[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Sep 16 14:11:20 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e145a7ef by Moritz Muehlenhoff at 2026-09-16T15:11:02+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -818,7 +818,7 @@ CVE-2026-54689 (mcp-searxng is a Model Context Protocol server that gives AI ass
 CVE-2026-54688 (mcp-searxng is a Model Context Protocol server that gives AI assistant ...)
 	NOT-FOR-US: mcp-searxng
 CVE-2026-54637 (Dragonfly is an open source P2P-based file distribution and image acce ...)
-	TODO: check
+	NOT-FOR-US: Dragonfly
 CVE-2026-54561 (MCP Memory Keeper is an MCP server for persistent context management i ...)
 	TODO: check
 CVE-2026-54549 (Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI ass ...)
@@ -880,21 +880,21 @@ CVE-2026-52819 (Kimai is an open-source time tracking application. Prior to 2.57
 CVE-2026-52724 (Kuma is a modern Envoy-based service mesh that can run on every cloud  ...)
 	NOT-FOR-US: Kimai
 CVE-2026-52484 (An issue in MitraStar GPT-2742GX4X5v6-SV GL_g2.5_100XNT0b23_3 allows a ...)
-	TODO: check
+	NOT-FOR-US: MitraStar
 CVE-2026-50166 (Kuma is a modern Envoy-based service mesh that can run on every cloud  ...)
-	TODO: check
+	NOT-FOR-US: Kuma
 CVE-2026-50024 (GitHacker is a tool that restores Git repositories from exposed .git d ...)
-	TODO: check
+	NOT-FOR-US: GitHacker
 CVE-2026-49446 (Cosmos provides users the ability self-host a home server by acting as ...)
-	TODO: check
+	NOT-FOR-US: Cosmos
 CVE-2026-49254 (Dragonfly is an open source P2P-based file distribution and image acce ...)
-	TODO: check
+	NOT-FOR-US: Dragonfly
 CVE-2026-48987 (pyLoad is a free and open-source download manager written in Python. P ...)
 	- pyload <itp> (bug #1001980)
 CVE-2026-48737 (pyLoad is a free and open-source download manager written in Python. P ...)
 	- pyload <itp> (bug #1001980)
 CVE-2026-48722 (Nextflow is a DSL for data-driven computational pipelines. From 25.09. ...)
-	TODO: check
+	NOT-FOR-US: Nextflow
 CVE-2026-48717 (Open Access Management (OpenAM) is an access management solution. Prio ...)
 	NOT-FOR-US: OpenAM
 CVE-2026-47780 (free5GC is an open-source implementation of the 5G core network. In 4. ...)
@@ -926,17 +926,17 @@ CVE-2026-45048 (Open Access Management (OpenAM) is an access management solution
 CVE-2026-44793 (Open Access Management (OpenAM) is an access management solution. Prio ...)
 	NOT-FOR-US: OpenAM
 CVE-2026-44778 (Inspektor Gadget is a set of tools and framework for data collection a ...)
-	TODO: check
+	NOT-FOR-US: Inspektor Gadget
 CVE-2026-44300 (OpenCost provides cost monitoring for Kubernetes workloads and cloud c ...)
-	TODO: check
+	NOT-FOR-US: OpenCost
 CVE-2026-44282 (Decidim is a participatory democracy framework. Prior to 0.32.0, a low ...)
-	TODO: check
+	NOT-FOR-US: Decidim
 CVE-2026-44203 (Open Access Management (OpenAM) is an access management solution. Prio ...)
 	NOT-FOR-US: OpenAM
 CVE-2026-44202 (Open Access Management (OpenAM) is an access management solution. Prio ...)
 	NOT-FOR-US: OpenAM
 CVE-2026-44163 (fluent-plugin-opentelemetry is a Fluentd input and output plugin for f ...)
-	TODO: check
+	NOT-FOR-US: fluent-plugin-opentelemetry
 CVE-2026-41573 (Open Access Management (OpenAM) is an access management solution. Prio ...)
 	NOT-FOR-US: OpenAM
 CVE-2026-40058 (CrowdStrike released a security update to address a vulnerability in t ...)
@@ -944,19 +944,19 @@ CVE-2026-40058 (CrowdStrike released a security update to address a vulnerabilit
 CVE-2026-39919 (Ghostscript before 10.08.0 contains a heap-based buffer overflow vulne ...)
 	TODO: check
 CVE-2026-39040 (BharatMLStack up to and including 1.3.0 is vulnerable to Cross Site Sc ...)
-	TODO: check
+	NOT-FOR-US: BharatMLStack
 CVE-2026-39039 (In BharatMLStack up to and including v1.3.0, Trufflebox UI stores the  ...)
-	TODO: check
+	NOT-FOR-US: BharatMLStack
 CVE-2026-39038 (BharatMLStack up to and including v1.3.0 is vulnerable to Cross Site S ...)
-	TODO: check
+	NOT-FOR-US: BharatMLStack
 CVE-2026-37152 (TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a ha ...)
 	NOT-FOR-US: TOTOLINK
 CVE-2026-25827 (An issue was discovered in Keyfactor SignServer before 7.6.0. A number ...)
-	TODO: check
+	NOT-FOR-US: Keyfactor SignServer
 CVE-2026-25826 (An issue was discovered in Keyfactor SignServer before 7.6.0. The attr ...)
