[Git][security-tracker-team/security-tracker][master] Process some more NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Sep 11 21:53:49 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
bfadf764 by Salvatore Bonaccorso at 2026-09-11T22:53:36+02:00
Process some more NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,11 +1,11 @@
CVE-2026-9160 (Improper neutralization of special elements used in a template engine ...)
NOT-FOR-US: Arma Digital Media Inc. Website Template
CVE-2026-8304 (Missing Authorization vulnerability in TUBITAK BILGEM Software Technol ...)
- TODO: check
+ NOT-FOR-US: Pardus About
CVE-2026-8303 (Incorrect privilege assignment vulnerability in TUBITAK BILGEM Softwar ...)
- TODO: check
+ NOT-FOR-US: Pardus-software
CVE-2026-8301 (Improper neutralization of special elements used in an OS command ('OS ...)
- TODO: check
+ NOT-FOR-US: Pardus Boot Repair
CVE-2026-89329 (A flaw was found in `multipathd`. A local attacker with access to the ...)
- multipath-tools <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2470013
@@ -109,17 +109,17 @@ CVE-2026-89010 (WAVLINK WN535M1 and WN535M3 routers running firmware prior to M3
CVE-2026-89009 (WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V2 ...)
NOT-FOR-US: Wavlink
CVE-2026-87988 (An arbitrary file access vulnerability in Mistral Vibe allows an attac ...)
- TODO: check
+ NOT-FOR-US: Mistral Vibe
CVE-2026-87987 (An arbitrary code execution vulnerability in Mistral Vibe allows an at ...)
- TODO: check
+ NOT-FOR-US: Mistral Vibe
CVE-2026-87986 (An arbitrary code execution vulnerability in Mistral Vibe allows an at ...)
- TODO: check
+ NOT-FOR-US: Mistral Vibe
CVE-2026-87985 (An arbitrary code execution vulnerability in Mistral Vibe allows an at ...)
- TODO: check
+ NOT-FOR-US: Mistral Vibe
CVE-2026-87984 (An arbitrary file write vulnerability in Mistral Vibe, introduced in v ...)
- TODO: check
+ NOT-FOR-US: Mistral Vibe
CVE-2026-87983 (An arbitrary file read vulnerability in Mistral Vibe, introduced in ve ...)
- TODO: check
+ NOT-FOR-US: Mistral Vibe
CVE-2026-87910 (When tarfile extracts a link on a system that doesn't support links, i ...)
TODO: check
CVE-2026-87859 (morgan is an HTTP request logger middleware for Node.js. In versions b ...)
@@ -127,9 +127,9 @@ CVE-2026-87859 (morgan is an HTTP request logger middleware for Node.js. In vers
CVE-2026-87776 (compression is a Node.js and Express compression middleware. In versio ...)
TODO: check
CVE-2026-87727 (a-blog cms Ver. 3.2.33 and earlier contains a path traversal vulnerabi ...)
- TODO: check
+ NOT-FOR-US: a-blog cms
CVE-2026-87123 (hbs is an Express view engine wrapper for Handlebars. Version 4.3.0 ca ...)
- TODO: check
+ NOT-FOR-US: Node hbs
CVE-2026-87122
REJECTED
CVE-2026-87020 (An integer overflow in a specified pitch and buffer-size computation l ...)
@@ -139,19 +139,19 @@ CVE-2026-86813 (The MetForm WordPress plugin before 4.1.9 does not properly neut
CVE-2026-86809 (The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does n ...)
NOT-FOR-US: WordPress plugin
CVE-2026-86793 (SGLang allows unauthenticated pickle deserialization through /update_w ...)
- TODO: check
+ NOT-FOR-US: SGLang
CVE-2026-85979 (Affected versions of Puppet Enterprise contain a command injection vul ...)
TODO: check
CVE-2026-85116 (The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2 ...)
NOT-FOR-US: WordPress plugin
CVE-2026-85083 (The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootl ...)
- TODO: check
+ NOT-FOR-US: ANJIA AJL33PC0801 IP camera
CVE-2026-84390 (A inclusion of sensitive information in source code vulnerability in F ...)
NOT-FOR-US: Fortinet
CVE-2026-82617 (The two built-in name-finder patterns exposed by opennlp.tools.namefin ...)
TODO: check
CVE-2026-82583 (NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an au ...)
- TODO: check
+ NOT-FOR-US: NextGen Connect (Mirth Connect)
CVE-2026-82578 (When XML batch processing is turned on and the XPath option is selecte ...)
TODO: check
CVE-2026-82535 (Chamilo LMS before 1.11.42 and 3.0.0 contains a stored cross-site scri ...)
@@ -353,7 +353,7 @@ CVE-2026-89087 (The cstruct package before 6.3.0 for OCaml mishandles indexes.)
CVE-2026-89086 (In the jose package before 0.11.0 for OCaml, library calls to validate ...)
TODO: check
CVE-2026-89060 (A cross-namespace authorization flaw in multicluster-observability-add ...)
- TODO: check
+ NOT-FOR-US: multicluster-observability-addon
CVE-2026-89054 (A missing authorization vulnerability in OpenNMS Horizon allows config ...)
NOT-FOR-US: OpenNMS
CVE-2026-88260 (Authentication bypass using an alternate path or channel and Improper ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bfadf7644222dc333ad4b16c52ea6912c05bfd6c
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bfadf7644222dc333ad4b16c52ea6912c05bfd6c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260911/9041d0c2/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list