[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Sep 16 14:26:33 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
32b157bd by Moritz Muehlenhoff at 2026-09-16T15:23:36+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -806,11 +806,11 @@ CVE-2026-55301 (In Wave6VpuDecFlush of wave6.c, there is a possible out-of-bound
 CVE-2026-55211 (Surfio is a library for reading and writing surface files. Prior to 0. ...)
 	TODO: check
 CVE-2026-55178 (GeoLens is a self-hosted geospatial data catalog with semantic search, ...)
-	TODO: check
+	NOT-FOR-US: GeoLens
 CVE-2026-55158 (Conflibot warns in advance when merging a pull request will cause conf ...)
-	TODO: check
+	NOT-FOR-US: Conflibot
 CVE-2026-55149 (Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using th ...)
-	TODO: check
+	NOT-FOR-US: Vouch Proxy
 CVE-2026-54724 (Kiwi TCMS is an open source test management system. Prior to 16.1, the ...)
 	NOT-FOR-US: Kiwi TCMS
 CVE-2026-54689 (mcp-searxng is a Model Context Protocol server that gives AI assistant ...)
@@ -820,17 +820,17 @@ CVE-2026-54688 (mcp-searxng is a Model Context Protocol server that gives AI ass
 CVE-2026-54637 (Dragonfly is an open source P2P-based file distribution and image acce ...)
 	NOT-FOR-US: Dragonfly
 CVE-2026-54561 (MCP Memory Keeper is an MCP server for persistent context management i ...)
-	TODO: check
+	NOT-FOR-US: MCP Memory Keeper
 CVE-2026-54549 (Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI ass ...)
-	TODO: check
+	NOT-FOR-US: Meta Ads MCP
 CVE-2026-54547 (Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI ass ...)
-	TODO: check
+	NOT-FOR-US: Meta Ads MCP
 CVE-2026-54450 (ToolHive is a utility designed to simplify the deployment and manageme ...)
-	TODO: check
+	NOT-FOR-US: ToolHive
 CVE-2026-54254 (Cyberdrop-DL is a bulk asynchronous downloader for multiple file hosts ...)
-	TODO: check
+	NOT-FOR-US: Cyberdrop-DL
 CVE-2026-54251 (netty-incubator-codec-ohttp implements Oblivious HTTP (OHTTP) gateway  ...)
-	TODO: check
+	NOT-FOR-US: netty-incubator-codec-ohttp
 CVE-2026-54168 (Pipelines-as-Code is a CI/CD system that lets users define Tekton pipe ...)
 	NOT-FOR-US: Pipelines-as-Code
 CVE-2026-54167 (Pipelines-as-Code is a CI/CD system that lets users define Tekton pipe ...)
@@ -840,23 +840,23 @@ CVE-2026-54077 (ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATA
 CVE-2026-54076 (ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the fix for CVE-2026- ...)
 	NOT-FOR-US: ArcadeDB
 CVE-2026-54050 (Sakai is a Collaboration and Learning Environment (CLE). From 23.0 unt ...)
-	TODO: check
+	NOT-FOR-US: Sakai
 CVE-2026-53966 (XWiki Platform is a generic wiki platform. From 13.4-rc-1 until 16.10. ...)
 	NOT-FOR-US: XWiki
 CVE-2026-53957 (Contentful MCP Server is a Model Context Protocol server for the Conte ...)
-	TODO: check
+	NOT-FOR-US: Contentful MCP Server
 CVE-2026-53954 (Bugsink is a self-hosted error tracking tool. Prior to version 2.2.2,  ...)
-	TODO: check
+	NOT-FOR-US: Bugsink
 CVE-2026-53941 (Inspektor Gadget is a set of tools and framework for data collection a ...)
-	TODO: check
+	NOT-FOR-US: Inspektor Gadget
 CVE-2026-53710 (MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A,  ...)
-	TODO: check
+	NOT-FOR-US: MCP Context Forge
 CVE-2026-53660 (Open Access Management (OpenAM) is an access management solution. Prio ...)
-	TODO: check
+	NOT-FOR-US: OpenAM
 CVE-2026-53658 (Fabric CA is a Certificate Authority for Hyperledger Fabric. Prior to  ...)
-	TODO: check
+	NOT-FOR-US: Fabric CA
 CVE-2026-53459 (Bambuddy is a self-hosted print archive and management system for Bamb ...)
-	TODO: check
+	NOT-FOR-US: Bambuddy
 CVE-2026-52828 (Kimai is an open-source time tracking application. Prior to 2.58.0, Ex ...)
 	NOT-FOR-US: Kimai
 CVE-2026-52827 (Kimai is an open-source time tracking application. Prior to 2.59.0, th ...)
@@ -1866,7 +1866,7 @@ CVE-2026-78415 (IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a
 CVE-2026-77191 (An authenticated supplicant on an adjacent network may bypass intended ...)
 	NOT-FOR-US: Arista Networks
 CVE-2026-76081 (ZITADEL is an open source identity management platform. Prior to versi ...)
-	TODO: check
+	NOT-FOR-US: ZITADEL
 CVE-2026-75983 (The Eventin \u2013 Event Calendar, Tickets, Registration, Booking & Wo ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-75945 (A race condition may cause a supplicant to remain in an authorized sta ...)
