[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Sep 15 20:15:09 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0ebd46e2 by security tracker role at 2026-09-15T19:15:02+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -9,7 +9,7 @@ CVE-2026-92177 (pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remo
 CVE-2026-92176 (pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execu ...)
 	TODO: check
 CVE-2026-92082 (By default, Payara Server does not limit the number of failed login at ...)
-	TODO: check
+	NOT-FOR-US: Payara
 CVE-2026-92021 (Use-after-free in the JavaScript Engine: JIT component. This vulnerabi ...)
 	TODO: check
 CVE-2026-92014 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
@@ -127,25 +127,25 @@ CVE-2026-91941 (Crawl4AI before 0.9.3 contains an uncontrolled resource consumpt
 CVE-2026-91940 (crawl4ai before 0.9.3 contains an arbitrary file write vulnerability i ...)
 	TODO: check
 CVE-2026-91938 (Flowise versions before 3.1.4 contain a server-side request forgery vu ...)
-	TODO: check
+	NOT-FOR-US: Flowise
 CVE-2026-91937 (Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId pa ...)
-	TODO: check
+	NOT-FOR-US: Flowise
 CVE-2026-91936 (Flowise versions before 3.1.4 contain a script injection vulnerability ...)
-	TODO: check
+	NOT-FOR-US: Flowise
 CVE-2026-91935 (Flowise before 3.1.4 fails to validate baseURL parameters in chat-mode ...)
-	TODO: check
+	NOT-FOR-US: Flowise
 CVE-2026-91934 (Flowise versions before 3.1.4 fail to validate file paths in the SQL D ...)
-	TODO: check
+	NOT-FOR-US: Flowise
 CVE-2026-91933 (Flowise before 3.1.4 fails to enforce workspace-level authorization ch ...)
-	TODO: check
+	NOT-FOR-US: Flowise
 CVE-2026-91932 (Flowise before 3.1.4 contains a validation bypass vulnerability in MCP ...)
-	TODO: check
+	NOT-FOR-US: Flowise
 CVE-2026-91931 (Flowise before 3.1.4 contains a remote code execution vulnerability in ...)
-	TODO: check
+	NOT-FOR-US: Flowise
 CVE-2026-91930 (Flowise before 3.1.4 fails to scope enterprise organization and worksp ...)
-	TODO: check
+	NOT-FOR-US: Flowise
 CVE-2026-91929 (Flowise versions before 3.1.4 contain cross-tenant authorization gaps  ...)
-	TODO: check
+	NOT-FOR-US: Flowise
 CVE-2026-91926 (A flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM targ ...)
 	TODO: check
 CVE-2026-91925 (Polyaxon through 2.16.4 renders operation specification fields with an ...)
@@ -163,9 +163,9 @@ CVE-2026-91857 (Affected versions of MISP expose several state-changing controll
 CVE-2026-91855 (A security flaw has been discovered in Open5GS up to 2.7.7. Affected b ...)
 	TODO: check
 CVE-2026-91854 (A vulnerability was identified in code-projects Record Management Syst ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2026-91853 (A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B202112 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-91851 (Affected versions of MISP incorrectly filter dashboard templates that  ...)
 	TODO: check
 CVE-2026-91849 (A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affe ...)
@@ -177,9 +177,9 @@ CVE-2026-91846 (Affected versions of MISP allow a collection element to be creat
 CVE-2026-91842 (A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1 ...)
 	TODO: check
 CVE-2026-91836 (A flaw has been found in OpenClaw ClawScan up to 0.1.6. This affects a ...)
-	TODO: check
+	NOT-FOR-US: OpenClaw
 CVE-2026-91835 (A vulnerability was detected in OpenClaw ClawScan up to 0.1.6. The imp ...)
-	TODO: check
+	NOT-FOR-US: OpenClaw
 CVE-2026-91826 (Stack-based buffer overflow vulnerability in Samsung Opensource rLotti ...)
