[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Sep 15 06:23:35 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
7e867bc9 by Salvatore Bonaccorso at 2026-09-15T07:23:13+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -314,7 +314,7 @@ CVE-2026-78318 (Improper neutralization of input during web page generation ('cr
CVE-2026-78299 (In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive ...)
TODO: check
CVE-2026-77884 (Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP se ...)
- TODO: check
+ NOT-FOR-US: Gallery - Private Photo Vault
CVE-2026-77883 (Exposure of sensitive information through data queries vulnerability i ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-77181 (Incorrect Authorization vulnerability in Apache Syncope. An adminis ...)
@@ -342,7 +342,7 @@ CVE-2026-73668 (Incorrect Authorization vulnerability in Apache Syncope. An
CVE-2026-73579 (Incorrect Authorization vulnerability in Apache Syncope. Any search ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-73494 (blaze is a Scala library for building asynchronous pipelines, with a f ...)
- TODO: check
+ NOT-FOR-US: blaze
CVE-2026-73470 (Improper Privilege Management vulnerability in Apache Syncope. De ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-73370 (Incorrect Authorization vulnerability in Apache Syncope. Delegated ...)
@@ -358,37 +358,37 @@ CVE-2026-73178 (Exposure of Sensitive Information to an Unauthorized Actor vulne
CVE-2026-72524 (Incorrect Authorization vulnerability in Apache Doris allows an authen ...)
TODO: check
CVE-2026-70658 (Pay is a payments engine for Ruby on Rails 6.0 and higher. Prior to 11 ...)
- TODO: check
+ NOT-FOR-US: pay-rails
CVE-2026-68570 (Incorrect Authorization vulnerability in Apache Doris allows an authen ...)
TODO: check
CVE-2026-61701 (Laravel MagicLink creates links for authentication without a password ...)
- TODO: check
+ NOT-FOR-US: Laravel MagicLink
CVE-2026-61534 (Yayson is a library for serializing and reading JSON API data in JavaS ...)
- TODO: check
+ NOT-FOR-US: Yayson
CVE-2026-5132 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7 ...)
TODO: check
CVE-2026-59960 (Argos JavaScript provides official Argos SDKs for JavaScript. Prior to ...)
- TODO: check
+ NOT-FOR-US: Argos JavaScript
CVE-2026-59570 (On affected versions of Zscaler client connector, a pre-installed peer ...)
NOT-FOR-US: Zscaler
CVE-2026-59569 (An improper input validation vulnerability in Zscaler Client Connector ...)
NOT-FOR-US: Zscaler
CVE-2026-59178 (ESPHome Device Builder Dashboard is a dashboard for the ESPHome home m ...)
- TODO: check
+ NOT-FOR-US: ESPHome Device Builder Dashboard
CVE-2026-57583 (OpenZeppelin Contracts Wizard is a web application to interactively bu ...)
- TODO: check
+ NOT-FOR-US: OpenZeppelin Contracts Wizard
CVE-2026-57581 (DotVVM is an open source MVVM framework for web applications. Prior to ...)
- TODO: check
+ NOT-FOR-US: DotVVM
CVE-2026-57579 (Alchemy is an open source content management system engine written in ...)
- TODO: check
+ NOT-FOR-US: Alchemy CMS
CVE-2026-57578 (DotVVM is an open source MVVM framework for web applications. Prior to ...)
- TODO: check
+ NOT-FOR-US: DotVVM
CVE-2026-57577 (DotVVM is an open source MVVM framework for web applications. Prior to ...)
- TODO: check
+ NOT-FOR-US: DotVVM
CVE-2026-57570 (backpack/crud provides Create, Read, Update & Delete (CRUD) functions ...)
- TODO: check
+ NOT-FOR-US: backpack/crud
CVE-2026-57497 (webtransport-go is an implementation of the WebTransport protocol. Pri ...)
- TODO: check
+ NOT-FOR-US: webtransport-go
CVE-2026-57145 (PraisonAI is a multi-agent teams system. Prior to 4.6.62, src/praisona ...)
NOT-FOR-US: PraisonAI
CVE-2026-57132 (PraisonAI is a multi-agent teams system. Prior to 4.6.62, setting PRAI ...)
@@ -422,15 +422,15 @@ CVE-2026-57115 (PraisonAI is a multi-agent teams system. Prior to praisonaiagent
CVE-2026-56839 (PraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOO ...)
NOT-FOR-US: PraisonAI
CVE-2026-55866 (SpiceDB is an open source database system for creating and managing se ...)
- TODO: check
+ NOT-FOR-US: SpiceDB
CVE-2026-55847 (Allure 2 is the version 2.x branch of Allure Report, a multi-language ...)
- TODO: check
+ NOT-FOR-US: Allure
CVE-2026-55846 (Allure 2 is the version 2.x branch of Allure Report, a multi-language ...)
- TODO: check
+ NOT-FOR-US: Allure
CVE-2026-55837 (dbt-mcp is a Model Context Protocol server for interacting with dbt. P ...)
- TODO: check
+ NOT-FOR-US: dbt-mcp
CVE-2026-55832 (Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX infer ...)
- TODO: check
+ NOT-FOR-US: Tract
CVE-2026-55795 (Craft Commerce is an ecommerce platform for Craft CMS. From 4.0.0 unti ...)
NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-55451 (gettext-converter provides gettext resource conversion utilities for J ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7e867bc9940c5ec5b4fdff464ba02e4cadc7a968
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7e867bc9940c5ec5b4fdff464ba02e4cadc7a968
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260915/7b4bcc66/attachment.htm>
More information about the debian-security-tracker-commits
mailing list