[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Sep 14 20:15:04 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
62db1477 by security tracker role at 2026-09-14T19:14:54+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -103,9 +103,9 @@ CVE-2026-90802 (A weakness has been identified in GNU Binutils 2.47. Affected is
 CVE-2026-90801 (A security flaw has been discovered in GNU Binutils 2.47. This impacts ...)
 	TODO: check
 CVE-2026-90796 (A vulnerability was identified in itsourcecode Leave Management System ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-90795 (A vulnerability was determined in itsourcecode Loan Management System  ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-90794 (A vulnerability was found in GPAC up to f1219cde. The affected element ...)
 	TODO: check
 CVE-2026-90793 (A vulnerability has been found in GPAC up to f1219cde. Impacted is the ...)
@@ -117,7 +117,7 @@ CVE-2026-90791 (A vulnerability was detected in GPAC up to f1219cde. This vulner
 CVE-2026-90790 (A security vulnerability has been detected in a2aproject a2a-python up ...)
 	TODO: check
 CVE-2026-90789 (A weakness has been identified in itsourcecode Leave Management System ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-90788 (A security flaw has been discovered in magicblack MacCMS10 2026.1000.4 ...)
 	TODO: check
 CVE-2026-90787 (A vulnerability was identified in Soarkey StudentManagement up to e08f ...)
@@ -147,35 +147,35 @@ CVE-2026-90708 (A weakness has been identified in Yot CMS up to 3.3.1. Affected
 CVE-2026-90707 (A security flaw has been discovered in Open5GS up to 2.7.x. Affected i ...)
 	TODO: check
 CVE-2026-90706 (A vulnerability was identified in D-Link DWR-M921 1.1.52. This impacts ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2026-90705 (A vulnerability was determined in D-Link DWR-M921 1.1.52. This affects ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2026-90704 (A vulnerability was found in D-Link DWR-M921 1.1.52. The impacted elem ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2026-90703 (A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2026-90702 (A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the funct ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2026-90701 (A vulnerability was detected in subhajitkhan online-clinic-management- ...)
 	TODO: check
 CVE-2026-90700 (A security vulnerability has been detected in itsourcecode Sales and I ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-90699 (A weakness has been identified in D-Link DWR-M920 1.1.7. This issue af ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2026-90698 (A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. ...)
 	TODO: check
 CVE-2026-90697 (A vulnerability was identified in SourceCodester Inventory Management  ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-90696 (A vulnerability was determined in SourceCodester Inventory Management  ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-90695 (A vulnerability was found in SourceCodester Inventory Management Syste ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-90694 (A vulnerability has been found in SourceCodester Inventory Management  ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-90693 (A flaw has been found in D-Link DIR-878 120B05. This impacts the funct ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2026-90692 (A vulnerability was detected in D-Link DIR-878 120B05. This affects th ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2026-90463 (A flaw was found in the sssd NSS responder. This input validation vuln ...)
 	TODO: check
 CVE-2026-8821 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7 ...)
@@ -187,35 +187,35 @@ CVE-2026-89180 (EFence developed by Thinking Software Technology has a SQL Injec
 CVE-2026-89023 (ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contain ...)
 	TODO: check
 CVE-2026-89021 (MikroTik RouterOS before 7.24.2 contains a path traversal vulnerabilit ...)
-	TODO: check
+	NOT-FOR-US: MikroTik
 CVE-2026-89020 (MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contai ...)
-	TODO: check
+	NOT-FOR-US: MikroTik
 CVE-2026-88932 (multer is a Node.js middleware for handling multipart/form-data upload ...)
 	TODO: check
 CVE-2026-88819 (In Siglet current and past versions the refresh token handler do not e ...)
 	TODO: check
 CVE-2026-87802 (Improper verification of cryptographic signature vulnerability in Apac ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-87785 (Authentication bypass by spoofing vulnerability in Apache Syncope.     ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-87779 (Insertion of sensitive information into log file vulnerability in Apac ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-87087
 	REJECTED
 CVE-2026-86836 (In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates wor ...)
 	TODO: check
 CVE-2026-86830 (Incorrect privilege assignment in Temporary Elevated Access Management ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-86460 (Cypher injection vulnerability in the Neo4j persistence layer when pro ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-86349 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7 ...)
 	TODO: check
 CVE-2026-86348 (Mattermost versions <=11.9 11.0.9 11.4.8 11.7.7 10.22.11.0 fail to rec ...)