 	TODO: check
 CVE-2026-91825 (Affected versions of MISP fail to authorize a submitted sharing group  ...)
@@ -197,7 +197,7 @@ CVE-2026-91780 (A weakness has been identified in GNU Binutils 2.47. This impact
 CVE-2026-91779 (A security flaw has been discovered in GNU Binutils 2.47. This affects ...)
 	TODO: check
 CVE-2026-91778 (In affected versions of Octopus Server, users with certain scoped perm ...)
-	TODO: check
+	NOT-FOR-US: Octopus Deploy
 CVE-2026-91091 (A vulnerability was identified in GPAC up to f1219cde. The impacted el ...)
 	TODO: check
 CVE-2026-91090 (A vulnerability was determined in GPAC up to f1219cde. The affected el ...)
@@ -205,7 +205,7 @@ CVE-2026-91090 (A vulnerability was determined in GPAC up to f1219cde. The affec
 CVE-2026-91089 (A vulnerability was found in GPAC up to f1219cde. Impacted is the func ...)
 	TODO: check
 CVE-2026-90650 (The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stor ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-90439 (NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ ...)
 	TODO: check
 CVE-2026-89308 (An unauthenticated OS command injection vulnerability exists in thepin ...)
@@ -219,7 +219,7 @@ CVE-2026-89025 (Hirschmann HiOS Switch Platform devices contain a denial-of-serv
 CVE-2026-89022 (BookStack before 26.05.5 contains an authentication bypass vulnerabili ...)
 	TODO: check
 CVE-2026-88765 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-88621 (OneNav v1.2.4 contains an authenticated arbitrary file deletion vulner ...)
 	TODO: check
 CVE-2026-88620 (SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an improper  ...)
@@ -247,53 +247,53 @@ CVE-2026-86472 (fast-uri is a dependency-free RFC 3986 URI parser for Node.js, u
 CVE-2026-85234 (A flaw was found in tftp-hpa. When the `in.tftpd` remap engine process ...)
 	TODO: check
 CVE-2026-82837 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-82191 (Joomla Extension - j2commerce.com - Unescaped request data reflected i ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-82190 (Joomla Extension - j2commerce.com - Predictable/forgeable order access ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-82189 (Joomla Extension - j2commerce.com - Any order can be marked Failed by  ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-81924 (Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery  ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-81923 (In Concrete CMS before 9.5.3, the SEO Bulk Update Meta Tags editor did ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-81922 (Concrete CMS before 9.5.3 did not enforce a per-page authorization che ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-81921 (Concrete CMS 8.5.3 through 9.5.2 enabled the OAuth 2.0 refresh-token g ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-81920 (Concrete CMS below 9.5.3 was vulnerable to Cross-Site Request Forgery  ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-81919 (Concrete CMS below 9.5.3 did not validate an anti-CSRF token on the bl ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-81899 (Concrete CMS 9.0.0 to 9.5.2 stored group folder names without sanitiza ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-81898 (In Concrete CMS below version 9.5.3, the Address attribute's country-l ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-81897 (In Concrete CMS below CMS 9.5.3, the save_control action in the Expres ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-81896 (Concrete CMS before 9.5.3 does not apply HTML entity encoding to user- ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-81895 (In Concrete CMS before 9.5.3, the Document Library block stored the fi ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-81894 (Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-s ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-81568 (Joomla Extension - j2commerce.com - Arbitrary file read via `task=down ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-81567 (Joomla Extension - j2commerce.com - Unauthenticated blind SQL injectio ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-81240 (Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81239 (Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81238 (Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a  ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81237 (Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81236 (Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81235 (Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a  ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-80217 (Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, whic ...)
 	TODO: check
 CVE-2026-79705 (A flaw was found in the buildah/copier Go package. When used outside o ...)
@@ -301,7 +301,7 @@ CVE-2026-79705 (A flaw was found in the buildah/copier Go package. When used out
 CVE-2026-79699 (A flaw was found in the containers/storage library. A crafted tar arch ...)
