[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 12 08:44:35 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ee327232 by Salvatore Bonaccorso at 2026-09-12T09:44:13+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -10,41 +10,41 @@ CVE-2026-90460 (An issue was discovered in OpenStack Keystone before 29.0.3. Tok
 	NOTE: https://bugs.launchpad.net/keystone/+bug/2158931
 	NOTE: https://review.opendev.org/c/openstack/keystone/+/1002330
 CVE-2026-90457 (The administrative password is hashed using a comparatively weak, fast ...)
-	TODO: check
+	NOT-FOR-US: CISA Malcolm
 CVE-2026-90456 (An example environment-configuration file for a bundled inventory-mana ...)
-	TODO: check
+	NOT-FOR-US: CISA Malcolm
 CVE-2026-90455 (A prior update that raised a bundled HTTP client library to a version  ...)
-	TODO: check
+	NOT-FOR-US: CISA Malcolm
 CVE-2026-90454 (A deployment mode intended to expose only read access to a bundled pac ...)
-	TODO: check
+	NOT-FOR-US: CISA Malcolm
 CVE-2026-90453 (A file-upload handler redirects the authenticated client's browser to  ...)
-	TODO: check
+	NOT-FOR-US: CISA Malcolm
 CVE-2026-90452 (Requests from the reverse proxy to the identity-provider service for t ...)
-	TODO: check
+	NOT-FOR-US: CISA Malcolm
 CVE-2026-90451 (An example environment-configuration file ships with a fixed, publicly ...)
-	TODO: check
+	NOT-FOR-US: CISA Malcolm
 CVE-2026-90450 (The application's role-authorization lookup defaults to granting acces ...)
-	TODO: check
+	NOT-FOR-US: CISA Malcolm
 CVE-2026-90449 (When a particular authentication mode is configured, the reverse proxy ...)
-	TODO: check
+	NOT-FOR-US: CISA Malcolm
 CVE-2026-90448 (A deployment mode intended to expose only read access to stored data p ...)
-	TODO: check
+	NOT-FOR-US: CISA Malcolm
 CVE-2026-90447 (A routing rule selects between two different authentication mechanisms ...)
-	TODO: check
+	NOT-FOR-US: CISA Malcolm
 CVE-2026-90446 (An application programming interface endpoint accepts a user-supplied  ...)
-	TODO: check
+	NOT-FOR-US: CISA Malcolm
 CVE-2026-90445 (An interface that accepts file uploads from authenticated users extrac ...)
-	TODO: check
+	NOT-FOR-US: CISA Malcolm
 CVE-2026-90444 (A file-transfer interface that requires valid credentials accepts atta ...)
-	TODO: check
+	NOT-FOR-US: CISA Malcolm
 CVE-2026-90443 (A web interface reflects a portion of the request URL into a script co ...)
-	TODO: check
+	NOT-FOR-US: CISA Malcolm
 CVE-2026-89332 (Inclusion of functionality from an untrusted control sphere in the Kir ...)
 	NOT-FOR-US: Amazon
 CVE-2026-89268 (QloApps through 1.7.0 renders back-office list filter POST parameters  ...)
-	TODO: check
+	NOT-FOR-US: QloApps
 CVE-2026-89267 (starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the sea ...)
-	TODO: check
+	NOT-FOR-US: Starlette-Admin
 CVE-2026-89266 (stb_vorbis through 1.22 contains a heap buffer overflow in start_decod ...)
 	TODO: check
 CVE-2026-87919 (The Product XML Feed Manager for WooCommerce  WordPress plugin before  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ee327232f9bf07b47fdd53a376176a17a5a653bf

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ee327232f9bf07b47fdd53a376176a17a5a653bf
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260912/a22d7f11/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list