[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Sep 14 21:06:13 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4c575af7 by Salvatore Bonaccorso at 2026-09-14T22:05:40+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -39,23 +39,23 @@ CVE-2026-90947 (A flaw was found in GIMP. When processing a specially crafted li
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2960
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/8a680c38fe84d529255e6b2916951ae7c480ed2c (master)
 CVE-2026-90946 (DeepWiki-Open through commit d92819a contains an arbitrary file read v ...)
-	TODO: check
+	NOT-FOR-US: DeepWiki-Open
 CVE-2026-90945 (Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT tok ...)
-	TODO: check
+	NOT-FOR-US: Crawlab
 CVE-2026-90944 (Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse en ...)
-	TODO: check
+	NOT-FOR-US: Krayin CRM
 CVE-2026-90943 (parallax filament-comments through 3.0.0 contains a stored cross-site  ...)
-	TODO: check
+	NOT-FOR-US: parallax filament-comments
 CVE-2026-90942 (Casdoor through 4.4.0 fails to properly mask the instance-wide built-i ...)
-	TODO: check
+	NOT-FOR-US: Casdoor
 CVE-2026-90941 (novel-plus through 5.3.3 contains an authorization bypass vulnerabilit ...)
-	TODO: check
+	NOT-FOR-US: novel-plus
 CVE-2026-90940 (novel-plus through 5.3.3 contains an insecure default cache-management ...)
-	TODO: check
+	NOT-FOR-US: novel-plus
 CVE-2026-90939 (novel-plus through 5.3.3 contains an information disclosure vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: novel-plus
 CVE-2026-90938 (LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 s ...)
-	TODO: check
+	NOT-FOR-US: LangBot
 CVE-2026-90937 (froxlor versions before 2.2.5 fail to validate newline characters in s ...)
 	TODO: check
 CVE-2026-90936 (Froxlor before 2.3.7 fails to properly scope sender alias lookups to t ...)
@@ -63,49 +63,49 @@ CVE-2026-90936 (Froxlor before 2.3.7 fails to properly scope sender alias lookup
 CVE-2026-90935 (Froxlor before 2.3.7 fails to validate the mysql_server parameter agai ...)
 	TODO: check
 CVE-2026-90934 (EspoCRM before 10.0.4 contains a field-level security bypass vulnerabi ...)
-	TODO: check
+	NOT-FOR-US: EspoCRM
 CVE-2026-90933 (laradashboard through 1.2.2 contains a missing authorization vulnerabi ...)
-	TODO: check
+	NOT-FOR-US: laradashboard
 CVE-2026-90932 (LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vu ...)
-	TODO: check
+	NOT-FOR-US: LaraDashboard
 CVE-2026-90931 (LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize SVG file c ...)
-	TODO: check
+	NOT-FOR-US: LaraDashboard
 CVE-2026-90930 (File Browser through 2.63.23 applies path rules to the requested lexic ...)
-	TODO: check
+	NOT-FOR-US: File Browser
 CVE-2026-90929 (File Browser versions >= 2.5.0 and <= 2.63.23 contain an incorrect aut ...)
-	TODO: check
+	NOT-FOR-US: File Browser
 CVE-2026-90928 (File Browser through 2.63.23 contains a memory exhaustion vulnerabilit ...)
-	TODO: check
+	NOT-FOR-US: File Browser
 CVE-2026-90927 (filebrowser through 2.63.23 fails to limit WebSocket message size in t ...)
-	TODO: check
+	NOT-FOR-US: File Browser
 CVE-2026-90919 (LightLLM through 1.2.0 contains a remote code execution vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: LightLLM
 CVE-2026-90898 (Bifrost registers MCP clients through its management API. A stdio clie ...)
-	TODO: check
+	NOT-FOR-US: Bifrost
 CVE-2026-90895 (Affected versions of MISP\u2019s interactive CLI shell implement acces ...)
 	TODO: check
 CVE-2026-90894 (Parallels Desktop runsprl_disp_serviceas root. Local clients reach it  ...)
-	TODO: check
+	NOT-FOR-US: Parallels Desktop
 CVE-2026-90893 (MISP contains a Cross-Site Request Forgery (CSRF) vulnerability in the ...)
 	TODO: check
 CVE-2026-90891 (ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. h ...)
-	TODO: check
+	NOT-FOR-US: ASRock Polychrome SYNC/RGB software
 CVE-2026-90890 (ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. h ...)
-	TODO: check
+	NOT-FOR-US: ASRock
 CVE-2026-90811 (A weakness has been identified in cosmicstack-labs mercury-agent up to ...)
-	TODO: check
+	NOT-FOR-US: cosmicstack-labs mercury-agent
 CVE-2026-90810 (A security flaw has been discovered in cosmicstack-labs mercury-agent  ...)
-	TODO: check
+	NOT-FOR-US: cosmicstack-labs mercury-agent
 CVE-2026-90809 (A vulnerability was identified in HKUDS nanobot up to 0.2.1. The affec ...)
-	TODO: check
+	NOT-FOR-US: HKUDS nanobot
 CVE-2026-90808 (A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted  ...)
-	TODO: check
+	NOT-FOR-US: HKUDS nanobot
 CVE-2026-90807 (A vulnerability was found in nanocoai NanoClaw up to 2.1.17. This issu ...)
-	TODO: check
+	NOT-FOR-US: nanocoai NanoClaw
 CVE-2026-90806 (A vulnerability has been found in DjangoCRM django-crm up to 1.2. This ...)
-	TODO: check
+	NOT-FOR-US: DjangoCRM django-crm
 CVE-2026-90805 (A flaw has been found in subhajitkhan online-clinic-management-system  ...)
-	TODO: check
+	NOT-FOR-US: subhajitkhan online-clinic-management-system
 CVE-2026-90804 (A vulnerability was detected in GNU Binutils 2.47. Affected by this is ...)
 	TODO: check
 CVE-2026-90803 (A security vulnerability has been detected in GNU Binutils 2.47. Affec ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4c575af7073934a18e9320433fedfb823b8a06b0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4c575af7073934a18e9320433fedfb823b8a06b0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260914/8dc6cf1c/attachment.htm>


More information about the debian-security-tracker-commits mailing list