 	TODO: check
 CVE-2026-79551 (Tenda Technology Co., Ltd NVR_4H CH3 v2.1 V27.5.58.6 was discovered to ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-79425 (An authenticated Server-Side Request Forgery (SSRF) in the /adminapi/f ...)
 	TODO: check
 CVE-2026-79411 (Incorrect privilege assignment in the admin user-management component  ...)
@@ -313,7 +313,7 @@ CVE-2026-79409 (An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obt
 CVE-2026-79303 (kaiten from 57.192.20 to before 57.214.26 is vulnerable to SQL Injecti ...)
 	TODO: check
 CVE-2026-78081 (Joomla Extension - j2commerce.com - Missing CSRF protection on cart, c ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-77972 (Time-of-check Time-of-use (TOCTOU) Race Condition in Slab safeurl allo ...)
 	TODO: check
 CVE-2026-77866 (Server-Side Request Forgery (SSRF) vulnerability in Slab safeurl allow ...)
@@ -327,13 +327,13 @@ CVE-2026-76159 (Incorrect Permission Assignment for Critical Resource in the  co
 CVE-2026-75092 (A privilege escalation flaw was found in the scan_mysql actor of leapp ...)
 	TODO: check
 CVE-2026-73467 (On affected platforms running Arista EOS, under certain circumstances  ...)
-	TODO: check
+	NOT-FOR-US: Arista Networks
 CVE-2026-73466 (On affected platforms running Arista EOS, under certain circumstances  ...)
-	TODO: check
+	NOT-FOR-US: Arista Networks
 CVE-2026-73465 (On affected platforms running Arista EOS, under certain circumstances  ...)
-	TODO: check
+	NOT-FOR-US: Arista Networks
 CVE-2026-73451 (On affected platforms running Arista EOS with dual switch cards and wi ...)
-	TODO: check
+	NOT-FOR-US: Arista Networks
 CVE-2026-69211 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
 	TODO: check
 CVE-2026-69209 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
@@ -343,17 +343,17 @@ CVE-2026-69208 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35
 CVE-2026-69204 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
 	TODO: check
 CVE-2026-68534 (Concrete CMS before 9.5.3 rendered Express entry labels as raw HTML wh ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-68533 (Concrete CMS below 9.5.3 conversation attachment uploaded endpoint imp ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-68532 (Concrete CMS 9.0.0 to dashboard group type controller did not validate ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-65831 (ArcadeDB is a Multi-Model DBMS. Prior to 26.7.1, a reader-role user ca ...)
 	TODO: check
 CVE-2026-63696 (Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-63695 (Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-63443 (Coder allows organizations to provision remote development environment ...)
 	TODO: check
 CVE-2026-62379 (Open Access Management (OpenAM) is an access management solution. Prio ...)
@@ -377,63 +377,63 @@ CVE-2026-59965 (Payload Plugins is a collection of plugins designed to enhance P
 CVE-2026-59341 (A security vulnerability exists in the Sealed Secrets controller's una ...)
 	TODO: check
 CVE-2026-59160 (Yeger is a monorepo for npm packages maintained under the yeger scope. ...)
-	TODO: check
+	NOT-FOR-US: Next.js
 CVE-2026-59157 (webhookd is a minimalist webhook server that triggers shell scripts an ...)