 	TODO: check
 CVE-2026-85921 (Double free in Windows Secure Kernel Mode allows an authorized attacke ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-85892 (Concurrent execution using shared resource with improper synchronizati ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-84445 (gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and ...)
 	TODO: check
 CVE-2026-84179 (Description    getTopologyPageInfo merged the Nimbus daemon configurat ...)
@@ -239,29 +239,29 @@ CVE-2026-82433 (Description  `getNimbusConf` returned the complete daemon config
 CVE-2026-82432 (Description  Nimbus validated `topology.blobstore.map` against the cal ...)
 	TODO: check
 CVE-2026-82431 (Description  `SimpleACLAuthorizer` evaluated the user-level command se ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-82430 (Description  When launching a Docker or OCI worker, the setuid-root `w ...)
 	TODO: check
 CVE-2026-82429 (Description  The setuid-root `worker-launcher` binary adjusts ownershi ...)
 	TODO: check
 CVE-2026-82428 (Description  Dependency artifacts uploaded with `storm jar --artifacts ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-82427 (Description  A topology's `topology.blobstore.map` lets the submitter  ...)
 	TODO: check
 CVE-2026-82426 (Description  Nimbus accepted the `uploadedJarLocation` argument of `su ...)
 	TODO: check
 CVE-2026-82232 (Improper neutralization of special elements used in an SQL command ('S ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-82035 (PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path trave ...)
 	TODO: check
 CVE-2026-82019 (TripleLift's ad rendering script (video-bundle.js) contains a DOM-base ...)
 	TODO: check
 CVE-2026-81566 (Joomla Extension - joomshaper.com - Missing Access Control in Menu Ite ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-81565 (Joomla Extension - joomshaper.com - Missing Directory Confinement in M ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-81564 (Joomla Extension - joomshaper.com - Missing Directory Confinement in M ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-81301 (Ekia File Manager 1.2.7 exposes com.ekia.filecontrolmanager.OpenFilePr ...)
 	TODO: check
 CVE-2026-7848 (Alior Bank PrestaShop module "raty"for commercial partners is vulnerab ...)
@@ -269,31 +269,31 @@ CVE-2026-7848 (Alior Bank PrestaShop module "raty"for commercial partners is vul
 CVE-2026-7208 (Yealink SIP-T33G firmware versions 124.86.x.x prior to 124.87.0.0 cont ...)
 	TODO: check
 CVE-2026-79701 (Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in  ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-79700 (Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-78375 (Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injec ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-78336 (Insertion of sensitive information into sent data vulnerability in Apa ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-78330 (Incorrect privilege assignment vulnerability in Apache Syncope.  When  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-78318 (Improper neutralization of input during web page generation ('cross-si ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-78299 (In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive  ...)
 	TODO: check
 CVE-2026-77884 (Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP se ...)
 	TODO: check
 CVE-2026-77883 (Exposure of sensitive information through data queries vulnerability i ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-77181 (Incorrect Authorization vulnerability in Apache Syncope.    An adminis ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-77147 (Improper Control of Generation of Code ('Code Injection') vulnerabilit ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-77051 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-76461 (A vulnerability in the email parsing of Cisco AsyncOS Software for Cis ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76443 (As part of Cisco's ongoing commitment to proactive security and produc ...)
 	TODO: check
 CVE-2026-76442 (As part of Cisco's ongoing commitment to proactive security and produc ...)
@@ -303,27 +303,27 @@ CVE-2026-76441 (As part of Cisco's ongoing commitment to proactive security and
 CVE-2026-76440 (As part of Cisco's ongoing commitment to proactive security and produc ...)
 	TODO: check
 CVE-2026-75030 (Missing Authorization vulnerability in Apache Syncope.    An administr ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-75015 (Insufficiently Protected Credentials vulnerability in Apache Syncope.  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-73668 (Incorrect Authorization vulnerability in Apache Syncope.      An admin ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-73579 (Incorrect Authorization vulnerability in Apache Syncope.    Any search ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-73494 (blaze is a Scala library for building asynchronous pipelines, with a f ...)
 	TODO: check
 CVE-2026-73470 (Improper Privilege Management vulnerability in Apache Syncope.      De ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-73370 (Incorrect Authorization vulnerability in Apache Syncope.    Delegated  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-73236 (Incorrect Authorization vulnerability in Apache Syncope.    Delegated  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-73195 (Improper Encoding or Escaping of Output vulnerability in Apache Syncop ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-73191 (URL Redirection to Untrusted Site ('Open Redirect') vulnerability in A ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-73178 (Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-72524 (Incorrect Authorization vulnerability in Apache Doris allows an authen ...)
