[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Sep 14 21:27:35 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
2613fbaa by Salvatore Bonaccorso at 2026-09-14T22:27:03+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -135,35 +135,35 @@ CVE-2026-90792 (A flaw has been found in GPAC up to f1219cde. This issue affects
 CVE-2026-90791 (A vulnerability was detected in GPAC up to f1219cde. This vulnerabilit ...)
 	- gpac <removed>
 CVE-2026-90790 (A security vulnerability has been detected in a2aproject a2a-python up ...)
-	TODO: check
+	NOT-FOR-US: a2aproject a2a-python
 CVE-2026-90789 (A weakness has been identified in itsourcecode Leave Management System ...)
 	NOT-FOR-US: itsourcecode System
 CVE-2026-90788 (A security flaw has been discovered in magicblack MacCMS10 2026.1000.4 ...)
-	TODO: check
+	NOT-FOR-US: magicblack MacCMS10
 CVE-2026-90787 (A vulnerability was identified in Soarkey StudentManagement up to e08f ...)
-	TODO: check
+	NOT-FOR-US: Soarkey StudentManagement
 CVE-2026-90786 (A vulnerability was determined in Dvidelabs flatcc up to 0.6.3. This i ...)
-	TODO: check
+	NOT-FOR-US: Dvidelabs flatcc
 CVE-2026-90785 (A vulnerability was found in Dvidelabs flatcc up to 0.6.3. This affect ...)
-	TODO: check
+	NOT-FOR-US: Dvidelabs flatcc
 CVE-2026-90784 (A vulnerability has been found in Dvidelabs flatcc up to 0.6.3. The im ...)
-	TODO: check
+	NOT-FOR-US: Dvidelabs flatcc
 CVE-2026-90716 (A vulnerability was detected in marcobambini Gravity up to 0.9.7. This ...)
-	TODO: check
+	NOT-FOR-US: marcobambini Gravity
 CVE-2026-90715 (A security vulnerability has been detected in marcobambini Gravity up  ...)
-	TODO: check
+	NOT-FOR-US: marcobambini Gravity
 CVE-2026-90714 (A weakness has been identified in marcobambini Gravity up to 0.9.7. Th ...)
-	TODO: check
+	NOT-FOR-US: marcobambini Gravity
 CVE-2026-90713 (A security flaw has been discovered in vllm-project vLLM up to 0.29.0. ...)
 	TODO: check
 CVE-2026-90712 (A vulnerability was identified in Gitlawb openclaude up to 0.30.0. Imp ...)
-	TODO: check
+	NOT-FOR-US: Gitlawb openclaude
 CVE-2026-90710 (A vulnerability was determined in taisan tarzan-cms 1.0.0. This issue  ...)
-	TODO: check
+	NOT-FOR-US: taisan tarzan-cms
 CVE-2026-90709 (A security vulnerability has been detected in Yot CMS up to 3.3.1. Aff ...)
-	TODO: check
+	NOT-FOR-US: Yot CMS
 CVE-2026-90708 (A weakness has been identified in Yot CMS up to 3.3.1. Affected by thi ...)
-	TODO: check
+	NOT-FOR-US: Yot CMS
 CVE-2026-90707 (A security flaw has been discovered in Open5GS up to 2.7.x. Affected i ...)
 	TODO: check
 CVE-2026-90706 (A vulnerability was identified in D-Link DWR-M921 1.1.52. This impacts ...)
@@ -203,15 +203,15 @@ CVE-2026-8821 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <=
 CVE-2026-89321 (Publishing limits the compressed size of a VSIX (ovsx.publishing.max-c ...)
 	TODO: check
 CVE-2026-89180 (EFence developed by Thinking Software Technology has a SQL Injection v ...)
-	TODO: check
+	NOT-FOR-US: Thinking Software Technology
 CVE-2026-89023 (ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contain ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-89021 (MikroTik RouterOS before 7.24.2 contains a path traversal vulnerabilit ...)
 	NOT-FOR-US: MikroTik
 CVE-2026-89020 (MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contai ...)
 	NOT-FOR-US: MikroTik
 CVE-2026-88932 (multer is a Node.js middleware for handling multipart/form-data upload ...)
-	TODO: check
+	NOT-FOR-US: Node multer
 CVE-2026-88819 (In Siglet current and past versions the refresh token handler do not e ...)
 	TODO: check
 CVE-2026-87802 (Improper verification of cryptographic signature vulnerability in Apac ...)
@@ -275,7 +275,7 @@ CVE-2026-82232 (Improper neutralization of special elements used in an SQL comma
 CVE-2026-82035 (PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path trave ...)
 	TODO: check
 CVE-2026-82019 (TripleLift's ad rendering script (video-bundle.js) contains a DOM-base ...)
-	TODO: check
+	NOT-FOR-US: TripleLift
 CVE-2026-81566 (Joomla Extension - joomshaper.com - Missing Access Control in Menu Ite ...)
 	NOT-FOR-US: Joomla
 CVE-2026-81565 (Joomla Extension - joomshaper.com - Missing Directory Confinement in M ...)
@@ -283,11 +283,11 @@ CVE-2026-81565 (Joomla Extension - joomshaper.com - Missing Directory Confinemen
 CVE-2026-81564 (Joomla Extension - joomshaper.com - Missing Directory Confinement in M ...)
 	NOT-FOR-US: Joomla
 CVE-2026-81301 (Ekia File Manager 1.2.7 exposes com.ekia.filecontrolmanager.OpenFilePr ...)
-	TODO: check
+	NOT-FOR-US: Ekia File Manager
 CVE-2026-7848 (Alior Bank PrestaShop module "raty"for commercial partners is vulnerab ...)
-	TODO: check
+	NOT-FOR-US: PrestaShop module
 CVE-2026-7208 (Yealink SIP-T33G firmware versions 124.86.x.x prior to 124.87.0.0 cont ...)
-	TODO: check
+	NOT-FOR-US: Yealink SIP-T33G firmware
 CVE-2026-79701 (Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in  ...)
 	NOT-FOR-US: Joomla
 CVE-2026-79700 (Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2613fbaa8d5cb5a5c6c46075564b0adcd808c490

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2613fbaa8d5cb5a5c6c46075564b0adcd808c490
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260914/5e4d0b09/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list