 	TODO: check
 CVE-2026-58773 (In link_load_gnss_image of link_device.c, there is a possible out-of-b ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-58767 (In multiple functions of arm-smmu-v3.c, there is a possible escalation ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-58766 (In multiple functions of arm-smmu-v3.c, there is a possible escalation ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-58765 (In GPU, there is a possible permission bypass due to a logic error in  ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-58755 (In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escal ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-58751 (In multiple functions of arm-smmu-v3.c, there is a possible use-after- ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-58747 (In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission by ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-58744 (In multiple locations, there is a possible escalation of privilege due ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-58739 (In platform_msg_handler_init of default_msg_handlers.c, there is a pos ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-58734 (In google_mba_recv_msg of google_mba_poll.c, there is a possible out-o ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-58731 (In multiple functions of physmem_extmem_linux.c, there is a possible o ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-58728 (In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-58726 (In FsmReleaseKey of fsm.c, there is a possible permission bypass due t ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-58724 (In multiple locations, there is a possible use-after-free due to a rac ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-58721 (In multiple locations, there is a possible information disclosure due  ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-58718 (In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escala ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-58716 (In multiple locations, there is a possible time-of-check to time-of-us ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-58710 (In DecodeFilmGrainParams of film_grain_dec.cc, there is a possible out ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-58704 (In Cellular Modem, there is a possible permission bypass due to a logi ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-58701 (In trusty_dputc of generic-arm64-smcall.c, there is a possible out-of- ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-58699 (In Vp9DecEndOfStream of vp9hwd_output.cc, there is a possible out-of-b ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-58698 (In ap_pmic_poll_msg_handler of ap_pmic_ipc.c, there is a possible perm ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-58695 (In gmc_phy_lp3_exit_restore_registers of phy_power.c, there is a possi ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-58691 (In FsmReleaseKey of fsm.c, there is a possible permission bypass due t ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-58683 (In IP Multimedia Subsystem, there is a possible out-of-bounds write du ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-58679 (In gf_ta_test_set_config of gf_ta_test.c, there is a possible heap buf ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-58678 (In Bootloader, there is a possible permission bypass due to a logic er ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-58502 (githubtoplanguages generates a user's top GitHub languages as an SVG.  ...)
 	TODO: check
 CVE-2026-58485 (mcp-searxng is a Model Context Protocol server that gives AI assistant ...)
@@ -453,111 +453,111 @@ CVE-2026-57442 (MCPVault is a lightweight Model Context Protocol server for safe
 CVE-2026-57441 (MCPVault is a lightweight Model Context Protocol server for safe acces ...)
 	TODO: check
 CVE-2026-57148 (PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_pla ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-57147 (PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_pla ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-57141 (PraisonAI is a multi-agent teams system. Prior to 1.7.2, the codeMode  ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-57140 (PraisonAI is a multi-agent teams system. From 1.6.0 until 1.7.2, Agent ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-57139 (PraisonAI is a multi-agent teams system. From 1.5.0 until 1.7.2, MCPSe ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-57138 (PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeM ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-57137 (PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, creat ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-57136 (PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, Comma ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-57135 (PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, Sandb ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-57134 (PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSe ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-57133 (PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, the s ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-57112 (PraisonAI is a multi-agent teams system. From praisonaiagents 0.6.0 un ...)
-	TODO: check
+	NOT-FOR-US: PraisonAI
 CVE-2026-57042 (In multiple functions of DreamPickerReceiver.kt, there is a possible p ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-57035 (In multiple locations, there is a possible out-of-bounds write due to  ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-57014 (In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there i ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-57012 (In the Setup Wizard, there is a possible remote package install due to ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-57008 (In Modem, there is a possible information disclosure due to improper i ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-57006 (In acfw_ffa.c, there is a possible secret read due to a logic error in ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56997 (In Av1DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of- ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56992 (In multiple files, there is a possible permission bypass due to a conf ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56989 (In multiple locations, there is a possible out-of-bounds write due to  ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56988 (In multiple functions of bluetooth_cco.cc, there is a possible use-aft ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56986 (In multiple files, there is a possible out-of-bounds read due to type  ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56985 (In multiple files, there is a possible way to obtain signatures due to ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56982 (In VPU, there is a possible permission bypass due to a missing permiss ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56979 (In multiple locations, there is a possible permission bypass due to a  ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56978 (In get_global_config_item_addr of gc.c, there is a possible out-of-bou ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56975 (In Cellular Modem, there is a possible denial of service due to improp ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56974 (In Start of AudioRtpPayloadEncoderNode.cpp, there is a possible out-of ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56973 (In multiple locations, there is a possible escalation of privilege due ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56972 (In multiple locations, there is a possible out-of-bounds write due to  ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56970 (In multiple locations, there is a possible permission bypass due to a  ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56967 (In Cellular Modem, there is a possible out-of-bounds write due to a he ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56964 (In multiple locations, there is a possible use-after-free due to a rac ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56960 (In multiple locations, there is a possible use-after-free due to a log ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56958 (In gf_algo_get_cached_dump_data of gf_algo.c, there is a possible out- ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56950 (In validate_ns_buf of mbu_class.rs, there is a possible information di ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56945 (In VPU, there is a possible out-of-bounds write due to a confused depu ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56942 (In ReadTileInfo of vp9hwd_headers.cc, there is a possible out-of-bound ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56941 (In multiple functions of fpc_tee_hal.c, there is a possible use-after- ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56932 (In Trusted Execution Environment, there is a possible memory corruptio ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56923 (In handle_unmap_req of tipc_virtio_dev.c, there is a possible memory c ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56922 (In CPM, there is a possible permission bypass due to a confused deputy ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56920 (In s_decode_vui_param of fw_hevc_dec_header.c, there is a possible out ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56915 (In bigo_worker_thread of bigo.c, there is a possible escalation of pri ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56914 (In multiple locations, there is a possible use-after-free due to impro ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56907 (In VPU, there is a possible shared memory overwrite due to improper in ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56892 (In ReadDataElement of common.c, there is a possible information disclo ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56889 (In multiple locations, there is a possible permission bypass due to an ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56888 (In multiple locations, there is a possible permission bypass due to si ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56882 (In Cellular Modem, there is a possible information disclosure due to a ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56881 (In enable_segment of remap.c, there is a possible permission bypass du ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56879 (In gmc_mb_msg_handler of gmc_mba.c, there is a possible memory corrupt ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-56831 (Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpa ...)
 	TODO: check
 CVE-2026-56830 (Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, an earli ...)
@@ -607,33 +607,33 @@ CVE-2026-55375 (canto-saas-api is a PHP library for interacting with the Canto S
 CVE-2026-55374 (canto-saas-api is a PHP library for interacting with the Canto SaaS AP ...)
 	TODO: check
 CVE-2026-55366 (In IP Multimedia Subsystem, there is a possible authentication bypass  ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-55365 (In multiple functions of remap.c, there is a possible out-of-bounds wr ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-55359 (In multiple locations, there is a possible permission bypass due to a  ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-55351 (In VPU, there is a possible out-of-bounds write due to an integer over ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-55343 (In decodeAmr of ImsMediaAudioPlayer.cpp, there is a possible out-of-bo ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-55332 (In multiple locations, there is a possible out-of-bounds write due to  ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-55331 (In IP Multimedia Subsystem, there is a possible out-of-bounds write du ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-55323 (In gf_base_update_finger_base of gf_base.c, there is a possible out-of ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-55318 (In multiple locations, there is a possible use-after-free due to a rac ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-55317 (In printf of printf.c, there is a possible out-of-bounds write due to  ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-55306 (In Cellular Modem, there is a possible denial of service due to improp ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-55304 (In addr_remap_address_map of remap.c, there is a possible escalation o ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-55302 (In multiple locations, there is a possible permission bypass due to a  ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-55301 (In Wave6VpuDecFlush of wave6.c, there is a possible out-of-bounds writ ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-55211 (Surfio is a library for reading and writing surface files. Prior to 0. ...)
 	TODO: check
 CVE-2026-55178 (GeoLens is a self-hosted geospatial data catalog with semantic search, ...)
@@ -673,7 +673,7 @@ CVE-2026-54076 (ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the fix for CVE
 CVE-2026-54050 (Sakai is a Collaboration and Learning Environment (CLE). From 23.0 unt ...)
