[Git][security-tracker-team/security-tracker][master] Add two apache-opennlp issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 12 10:14:07 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
541468be by Salvatore Bonaccorso at 2026-09-12T11:13:43+02:00
Add two apache-opennlp issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1935,7 +1935,8 @@ CVE-2026-85083 (The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for
 CVE-2026-84390 (A inclusion of sensitive information in source code vulnerability in F ...)
 	NOT-FOR-US: Fortinet
 CVE-2026-82617 (The two built-in name-finder patterns exposed by opennlp.tools.namefin ...)
-	TODO: check
+	- apache-opennlp <unfixed>
+	NOTE: https://lists.apache.org/thread/spzhcxxszqdpppg70m1zz2l3mv29mhl3
 CVE-2026-82583 (NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an au ...)
 	NOT-FOR-US: NextGen Connect (Mirth Connect)
 CVE-2026-82578 (When XML batch processing is turned on and the XPath option is selecte ...)
@@ -2016,7 +2017,8 @@ CVE-2026-68528 (Concrete CMS RSS Displayer block below version 9.5.3  rendered r
 CVE-2026-68497 (jackson-databind binds a JSON string to a javax.xml.datatype.Duration  ...)
 	TODO: check
 CVE-2026-67211 (OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP S ...)
-	TODO: check
+	- apache-opennlp <not-affected> (Vulnerable code not present)
+	NOTE: https://lists.apache.org/thread/gnobdsj640c60xl76q8g9o73c7jsybjm
 CVE-2026-62140 (Unauthenticated Insecure Direct Object References (IDOR) in Quiz And S ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62139 (Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Googl ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/541468be9ec7fe3721c80f9eacf41c34c9bd57cf

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/541468be9ec7fe3721c80f9eacf41c34c9bd57cf
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260912/56741227/attachment.htm>


More information about the debian-security-tracker-commits mailing list