@@ -1878,15 +1878,15 @@ CVE-2026-75943 (A brief (milliseconds to seconds) traffic leak may occur when an
 CVE-2026-75792 (IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote ...)
 	NOT-FOR-US: IBM
 CVE-2026-73497 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
-	TODO: check
+	NOT-FOR-US: MCP Atlassian
 CVE-2026-73496 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
-	TODO: check
+	NOT-FOR-US: MCP Atlassian
 CVE-2026-73449 (On affected platforms running Arista EOS with both 802.1X port authent ...)
 	NOT-FOR-US: Arista Networks
 CVE-2026-68489 (Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Nod ...)
-	TODO: check
+	NOT-FOR-US: Plesk extension
 CVE-2026-67399 (Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0. ...)
-	TODO: check
+	NOT-FOR-US: WHMCS
 CVE-2026-65838 (Skipper is an HTTP router and reverse proxy for service composition. P ...)
 	TODO: check
 CVE-2026-65415 (A race condition was addressed with additional validation. This issue  ...)
@@ -2030,19 +2030,19 @@ CVE-2026-54247 (Skipper is an HTTP router and reverse proxy for service composit
 CVE-2026-54246 (Skipper is an HTTP router and reverse proxy for service composition. P ...)
 	TODO: check
 CVE-2026-53719 (Envoy Gateway is an open source project for managing Envoy Proxy as a  ...)
-	TODO: check
+	- envoyproxy <itp> (bug #987544)
 CVE-2026-53718 (Envoy Gateway is an open source project for managing Envoy Proxy as a  ...)
-	TODO: check
+	- envoyproxy <itp> (bug #987544)
 CVE-2026-53717 (Envoy Gateway is an open source project for managing Envoy Proxy as a  ...)
-	TODO: check
+	- envoyproxy <itp> (bug #987544)
 CVE-2026-53716 (Envoy Gateway is an open source project for managing Envoy Proxy as a  ...)
-	TODO: check
+	- envoyproxy <itp> (bug #987544)
 CVE-2026-53715 (Envoy Gateway is an open source project for managing Envoy Proxy as a  ...)
-	TODO: check
+	- envoyproxy <itp> (bug #987544)
 CVE-2026-53714 (Envoy Gateway is an open source project for managing Envoy Proxy as a  ...)
-	TODO: check
+	- envoyproxy <itp> (bug #987544)
 CVE-2026-53713 (Envoy Gateway is an open source project for managing Envoy Proxy as a  ...)
-	TODO: check
+	- envoyproxy <itp> (bug #987544)
 CVE-2026-50006 (Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5 ...)
 	TODO: check
 CVE-2026-47253 (Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5 ...)
@@ -2756,19 +2756,19 @@ CVE-2026-54529 (SQLAdmin is a flexible Admin interface for SQLAlchemy models. Pr
 CVE-2026-54452 (safeurl is a server-side request forgery protection library. Prior to  ...)
 	TODO: check
 CVE-2026-54182 (backpack/crud provides Create, Read, Update & Delete (CRUD) functions  ...)
-	TODO: check
+	NOT-FOR-US: backpack/crud
 CVE-2026-54181 (backpack/crud provides Create, Read, Update & Delete (CRUD) functions  ...)
-	TODO: check
+	NOT-FOR-US: backpack/crud
 CVE-2026-54180 (backpack/crud provides Create, Read, Update & Delete (CRUD) functions  ...)
-	TODO: check
+	NOT-FOR-US: backpack/crud
 CVE-2026-54178 (backpack/crud provides Create, Read, Update & Delete (CRUD) functions  ...)
-	TODO: check
+	NOT-FOR-US: backpack/crud
 CVE-2026-54177 (backpack/crud provides Create, Read, Update & Delete (CRUD) functions  ...)
-	TODO: check
+	NOT-FOR-US: backpack/crud
 CVE-2026-54176 (backpack/crud provides Create, Read, Update & Delete (CRUD) functions  ...)
-	TODO: check
+	NOT-FOR-US: backpack/crud
 CVE-2026-54175 (backpack/crud provides Create, Read, Update & Delete (CRUD) functions  ...)
-	TODO: check
+	NOT-FOR-US: backpack/crud
 CVE-2026-54156 (node-opcua is an OPC UA implementation for TypeScript and Node.js. Pri ...)
 	TODO: check
 CVE-2026-54155 (node-opcua is an OPC UA implementation for TypeScript and Node.js. Pri ...)
@@ -2810,7 +2810,7 @@ CVE-2026-47256 (OpenTelemetry, also known as OTel, is a vendor-neutral open sour
 CVE-2026-46696 (October System provides the system module for October Content Manageme ...)
 	TODO: check
 CVE-2026-44162 (fluent-plugin-s3 is an Amazon S3 input and output plugin for Fluentd.  ...)
-	TODO: check
+	NOT-FOR-US: fluent-plugin-s3
 CVE-2026-34151 (XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0 ...)
 	NOT-FOR-US: XWiki
 CVE-2026-25687 (A race condition in the ZPA tunnel handler of affected versions of Zsc ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/32b157bd5f3d32ce936056e30bf4a7d4144174dc

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/32b157bd5f3d32ce936056e30bf4a7d4144174dc
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260916/e122746f/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list