan/module-blog-graph-ql)
 CVE-2026-79322 (SQL injection in the RelatedProduct block in Mageplaza Blog for Magent ...)
-	TODO: check
+	NOT-FOR-US: Mageplaza Blog for Magento 2 (mageplaza/magento-2-blog-extension)
 CVE-2026-78494 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 A ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-78493 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 A ...)
@@ -346,7 +346,7 @@ CVE-2026-78482 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG
 CVE-2026-78481 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 A ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-78377 (URL redirection to untrusted site ('open redirect') vulnerability in Y ...)
-	TODO: check
+	NOT-FOR-US: Library Information and Document Automation Program
 CVE-2026-77974 (After spoofing the device and obtaining one user confirmation, an atta ...)
 	TODO: check
 CVE-2026-77120 (CWE-78: Improper Neutralization of Special Elements used in an OS Comm ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/60aba6742d2300e4f1533fcd8d06b5b10af84a02

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/60aba6742d2300e4f1533fcd8d06b5b10af84a02
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260910/a64dd159/attachment.htm>


More information about the debian-security-tracker-commits mailing list