[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Sep 10 20:15:09 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a019af30 by security tracker role at 2026-09-10T19:15:03+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
 CVE-2026-9338 (IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denia ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-9336 (IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denia ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-9166 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
 	TODO: check
 CVE-2026-9163 (Improper neutralization of special elements used in an SQL command ('S ...)
@@ -11,7 +11,7 @@ CVE-2026-9161 (Observable response discrepancy vulnerability in DernekPlus Websi
 CVE-2026-8323 (URL redirection to untrusted site ('open redirect') vulnerability in A ...)
 	TODO: check
 CVE-2026-89049 (A server-side request forgery issue due to improper validation of equi ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-89046 (zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds re ...)
 	TODO: check
 CVE-2026-89045 (zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative l ...)
@@ -127,51 +127,51 @@ CVE-2026-88770 (A flaw was found in the Device Authorization Grant flow of Keycl
 CVE-2026-88763 (A flaw was found in the skupper-router component of Red Hat Service In ...)
 	TODO: check
 CVE-2026-88290 (GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to  ...)
-	TODO: check
+	NOT-FOR-US: GeoVision
 CVE-2026-88289 (GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-control ...)
-	TODO: check
+	NOT-FOR-US: GeoVision
 CVE-2026-88288 (GeoVision GV-LPC2211 V1.13 fails to restrict the filename supplied to  ...)
-	TODO: check
+	NOT-FOR-US: GeoVision
 CVE-2026-88287 (GeoVision GV-LPC2211 V1.13 fails to bound the number of Scopes tokens  ...)
-	TODO: check
+	NOT-FOR-US: GeoVision
 CVE-2026-88286 (GeoVision GV-LPC2211 V1.13 improperly manages PTZ connection state, al ...)
-	TODO: check
+	NOT-FOR-US: GeoVision
 CVE-2026-88285 (GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control se ...)
-	TODO: check
+	NOT-FOR-US: GeoVision
 CVE-2026-88284 (GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ON ...)
-	TODO: check
+	NOT-FOR-US: GeoVision
 CVE-2026-88283 (GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ON ...)
-	TODO: check
+	NOT-FOR-US: GeoVision
 CVE-2026-88282 (GeoVision GV-LPC2211 V1.13 allows an administrator-controlled FTP user ...)
-	TODO: check
+	NOT-FOR-US: GeoVision
 CVE-2026-88281 (GeoVision GV-LPC2211 V1.13 fails to limit repeated Username elements i ...)
-	TODO: check
+	NOT-FOR-US: GeoVision
 CVE-2026-88280 (GeoVision GV-LPC2211 V1.13 copies an oversized ONVIF SetUser password  ...)
-	TODO: check
+	NOT-FOR-US: GeoVision
 CVE-2026-88279 (GeoVision GV-LPC2211 V1.13 copies oversized ONVIF CreateUsers username ...)
-	TODO: check
+	NOT-FOR-US: GeoVision
 CVE-2026-88278 (GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken  ...)
-	TODO: check
+	NOT-FOR-US: GeoVision
 CVE-2026-88277 (GeoVision GV-LPC2211 V1.13 allows an authenticated ONVIF user to injec ...)
-	TODO: check
+	NOT-FOR-US: GeoVision
 CVE-2026-88276 (GeoVision GV-LPC2211 V1.13 allows administrator-controlled WEP key val ...)
-	TODO: check
+	NOT-FOR-US: GeoVision
 CVE-2026-88275 (GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK  ...)
-	TODO: check
+	NOT-FOR-US: GeoVision
 CVE-2026-88274 (GeoVision GV-LPC2211 V1.13 allows an administrator-controlled wireless ...)
-	TODO: check
+	NOT-FOR-US: GeoVision
 CVE-2026-88273 (GeoVision GV-LPC2211 V1.13 allows an administrator-controlled PPPoE us ...)
-	TODO: check
+	NOT-FOR-US: GeoVision
 CVE-2026-88272 (GeoVision GV-LPC2211 V1.13 allows an administrator-controlled username ...)
-	TODO: check
+	NOT-FOR-US: GeoVision
 CVE-2026-88271 (GeoVision GV-LPC2211 V1.13 allows a Guest user to overwrite device con ...)
-	TODO: check
+	NOT-FOR-US: GeoVision
 CVE-2026-88270 (GeoVision GV-LPC2211 V1.13 allows a Guest user to enter SSVR firmware- ...)
-	TODO: check
+	NOT-FOR-US: GeoVision
 CVE-2026-88269 (GeoVision GV-LPC2211 V1.13 allows a Guest user to retrieve persistent  ...)
