[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Sep 16 08:18:32 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
fc136c70 by Moritz Muehlenhoff at 2026-09-16T09:18:23+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -398,7 +398,7 @@ CVE-2026-77179 (On macOS, the virtio-fs host server used by Docker Sandboxes imp
 CVE-2026-76159 (Incorrect Permission Assignment for Critical Resource in the  configur ...)
 	TODO: check
 CVE-2026-75092 (A privilege escalation flaw was found in the scan_mysql actor of leapp ...)
-	TODO: check
+	NOT-FOR-US: leapp-repository
 CVE-2026-73467 (On affected platforms running Arista EOS, under certain circumstances  ...)
 	NOT-FOR-US: Arista Networks
 CVE-2026-73466 (On affected platforms running Arista EOS, under certain circumstances  ...)
@@ -650,13 +650,13 @@ CVE-2026-55863 (motionEye (mEye) is an online interface for a piece of software
 CVE-2026-55828 (qbee transport is a remote access transport protocol implementation. P ...)
 	TODO: check
 CVE-2026-55776 (OpenBao is an open source identity-based secrets management system. Pr ...)
-	TODO: check
+	- openbao <itp> (bug #1069794)
 CVE-2026-55775 (OpenBao is an open source identity-based secrets management system. Pr ...)
-	TODO: check
+	- openbao <itp> (bug #1069794)
 CVE-2026-55774 (OpenBao is an open source identity-based secrets management system. Pr ...)
-	TODO: check
+	- openbao <itp> (bug #1069794)
 CVE-2026-55770 (OpenBao is an open source identity-based secrets management system. Pr ...)
-	TODO: check
+	- openbao <itp> (bug #1069794)
 CVE-2026-55701 (The OpenTelemetry Collector Contrib repository contains components for ...)
 	TODO: check
 CVE-2026-55692 (The EmbedVideo Extension is a MediaWiki extension which adds a parser  ...)
@@ -1756,9 +1756,9 @@ CVE-2026-81901 (In Concrete CMS 9.2.0 through 9.5.2, the REST API page update en
 CVE-2026-81900 (Concrete CMS before 9.5.3 applied only trim() to the YouTube block's s ...)
 	NOT-FOR-US: Concrete CMS
 CVE-2026-81320 (A flaw was found in hawtio-operator. When a custom Route TLS secret is ...)
-	TODO: check
+	NOT-FOR-US: hawtio-operator
 CVE-2026-81303 (A flaw was found in hawtio-operator. The operator holds routes/custom- ...)
-	TODO: check
+	NOT-FOR-US: hawtio-operator
 CVE-2026-7884 (IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12. ...)
 	NOT-FOR-US: IBM
 CVE-2026-78415 (IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote ...)
@@ -2621,7 +2621,7 @@ CVE-2026-55832 (Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX
 CVE-2026-55795 (Craft Commerce is an ecommerce platform for Craft CMS. From 4.0.0 unti ...)
 	NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-55451 (gettext-converter provides gettext resource conversion utilities for J ...)
-	TODO: check
+	NOT-FOR-US: Node gettext-converter
 CVE-2026-55416 (Pimcore is an Open Source Data & Experience Management Platform. Prior ...)
 	TODO: check
 CVE-2026-55253 (LangChain MongoDB provides integrations between MongoDB, Atlas, LangCh ...)
@@ -2677,7 +2677,7 @@ CVE-2026-53752 (docx4j is an open source Java library for creating, editing, and
 CVE-2026-53708 (ContextForge is an AI gateway, registry, and proxy that provides centr ...)
 	TODO: check
 CVE-2026-53659 (http4k is a functional toolkit for Kotlin HTTP applications. Prior to  ...)
-	TODO: check
+	NOT-FOR-US: http4k
 CVE-2026-53496 (ExifReader is a JavaScript Exif information parser. Prior to 4.40.1, E ...)
 	TODO: check
 CVE-2026-53495 (containerd is an open-source container runtime. Prior to 1.7.35, 2.0.1 ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fc136c70f6c2898723511d5a1f3f44ac6255acef

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fc136c70f6c2898723511d5a1f3f44ac6255acef
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260916/e373c94f/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list