[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Tue Sep 15 11:47:36 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
22693811 by Moritz Muehlenhoff at 2026-09-15T11:50:32+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -33,7 +33,7 @@ CVE-2026-91146 (Takahe through 0.11.0 fails to restrict URL schemes in link href
 CVE-2026-91145 (Activiti through 7.1.0.M6 fails to validate hash-brace deferred expres ...)
 	NOT-FOR-US: Activiti
 CVE-2026-91144 (ZFile through 5.0.5 fails to validate requested file paths against a s ...)
-	TODO: check
+	NOT-FOR-US: ZFile
 CVE-2026-91143 (goproxy through 15.3 fails to apply HTTP proxy basic authentication to ...)
 	TODO: check
 CVE-2026-91088 (A vulnerability has been found in GPAC up to f1219cde. This issue affe ...)
@@ -139,19 +139,19 @@ CVE-2026-90816 (A vulnerability was found in FFmpeg 8.0.x. This affects the func
 CVE-2026-90815 (A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3 ...)
 	TODO: check
 CVE-2026-90814 (A flaw has been found in cosmicstack-labs mercury-agent up to 1.1.13.  ...)
-	TODO: check
+	NOT-FOR-US: mercury-agent
 CVE-2026-90813 (A vulnerability was detected in cosmicstack-labs mercury-agent up to 1 ...)
-	TODO: check
+	NOT-FOR-US: mercury-agent
 CVE-2026-90812 (A security vulnerability has been detected in cosmicstack-labs mercury ...)
-	TODO: check
+	NOT-FOR-US: mercury-agent
 CVE-2026-90711 (proxy-addr is a Node.js module that determines a request's client addr ...)
 	TODO: check
 CVE-2026-89141 (The AI Engine \u2013 The Chatbot, AI Framework & MCP for WordPress plu ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-88262 (Insufficient session expiration vulnerability in bizwell xClick allows ...)
-	TODO: check
+	NOT-FOR-US: xClick
 CVE-2026-88261 (Improper input validation vulnerability in bizwell xClick allows Store ...)
-	TODO: check
+	NOT-FOR-US: xClick
 CVE-2026-86924 (A memory corruption issue was addressed with improved input validation ...)
 	NOT-FOR-US: Apple
 CVE-2026-86917 (A permissions issue was addressed with additional restrictions. This i ...)
@@ -1787,7 +1787,7 @@ CVE-2023-40772 (A directory Traversal vulnerability in DataEase before 1.18.10 a
 CVE-2023-37366 (An issue was discovered in Samsung Exynos Mobile Processor, Automotive ...)
 	NOT-FOR-US: Samsung
 CVE-2023-32803 (The ca-certificates package before ca-certificates-2021.2.50-72 for Am ...)
-	TODO: check
+	NOT-FOR-US: Amazon Linux
 CVE-2023-32778 (An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. An atta ...)
 	NOT-FOR-US: ILIAS
 CVE-2026-90783 (MKVToolNix through 101.0 contains a heap buffer overflow in the bundle ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/22693811312d61fc5ed099604e2626141b6129cb

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/22693811312d61fc5ed099604e2626141b6129cb
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260915/f67c24bd/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list