 	TODO: check
 CVE-2026-53966 (XWiki Platform is a generic wiki platform. From 13.4-rc-1 until 16.10. ...)
-	TODO: check
+	NOT-FOR-US: XWiki
 CVE-2026-53957 (Contentful MCP Server is a Model Context Protocol server for the Conte ...)
 	TODO: check
 CVE-2026-53954 (Bugsink is a self-hosted error tracking tool. Prior to version 2.2.2,  ...)
@@ -729,7 +729,7 @@ CVE-2026-48722 (Nextflow is a DSL for data-driven computational pipelines. From
 CVE-2026-48717 (Open Access Management (OpenAM) is an access management solution. Prio ...)
 	TODO: check
 CVE-2026-47780 (free5GC is an open-source implementation of the 5G core network. In 4. ...)
-	TODO: check
+	NOT-FOR-US: Free5GC
 CVE-2026-47426 (Open Access Management (OpenAM) is an access management solution. Prio ...)
 	TODO: check
 CVE-2026-47424 (Open Access Management (OpenAM) is an access management solution. Prio ...)
@@ -771,7 +771,7 @@ CVE-2026-44163 (fluent-plugin-opentelemetry is a Fluentd input and output plugin
 CVE-2026-41573 (Open Access Management (OpenAM) is an access management solution. Prio ...)
 	TODO: check
 CVE-2026-40058 (CrowdStrike released a security update to address a vulnerability in t ...)
-	TODO: check
+	NOT-FOR-US: CrowdStrike
 CVE-2026-39919 (Ghostscript before 10.08.0 contains a heap-based buffer overflow vulne ...)
 	TODO: check
 CVE-2026-39040 (BharatMLStack up to and including 1.3.0 is vulnerable to Cross Site Sc ...)
@@ -781,7 +781,7 @@ CVE-2026-39039 (In BharatMLStack up to and including v1.3.0, Trufflebox UI store
 CVE-2026-39038 (BharatMLStack up to and including v1.3.0 is vulnerable to Cross Site S ...)
 	TODO: check
 CVE-2026-37152 (TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a ha ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-25827 (An issue was discovered in Keyfactor SignServer before 7.6.0. A number ...)
 	TODO: check
 CVE-2026-25826 (An issue was discovered in Keyfactor SignServer before 7.6.0. The attr ...)
@@ -789,11 +789,11 @@ CVE-2026-25826 (An issue was discovered in Keyfactor SignServer before 7.6.0. Th
 CVE-2026-25825 (An issue was discovered in Keyfactor SignServer before 7.6.0. The outp ...)
 	TODO: check
 CVE-2026-21588 (This High severity DoS (Denial of Service) vulnerability was introduce ...)
-	TODO: check
+	NOT-FOR-US: Atlassian
 CVE-2026-21587 (This High severity Improper Authorization vulnerability was introduced ...)
-	TODO: check
+	NOT-FOR-US: Atlassian
 CVE-2026-21586 (This High severity Improper Authorization vulnerability was introduced ...)
-	TODO: check
+	NOT-FOR-US: Atlassian
 CVE-2026-1759 (Improper handling of insufficient permissions or privileges vulnerabil ...)
 	TODO: check
 CVE-2026-1758 (Session fixation vulnerability in Secomea GateManager (webserver modul ...)
@@ -811,115 +811,115 @@ CVE-2026-19774 (BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vul
 CVE-2026-19773 (libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Rem ...)
 	TODO: check
 CVE-2026-19641 (On affected platforms running Arista EOS with password authentication  ...)
-	TODO: check
+	NOT-FOR-US: Arista Networks
 CVE-2026-19515 (The WSO2 Integrator MI VS Code extension fails to properly sanitize or ...)
-	TODO: check
+	NOT-FOR-US: WSO2
 CVE-2026-19504 (Fabric.js loadFromJSON Server-Side Request Forgery Vulnerability. This ...)