-	TODO: check
+	NOT-FOR-US: Keyfactor SignServer
 CVE-2026-25825 (An issue was discovered in Keyfactor SignServer before 7.6.0. The outp ...)
-	TODO: check
+	NOT-FOR-US: Keyfactor SignServer
 CVE-2026-21588 (This High severity DoS (Denial of Service) vulnerability was introduce ...)
 	NOT-FOR-US: Atlassian
 CVE-2026-21587 (This High severity Improper Authorization vulnerability was introduced ...)
@@ -968,13 +968,13 @@ CVE-2026-1759 (Improper handling of insufficient permissions or privileges vulne
 CVE-2026-1758 (Session fixation vulnerability in Secomea GateManager (webserver modul ...)
 	TODO: check
 CVE-2026-19886 (OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code ...)
-	TODO: check
+	NOT-FOR-US: Origin Viewer
 CVE-2026-19885 (OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote C ...)
-	TODO: check
+	NOT-FOR-US: Origin Viewer
 CVE-2026-19781 (Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote ...)
-	TODO: check
+	NOT-FOR-US: Ashlar-Vellum Cobalt
 CVE-2026-19780 (Koha Eval Code Injection Remote Code Execution Vulnerability. This vul ...)
-	TODO: check
+	- koha <itp> (bug #702134)
 CVE-2026-19774 (BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerabi ...)
 	- bluez 5.87-1
 	NOTE: https://github.com/bluez/bluez/pull/2251
@@ -988,7 +988,7 @@ CVE-2026-19515 (The WSO2 Integrator MI VS Code extension fails to properly sanit
 CVE-2026-19504 (Fabric.js loadFromJSON Server-Side Request Forgery Vulnerability. This ...)
 	TODO: check
 CVE-2026-19407 (Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK  ...)
-	TODO: check
+	NOT-FOR-US: Google Cloud Gemini Enterprise Agent Platform SDK
 CVE-2026-18115 (Concrete CMS 9.2.0 to 9.5.2 did not enforce per-field edit_user_proper ...)
 	NOT-FOR-US: Concrete CMS
 CVE-2026-18113 (In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did not HTM ...)
@@ -998,9 +998,9 @@ CVE-2026-18111 (Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site
 CVE-2026-18110 (Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization ...)
 	NOT-FOR-US: Concrete CMS
 CVE-2026-16141 (OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic fl ...)
-	TODO: check
+	NOT-FOR-US: OpenBMC
 CVE-2026-16140 (OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a  ...)
-	TODO: check
+	NOT-FOR-US: OpenBMC
 CVE-2026-15609 (The Bridge - Creative Multipurpose WordPress Theme theme for WordPress ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-14805 (The Consulting theme for WordPress is vulnerable to Privilege Escalati ...)
@@ -1086,13 +1086,13 @@ CVE-2026-0170 (In Vp9DecodeFrameTag of vp9hwd_headers.cc, there is a possible ou
 CVE-2026-0159 (In Cellular Modem, there is a possible out-of-bounds write due to a mi ...)
 	NOT-FOR-US: Google devices
 CVE-2025-66974 (An issue in Prolink 13A Smart Plug Model Version: DS-3202M-UKv3 Wi-Fi  ...)
-	TODO: check
+	NOT-FOR-US: Prolink
 CVE-2025-5802 (The self-registration flow accepts user-supplied input for usernames w ...)
 	NOT-FOR-US: WSO2
 CVE-2025-13166 (The SMS OTP flow fails to adequately handle error messages, allowing a ...)
 	NOT-FOR-US: WSO2
 CVE-2024-58385 (Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: Yonyou
 CVE-2024-58384 (Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAs ...)
 	- python-tornado 6.4.1-1
 	NOTE: https://github.com/tornadoweb/tornado/security/advisories/GHSA-w235-7p84-xx57
@@ -1100,7 +1100,7 @@ CVE-2024-14029 (Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunke
 	- python-tornado 6.4.1-1
 	NOTE: https://github.com/tornadoweb/tornado/security/advisories/GHSA-753j-mpmx-qq6g
 CVE-2023-54398 (Yonyou U8 Cloud contains an unauthenticated Java deserialization vulne ...)
-	TODO: check
+	NOT-FOR-US: Yonyou
 CVE-2023-54397 (Tornado before 6.3.3 contains an HTTP request smuggling vulnerability  ...)
 	TODO: check
 CVE-2026-92079 (Mitigation bypass in the Widget: Win32 component. This vulnerability w ...)
@@ -1844,9 +1844,9 @@ CVE-2026-84489 (A buffer overflow was addressed with improved bounds checking. T
 CVE-2026-84487 (An integer overflow was addressed with improved input validation. This ...)
 	NOT-FOR-US: Apple
 CVE-2026-82519 (Really Simple Security plugin for WordPress before 9.8.2 contains a mi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-82028 (Magistrala before 1.0.0 contains a SQL injection vulnerability in the  ...)
-	TODO: check
+	NOT-FOR-US: Magistrala
 CVE-2026-81903 (Concrete CMS versions 9.0.0 to 9.5.2 stored the Page Container icon va ...)
 	NOT-FOR-US: Concrete CMS
 CVE-2026-81902 (Concrete CMS 9 through 9.5.2 did not validate a CSRF token in the orph ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e145a7effa6b6a9a79793859cf7c7bdb5ca82564

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e145a7effa6b6a9a79793859cf7c7bdb5ca82564
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260916/4ce3ac31/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list