[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Sep 11 09:46:40 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
97d0f917 by Moritz Muehlenhoff at 2026-09-11T10:46:30+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -193,27 +193,27 @@ CVE-2026-73785 (A potential security vulnerability in HPE IceWall Federation Age
 CVE-2026-73784 (A potential security vulnerability in HPE IceWall products could be ex ...)
 	NOT-FOR-US: HPE
 CVE-2026-71647 (An issue in EGO-Planner-v2 All versions up to commit 5c99a95880401e259 ...)
-	TODO: check
+	NOT-FOR-US: EGO-Planner-v2
 CVE-2026-71645 (An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected  ...)
-	TODO: check
+	NOT-FOR-US: Robotics-STAR-Lab
 CVE-2026-71643 (An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99 ...)
-	TODO: check
+	NOT-FOR-US: EGO-Planner-v2
 CVE-2026-71642 (An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99 ...)
-	TODO: check
+	NOT-FOR-US: EGO-Planner-v2
 CVE-2026-71640 (An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99 ...)
-	TODO: check
+	NOT-FOR-US: EGO-Planner-v2
 CVE-2026-63427 (An authentication bypass vulnerability was discovered in Lenovo Softwa ...)
 	NOT-FOR-US: Lenovo
 CVE-2026-57844
 	REJECTED
 CVE-2026-54054 (Transmute is a free, open-source, self-hosted file conversion and comp ...)
-	TODO: check
+	NOT-FOR-US: Transmute
 CVE-2026-49836 (psd-tools is a Python package for working with Adobe Photoshop PSD fil ...)
 	TODO: check
 CVE-2026-3096 (The product's web portals allow external links to be opened in a new b ...)
 	NOT-FOR-US: WSO2
 CVE-2026-36392 (FairSketch Rise CRM Version 3.9.6 is vulnerable to Cross Site Scriptin ...)
-	TODO: check
+	NOT-FOR-US: FairSketch Rise CRM
 CVE-2026-2310 (IBM webMethods Integration Server 11.1 IBM webMethods Integration is v ...)
 	NOT-FOR-US: IBM
 CVE-2026-19991 (The UsersWP plugin for WordPress is vulnerable to Arbitrary File Delet ...)
@@ -586,7 +586,7 @@ CVE-2026-88025 (Improper neutralization of special elements in data query logic
 CVE-2026-88024 (Improper neutralization of special elements in data query logic in the ...)
 	NOT-FOR-US: MongoDB Rust Driver
 CVE-2026-88023 (Improper neutralization of special elements in data query logic in the ...)
-	NOT-FOR-US: MongoDB PHP Library
+	NOT-FOR-US: MongoDB PHP Library, different from src:php-mongodb
 CVE-2026-88022 (Improper neutralization of special elements in data query logic in the ...)
 	NOT-FOR-US: MongoDB integration for Laravel
 CVE-2026-88021 (Consul and Consul Enterprise are vulnerable to an authorization bypass ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/97d0f917642a5763209e831bfb66ccabf18b09a2

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/97d0f917642a5763209e831bfb66ccabf18b09a2
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260911/0ceb6104/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list