[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Sep 10 22:00:18 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
c9ce9e56 by Moritz Muehlenhoff at 2026-09-10T23:00:08+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -248,11 +248,11 @@ CVE-2026-88028 (Improper neutralization of special elements in data query logic
CVE-2026-88027 (Improper neutralization of special elements in data query logic in the ...)
TODO: check
CVE-2026-88026 (Improper neutralization of regular-expression metacharacters in the LI ...)
- TODO: check
+ NOT-FOR-US: MongoDB C# Driver
CVE-2026-88025 (Improper neutralization of special elements in data query logic in the ...)
- TODO: check
+ NOT-FOR-US: MongoDB C# Driver
CVE-2026-88024 (Improper neutralization of special elements in data query logic in the ...)
- TODO: check
+ NOT-FOR-US: MongoDB Rust Driver
CVE-2026-88023 (Improper neutralization of special elements in data query logic in the ...)
TODO: check
CVE-2026-88022 (Improper neutralization of special elements in data query logic in the ...)
@@ -603,7 +603,7 @@ CVE-2026-77770 (The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2F
CVE-2026-76562 (The Sidebar Manager Light plugin for WordPress is vulnerable to Stored ...)
NOT-FOR-US: WordPress plugin
CVE-2026-75880 (An authenticated client could attach a consumer with a selector contai ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-75308 (yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS). The file ...)
NOT-FOR-US: yshopmall
CVE-2026-75307 (zhitan-ems 1.0.0 is vulnerable to Cross Site Scripting (XSS) via SVG f ...)
@@ -641,7 +641,7 @@ CVE-2026-71613 (Buffer Overflow vulnerability in GPAC c2dee3aff638cd96f9617ac5b1
CVE-2026-71612 (Buffer Overflow vulnerability in GPAC c2dee3aff638cd96f9617ac5b17dc286 ...)
- gpac <removed>
CVE-2026-67593 (A remote attacker can craft an Openwire RemoveSubscriptionInfo command ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-61915 (An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH ...)
- cyrus-imapd <unfixed>
NOTE: https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.4.html
@@ -663,9 +663,9 @@ CVE-2026-61908 (An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP emai
NOTE: https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.4.html
NOTE: https://www.cyrusimap.org/3.12/imap/download/release-notes/3.10/x/3.10.4.html
CVE-2026-57967 (An unauthenticated remote attacker can craft a CORE protocol SESSION_R ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-57822 (When the broker is processing message-based management requests, sent ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-53956 (Rattler is a library that provides common functionality used within th ...)
NOT-FOR-US: Rattler
CVE-2026-50165 (alf.io is an open source ticket reservation system for conferences, tr ...)
@@ -673,11 +673,11 @@ CVE-2026-50165 (alf.io is an open source ticket reservation system for conferenc
CVE-2026-4657 (The Easy Google Fonts plugin for WordPress is vulnerable to Stored Cro ...)
NOT-FOR-US: WordPress plugin
CVE-2026-49364 (An unauthenticated network-adjacent attacker can leverage discovery to ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-49363 (An unauthenticated remote attacker connecting with the CORE protocol c ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-49362 (An unauthenticated remote attacker can create arbitrary durable queues ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-38998 (A use-after-free in the SocketDescriptor::tcpReadHandler1 function (li ...)
TODO: check
CVE-2026-36433 (An issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities ...)
@@ -1096,7 +1096,7 @@ CVE-2026-77120 (CWE-78: Improper Neutralization of Special Elements used in an O
CVE-2026-75927 (The PublishPress Capabilities \u2013 User Role Editor, Access Permissi ...)
NOT-FOR-US: WordPress plugin
CVE-2026-74761 (Improper input validation in TopicRegion in Apache ActiveMQ, Apache Ac ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-73334 (Potential problem for users of theorg.apache.parquet.crypto.keytools p ...)
TODO: check
CVE-2026-73324 (VLC media player copies an RTSP response line into a fixed buffer with ...)
@@ -1172,7 +1172,7 @@ CVE-2026-19778 (The WPMR Google Feed Manager for WooCommerce \u2013 Sell on Goog
CVE-2026-19733 (Server-Side request forgery (SSRF) vulnerability in Yordam Informatics ...)
NOT-FOR-US: Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program
CVE-2026-19729 (A flaw was found in the key provider component of the keycloak-service ...)
- TODO: check
+ NOT-FOR-US: Red Hat build of Keycloak
CVE-2026-19233 (CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that ...)
NOT-FOR-US: Schneider Electric
CVE-2026-18147 (A flaw was found in FreeIPA. An unauthenticated remote attacker could ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c9ce9e562bc88a3b4abf8358bb28b423f98c9e72
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c9ce9e562bc88a3b4abf8358bb28b423f98c9e72
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260910/2155b50b/attachment.htm>
More information about the debian-security-tracker-commits
mailing list