 	TODO: check
 CVE-2026-19407 (Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK  ...)
 	TODO: check
 CVE-2026-18115 (Concrete CMS 9.2.0 to 9.5.2 did not enforce per-field edit_user_proper ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-18113 (In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did not HTM ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-18111 (Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site script ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-18110 (Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-16141 (OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic fl ...)
 	TODO: check
 CVE-2026-16140 (OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a  ...)
 	TODO: check
 CVE-2026-15609 (The Bridge - Creative Multipurpose WordPress Theme theme for WordPress ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14805 (The Consulting theme for WordPress is vulnerable to Privilege Escalati ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13210 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-12910 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-12752 (IBM Business Automation Workflow containers and traditional is vulnera ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-12751 (IBM Cloud Pak for Business Automation is vulnerable to HTML injection. ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-12750 (IBM Cloud Pak for Business Automation is vulnerable to stored cross-si ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-12749 (IBM Cloud Pak for Business Automation is vulnerable to stored cross-si ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-12742 (IBM Business Automation Workflow containers and traditional could allo ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-12728 (IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3 ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-12667 (IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3 ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-12666 (IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3 ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-12358 (IBM Verify Identity Access could allow a remote attacker to cause a de ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-12355 (IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3 ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-12354 (IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3 ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-12351 (IBM MQ 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0 ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-12150 (IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3 ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-12101 (IBM Verify Identity Access could allow an administrator to execute add ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-11934 (IBM Verify Identity Access could allow an administrator to execute add ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-11929 (IBM Security Verify Identity Access Reverse Proxy in certain configura ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-11928 (IBM Verify Identity Access is vulnerable to a buffer overflow attack.)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-11927 (IBM Security Verify Identity Access reverse proxy may allow parameters ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-11926 (IBM Verify Identity Access could allow a remote attacker to cause a de ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-11921 (IBM Verify Identity Access containers may not apply management passwor ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-11918 (IBM ContextForge MCP Gateway <= v1.0.4 IBM mcp-context-forge could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-11864 (IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fi ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-11729 (IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3 ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-11728 (IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3 ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-0200 (In Cellular Modem, there is a possible out-of-bounds write due to a he ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0199 (In gf_ta_test_set_config of gf_ta_test.c, there is a possible out-of-b ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0197 (In VPU, there is a possible information dislclosure due to a logic err ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0194 (In multiple locations, there is a possible permission bypass due to an ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0192 (In Bootloader, there is a possible escalation of privilege due to a mi ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0189 (In ac_init_policy of init.c, there is a possible permission bypass due ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0187 (In gsa_sw_pk_hash_compare of image-auth-srv.c, there is a possible esc ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0186 (In ac_init_one_sswrp of init.c, there is a possible escalation of priv ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0183 (In CPM, there is a possible information disclosure due to a confused d ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0179 (In Bootloader, there is a possible permission bypass due to a missing  ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0177 (In do_sss_aes_gcm_256_op of crypto-aes.c, there is a possible out-of-b ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0171 (In multiple locations, there is a possible out-of-bounds write due to  ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0170 (In Vp9DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of- ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0159 (In Cellular Modem, there is a possible out-of-bounds write due to a mi ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2025-66974 (An issue in Prolink 13A Smart Plug Model Version: DS-3202M-UKv3 Wi-Fi  ...)
 	TODO: check
 CVE-2025-5802 (The self-registration flow accepts user-supplied input for usernames w ...)
-	TODO: check
+	NOT-FOR-US: WSO2
 CVE-2025-13166 (The SMS OTP flow fails to adequately handle error messages, allowing a ...)
-	TODO: check
+	NOT-FOR-US: WSO2
 CVE-2024-58385 (Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability  ...)
 	TODO: check
 CVE-2024-58384 (Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAs ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0ebd46e2436f152d9de1c50824484533499070f6

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0ebd46e2436f152d9de1c50824484533499070f6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260915/7e4dd33d/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list