-	TODO: check
+	NOT-FOR-US: GeoVision
 CVE-2026-88268 (GeoVision GV-LPC2211 V1.13 contains an authenticated stack buffer over ...)
-	TODO: check
+	NOT-FOR-US: GeoVision
 CVE-2026-88265 (A flaw was found in crun. After pivot_root, reopening /dev/null for st ...)
 	TODO: check
 CVE-2026-88264 (A flaw was found in crun. When the container configuration does not gi ...)
@@ -279,9 +279,9 @@ CVE-2026-87962 (t-digest versions 3.1 through 3.3 contain a denial of service vu
 CVE-2026-87961 (ESP32-audioI2S versions 3.4.4 through 4.0.0 contain a heap-based out-o ...)
 	TODO: check
 CVE-2026-87913 (A missing S3 bucket ownership verification in the AWS Security Agent M ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-87912 (A missing S3 bucket ownership verification in the AWS Security Agent p ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-87803 (An authorization bypass vulnerability exists in the Countly Server DBV ...)
 	TODO: check
 CVE-2026-87107 (Consul and Consul Enterprise are vulnerable to an authorization bypass ...)
@@ -291,107 +291,107 @@ CVE-2026-87106 (Consul and Consul Enterprise are vulnerable to a denial of servi
 CVE-2026-87090 (Consul and Consul Enterprise are vulnerable to an authorization bypass ...)
 	TODO: check
 CVE-2026-85545 (There is an Vulnerability in some HikCentral Access Control versions.  ...)
-	TODO: check
+	NOT-FOR-US: Hikvision
 CVE-2026-85544 (There is an Improper Encryption Configuration Vulnerability in some Hi ...)
-	TODO: check
+	NOT-FOR-US: Hikvision
 CVE-2026-85543 (Some Wi-Fi series camera products have insufficient permission validat ...)
-	TODO: check
+	NOT-FOR-US: Hikvision
 CVE-2026-85310 (import_contacts Path Traversal in Groundhogg <= 4.7.1 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-85228 (An integer overflow in the tensor buffer validation component in Amazo ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-85217 (A maliciously crafted add-in, when installed and executed in Autodesk  ...)
-	TODO: check
+	NOT-FOR-US: Autodesk
 CVE-2026-84828 (A flaw was found in PCS (Pacemaker Configuration System). A local atta ...)
 	TODO: check
 CVE-2026-84821 (Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84819 (Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.3 versi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84816 (Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84042 (A flaw was found in crun. When crun is built with libkrun and a contai ...)
 	TODO: check
 CVE-2026-81805 (Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81804 (Unauthenticated Sensitive Data Exposure in ZHBackup \u2013 Backup, Res ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81803 (Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versio ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81801 (Subscriber Settings Change in WP-Stateless <= 4.4.1 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81800 (Unauthenticated SQL Injection in Verified Reviews (Avis V\xe9rifi\xe9s ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81799 (Unauthenticated Broken Access Control in Return Refund and Exchange Fo ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81796 (Unauthenticated Broken Authentication in WP Travel <= 12.0.3 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81795 (Unauthenticated Cross Site Scripting (XSS) in Page Visits Counter &#82 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81794 (Unauthenticated Broken Access Control in Shirt Product Designer for Wo ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81793 (Unauthenticated Broken Access Control in Salon booking system <= 10.31 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81791 (Subscriber Cross Site Scripting (XSS) in EventON <= 2.5.7 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81789 (Unauthenticated Arbitrary File Deletion in Advanced Product Fields Ext ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81788 (Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 ve ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81787 (Unauthenticated Broken Authentication in IMPress for IDX Broker <= 3.3 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81786 (Unauthenticated Broken Access Control in Thank You Page Customizer for ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81785 (Unauthenticated Broken Access Control in BuddyForms <= 2.9.0 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81784 (Unauthenticated PHP Object Injection in Wise Chat <= 3.4 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81783 (Subscriber Broken Authentication in MailMunch \u2013 Grow your Email L ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81782 (Subscriber Cross Site Scripting (XSS) in WP Docs <= 2.3.1 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81468 (Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper  ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81467 (Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper  ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81275 (Subscriber Arbitrary File Download in Youzify <= 1.3.7 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81052 (Dell ThinOS 10, versions prior to 2605_10.2616, contain a Download of  ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81051 (Dell ThinOS 10, versions prior to 2605_10.2616, contain a Security Ver ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81049 (Dell ThinOS 10, versions prior to 2605_10.2616, contain a Missing Supp ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81048 (Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Ne ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81046 (Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection M ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-80354 (Authorization bypass through User-Controlled key vulnerability in Apac ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-80352 (Improper Control of Generation of Code ('Code Injection') vulnerabilit ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-80351 (Improper neutralization of directives in dynamically evaluated code (' ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-7188 (Improper neutralization of special elements used in an SQL command ('S ...)
