[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Sep 12 08:44:35 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
ee327232 by Salvatore Bonaccorso at 2026-09-12T09:44:13+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -10,41 +10,41 @@ CVE-2026-90460 (An issue was discovered in OpenStack Keystone before 29.0.3. Tok
NOTE: https://bugs.launchpad.net/keystone/+bug/2158931
NOTE: https://review.opendev.org/c/openstack/keystone/+/1002330
CVE-2026-90457 (The administrative password is hashed using a comparatively weak, fast ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-90456 (An example environment-configuration file for a bundled inventory-mana ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-90455 (A prior update that raised a bundled HTTP client library to a version ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-90454 (A deployment mode intended to expose only read access to a bundled pac ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-90453 (A file-upload handler redirects the authenticated client's browser to ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-90452 (Requests from the reverse proxy to the identity-provider service for t ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-90451 (An example environment-configuration file ships with a fixed, publicly ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-90450 (The application's role-authorization lookup defaults to granting acces ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-90449 (When a particular authentication mode is configured, the reverse proxy ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-90448 (A deployment mode intended to expose only read access to stored data p ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-90447 (A routing rule selects between two different authentication mechanisms ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-90446 (An application programming interface endpoint accepts a user-supplied ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-90445 (An interface that accepts file uploads from authenticated users extrac ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-90444 (A file-transfer interface that requires valid credentials accepts atta ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-90443 (A web interface reflects a portion of the request URL into a script co ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-89332 (Inclusion of functionality from an untrusted control sphere in the Kir ...)
NOT-FOR-US: Amazon
CVE-2026-89268 (QloApps through 1.7.0 renders back-office list filter POST parameters ...)
- TODO: check
+ NOT-FOR-US: QloApps
CVE-2026-89267 (starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the sea ...)
- TODO: check
+ NOT-FOR-US: Starlette-Admin
CVE-2026-89266 (stb_vorbis through 1.22 contains a heap buffer overflow in start_decod ...)
TODO: check
CVE-2026-87919 (The Product XML Feed Manager for WooCommerce WordPress plugin before ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ee327232f9bf07b47fdd53a376176a17a5a653bf
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ee327232f9bf07b47fdd53a376176a17a5a653bf
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260912/a22d7f11/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list