 	TODO: check
 CVE-2026-70658 (Pay is a payments engine for Ruby on Rails 6.0 and higher. Prior to 11 ...)
@@ -339,9 +339,9 @@ CVE-2026-5132 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <=
 CVE-2026-59960 (Argos JavaScript provides official Argos SDKs for JavaScript. Prior to ...)
 	TODO: check
 CVE-2026-59570 (On affected versions of Zscaler client connector, a pre-installed peer ...)
-	TODO: check
+	NOT-FOR-US: Zscaler
 CVE-2026-59569 (An improper input validation vulnerability in Zscaler Client Connector ...)
-	TODO: check
+	NOT-FOR-US: Zscaler
 CVE-2026-59178 (ESPHome Device Builder Dashboard is a dashboard for the ESPHome home m ...)
 	TODO: check
 CVE-2026-57583 (OpenZeppelin Contracts Wizard is a web application to interactively bu ...)
@@ -401,7 +401,7 @@ CVE-2026-55837 (dbt-mcp is a Model Context Protocol server for interacting with
 CVE-2026-55832 (Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX infer ...)
 	TODO: check
 CVE-2026-55795 (Craft Commerce is an ecommerce platform for Craft CMS. From 4.0.0 unti ...)
-	TODO: check
+	NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-55451 (gettext-converter provides gettext resource conversion utilities for J ...)
 	TODO: check
 CVE-2026-55416 (Pimcore is an Open Source Data & Experience Management Platform. Prior ...)
@@ -451,7 +451,7 @@ CVE-2026-54156 (node-opcua is an OPC UA implementation for TypeScript and Node.j
 CVE-2026-54155 (node-opcua is an OPC UA implementation for TypeScript and Node.js. Pri ...)
 	TODO: check
 CVE-2026-54150 (next-video is a library for adding video to Next.js applications. Prio ...)
-	TODO: check
+	NOT-FOR-US: Next.js
 CVE-2026-54087 (EasyAdmin is a fast and modern admin generator for Symfony application ...)
 	TODO: check
 CVE-2026-53752 (docx4j is an open source Java library for creating, editing, and savin ...)
@@ -471,7 +471,7 @@ CVE-2026-50270 (dd-trace-java is a Datadog APM client for Java. Prior to 1.62.0,
 CVE-2026-50157 (Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management ...)
 	TODO: check
 CVE-2026-4103 (Insufficient HTML sanitization in the Publisher Portal and Developer P ...)
-	TODO: check
+	NOT-FOR-US: WSO2
 CVE-2026-49400 (October System provides the system module for October Content Manageme ...)
 	TODO: check
 CVE-2026-49250 (Conform, a type-safe form validation library, allows the parsing of ne ...)
@@ -483,25 +483,25 @@ CVE-2026-46696 (October System provides the system module for October Content Ma
 CVE-2026-44162 (fluent-plugin-s3 is an Amazon S3 input and output plugin for Fluentd.  ...)
 	TODO: check
 CVE-2026-34151 (XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0 ...)
-	TODO: check
+	NOT-FOR-US: XWiki
 CVE-2026-25687 (A race condition in the ZPA tunnel handler of affected versions of Zsc ...)
-	TODO: check
+	NOT-FOR-US: Zscaler
 CVE-2026-21391 (An improper validation vulnerability exists within PingAM where a well ...)
-	TODO: check
+	NOT-FOR-US: Ping Identity Corporation
 CVE-2026-20773 (A role-based access control issue was identified in the administrative ...)
-	TODO: check
+	NOT-FOR-US: Ping Identity Corporation
 CVE-2026-20353 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-19543 (IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18515 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18151 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-15923 (The Zephyr SDIO subsystem function sdio_io_rw_extended_helper() in sub ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-15893 (net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c derives a  ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-15814 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7 ...)
 	TODO: check
 CVE-2026-15600 (Alior Bank PrestaShop module "raty" for commercial partners is vulnera ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/62db14776f15d035ae41a35205d8e0b74299984c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/62db14776f15d035ae41a35205d8e0b74299984c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260914/285082ac/attachment.htm>


More information about the debian-security-tracker-commits mailing list