 	TODO: check
 CVE-2026-79987 (A remote, authenticated, non-admin Craft CMS Control Panel user with o ...)
-	TODO: check
+	NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-78536 (Unauthenticated Broken Access Control in Robokassa payment gateway for ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78374 (Joomla Extension - joomlart.com - Open mail relay via contact AJAX end ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-78303 (Joomla Extension - joomshaper.com - Unvalidated Email Destination & Fo ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-78302 (Joomla Extension - joomshaper.com - Unauthenticated Stored Cross-Site  ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-78085 (Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Ma ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-78084 (Joomla Extension - joomshaper.com - Missing Access Control in Gallery  ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-78083 (Joomla Extension - joomshaper.com - Missing CSRF Token Verification in ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-78082 (Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in P ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-75584 (ION-DTN before 4.2.1-a.1 contains a denial of service vulnerability th ...)
 	TODO: check
 CVE-2026-73699 (FileRun before 2026.3.0 contains a PHP object injection vulnerability  ...)
@@ -413,9 +413,9 @@ CVE-2026-68487 (Path traversal in Plesk's Backup Manager causes arbitrary file w
 CVE-2026-68006 (An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker to exec ...)
 	TODO: check
 CVE-2026-66674 (Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66632 (Unauthenticated Content Injection in Simple Cloudflare Turnstile <= 1. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65639 (OS command injection in the advanced-rule parser of ConfigServer Secur ...)
 	TODO: check
 CVE-2026-65638 (Improper escaping of a request URL in  ConfigServer Security & Firewal ...)
@@ -427,15 +427,15 @@ CVE-2026-64837 (ICEcoder through 8.1 passes an unescaped filesystem path into a
 CVE-2026-64836 (ICEcoder versions through 8.1 contain a path traversal vulnerability i ...)
 	TODO: check
 CVE-2026-5399 (The Redux Framework plugin for WordPress is vulnerable to Stored Cross ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-52098 (An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrar ...)
-	TODO: check
+	NOT-FOR-US: Flowise
 CVE-2026-52097 (An issue in AppFlowy 0.11.8 allows a remote attacker to execute arbitr ...)
 	TODO: check
 CVE-2026-4130 (There is a storage of sensitive information in cleartext vulnerability ...)
-	TODO: check
+	NOT-FOR-US: National Instruments
 CVE-2026-4129 (There is an improper access control vulnerability in NI SystemLink tha ...)
-	TODO: check
+	NOT-FOR-US: National Instruments
 CVE-2026-46387 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
 	TODO: check
 CVE-2026-45763 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
@@ -443,29 +443,29 @@ CVE-2026-45763 (Suricata is a network Intrusion Detection System, Intrusion Prev
 CVE-2026-45747 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
 	TODO: check
 CVE-2026-42808 (An issue was discovered in Bosch Sensortec COINES_SDK versions 2.0 thr ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2026-42807 (A heap-based buffer overflow vulnerability in the PC bridge protocol d ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2026-42806 (An out-of-bounds read vulnerability was discovered in the Bosch BME690 ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2026-42805 (A stack-based buffer overflow vulnerability exists in the Bosch Sensor ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2026-42804 (A stack-based buffer overflow vulnerability exists in the Bosch Sensor ...)
-	TODO: check
+	NOT-FOR-US: Bosch
 CVE-2026-38626 (Garlic-Hub v1.0.1 is vulnerable to SQL Injection in src/Modules/Items/ ...)
 	TODO: check
 CVE-2026-17038 (DrEryk Gabinet before 11.5.0uses hard-coded API credentials in its tic ...)
 	TODO: check
 CVE-2026-15889 (The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Stored C ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15461 (The Sierra Wireless HL78xx modem GNSS driver (drivers/modem/hl78xx/, l ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-15419 (In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a l ...)
-	TODO: check
+	NOT-FOR-US: Silicon Labs
 CVE-2026-15418 (In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a l ...)
-	TODO: check
+	NOT-FOR-US: Silicon Labs
 CVE-2026-15417 (In the silabser.sys Windows 8 driver for CP210x devices, a local unpri ...)
-	TODO: check
+	NOT-FOR-US: Silicon Labs
 CVE-2026-13745 (A vulnerability in the Gemini CLI and associated GitHub Action allowed ...)
 	TODO: check
 CVE-2026-12683 (Improper neutralization of input during web page generation ('cross-si ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a019af30c6c1363b2181c5f2ac5b1cfb8a3d9c4f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a019af30c6c1363b2181c5f2ac5b1cfb8a3d9c4f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260910/9f41bdd1/attachment.htm>


More information about the debian-security-tracker-commits mailing list