[Git][security-tracker-team/security-tracker][master] Process some more NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 11 21:53:49 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
bfadf764 by Salvatore Bonaccorso at 2026-09-11T22:53:36+02:00
Process some more NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,11 +1,11 @@
 CVE-2026-9160 (Improper neutralization of special elements used in a template engine  ...)
 	NOT-FOR-US: Arma Digital Media Inc. Website Template
 CVE-2026-8304 (Missing Authorization vulnerability in TUBITAK BILGEM Software Technol ...)
-	TODO: check
+	NOT-FOR-US: Pardus About
 CVE-2026-8303 (Incorrect privilege assignment vulnerability in TUBITAK BILGEM Softwar ...)
-	TODO: check
+	NOT-FOR-US: Pardus-software
 CVE-2026-8301 (Improper neutralization of special elements used in an OS command ('OS ...)
-	TODO: check
+	NOT-FOR-US: Pardus Boot Repair
 CVE-2026-89329 (A flaw was found in `multipathd`. A local attacker with access to the  ...)
 	- multipath-tools <unfixed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2470013
@@ -109,17 +109,17 @@ CVE-2026-89010 (WAVLINK WN535M1 and WN535M3 routers running firmware prior to M3
 CVE-2026-89009 (WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V2 ...)
 	NOT-FOR-US: Wavlink
 CVE-2026-87988 (An arbitrary file access vulnerability in Mistral Vibe allows an attac ...)
-	TODO: check
+	NOT-FOR-US: Mistral Vibe
 CVE-2026-87987 (An arbitrary code execution vulnerability in Mistral Vibe allows an at ...)
-	TODO: check
+	NOT-FOR-US: Mistral Vibe
 CVE-2026-87986 (An arbitrary code execution vulnerability in Mistral Vibe allows an at ...)
-	TODO: check
+	NOT-FOR-US: Mistral Vibe
 CVE-2026-87985 (An arbitrary code execution vulnerability in Mistral Vibe allows an at ...)
-	TODO: check
+	NOT-FOR-US: Mistral Vibe
 CVE-2026-87984 (An arbitrary file write vulnerability in Mistral Vibe, introduced in v ...)
-	TODO: check
+	NOT-FOR-US: Mistral Vibe
 CVE-2026-87983 (An arbitrary file read vulnerability in Mistral Vibe, introduced in ve ...)
-	TODO: check
+	NOT-FOR-US: Mistral Vibe
 CVE-2026-87910 (When tarfile extracts a link on a system that doesn't support links, i ...)
 	TODO: check
 CVE-2026-87859 (morgan is an HTTP request logger middleware for Node.js. In versions b ...)
@@ -127,9 +127,9 @@ CVE-2026-87859 (morgan is an HTTP request logger middleware for Node.js. In vers
 CVE-2026-87776 (compression is a Node.js and Express compression middleware. In versio ...)
 	TODO: check
 CVE-2026-87727 (a-blog cms Ver. 3.2.33 and earlier contains a path traversal vulnerabi ...)
-	TODO: check
+	NOT-FOR-US: a-blog cms
 CVE-2026-87123 (hbs is an Express view engine wrapper for Handlebars. Version 4.3.0 ca ...)
-	TODO: check
+	NOT-FOR-US: Node hbs
 CVE-2026-87122
 	REJECTED
 CVE-2026-87020 (An integer overflow in a specified pitch and buffer-size computation l ...)
@@ -139,19 +139,19 @@ CVE-2026-86813 (The MetForm WordPress plugin before 4.1.9 does not properly neut
 CVE-2026-86809 (The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does n ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-86793 (SGLang allows unauthenticated pickle deserialization through /update_w ...)
-	TODO: check
+	NOT-FOR-US: SGLang
 CVE-2026-85979 (Affected versions of Puppet Enterprise contain a command injection vul ...)
 	TODO: check
 CVE-2026-85116 (The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2 ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-85083 (The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootl ...)
-	TODO: check
+	NOT-FOR-US: ANJIA AJL33PC0801 IP camera
 CVE-2026-84390 (A inclusion of sensitive information in source code vulnerability in F ...)
 	NOT-FOR-US: Fortinet
 CVE-2026-82617 (The two built-in name-finder patterns exposed by opennlp.tools.namefin ...)
 	TODO: check
 CVE-2026-82583 (NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an au ...)
-	TODO: check
+	NOT-FOR-US: NextGen Connect (Mirth Connect)
 CVE-2026-82578 (When XML batch processing is turned on and the XPath option is selecte ...)
 	TODO: check
 CVE-2026-82535 (Chamilo LMS before 1.11.42 and 3.0.0 contains a stored cross-site scri ...)
@@ -353,7 +353,7 @@ CVE-2026-89087 (The cstruct package before 6.3.0 for OCaml mishandles indexes.)
 CVE-2026-89086 (In the jose package before 0.11.0 for OCaml, library calls to validate ...)
 	TODO: check
 CVE-2026-89060 (A cross-namespace authorization flaw in multicluster-observability-add ...)
-	TODO: check
+	NOT-FOR-US: multicluster-observability-addon
 CVE-2026-89054 (A missing authorization vulnerability in OpenNMS Horizon allows config ...)
 	NOT-FOR-US: OpenNMS
 CVE-2026-88260 (Authentication bypass using an alternate path or channel and Improper  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bfadf7644222dc333ad4b16c52ea6912c05bfd6c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bfadf7644222dc333ad4b16c52ea6912c05bfd6c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260911/9041d0c2/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list