[Git][security-tracker-team/security-tracker][master] Process some more NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Sep 16 15:55:16 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
56a58e48 by Salvatore Bonaccorso at 2026-09-16T16:54:54+02:00
Process some more NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -804,7 +804,7 @@ CVE-2026-55302 (In multiple locations, there is a possible permission bypass due
CVE-2026-55301 (In Wave6VpuDecFlush of wave6.c, there is a possible out-of-bounds writ ...)
NOT-FOR-US: Google devices
CVE-2026-55211 (Surfio is a library for reading and writing surface files. Prior to 0. ...)
- TODO: check
+ NOT-FOR-US: Surfio
CVE-2026-55178 (GeoLens is a self-hosted geospatial data catalog with semantic search, ...)
NOT-FOR-US: GeoLens
CVE-2026-55158 (Conflibot warns in advance when merging a pull request will cause conf ...)
@@ -1889,7 +1889,7 @@ CVE-2026-68489 (Static Code Injection in Plesk extensions "Ruby" before 1.6.6 an
CVE-2026-67399 (Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0. ...)
NOT-FOR-US: WHMCS
CVE-2026-65838 (Skipper is an HTTP router and reverse proxy for service composition. P ...)
- TODO: check
+ NOT-FOR-US: Zalando Skipper
CVE-2026-65415 (A race condition was addressed with additional validation. This issue ...)
NOT-FOR-US: Apple
CVE-2026-65414 (An out-of-bounds write issue was addressed with improved bounds checki ...)
@@ -2617,13 +2617,13 @@ CVE-2026-77051 (Improper Neutralization of Special Elements used in an SQL Comma
CVE-2026-76461 (A vulnerability in the email parsing of Cisco AsyncOS Software for Cis ...)
NOT-FOR-US: Cisco
CVE-2026-76443 (As part of Cisco's ongoing commitment to proactive security and produc ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-76442 (As part of Cisco's ongoing commitment to proactive security and produc ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-76441 (As part of Cisco's ongoing commitment to proactive security and produc ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-76440 (As part of Cisco's ongoing commitment to proactive security and produc ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-75030 (Missing Authorization vulnerability in Apache Syncope. An administr ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-75015 (Insufficiently Protected Credentials vulnerability in Apache Syncope. ...)
@@ -2727,13 +2727,13 @@ CVE-2026-55795 (Craft Commerce is an ecommerce platform for Craft CMS. From 4.0.
CVE-2026-55451 (gettext-converter provides gettext resource conversion utilities for J ...)
NOT-FOR-US: Node gettext-converter
CVE-2026-55416 (Pimcore is an Open Source Data & Experience Management Platform. Prior ...)
- TODO: check
+ NOT-FOR-US: Pimcore
CVE-2026-55253 (LangChain MongoDB provides integrations between MongoDB, Atlas, LangCh ...)
- TODO: check
+ NOT-FOR-US: LangChain MongoDB
CVE-2026-55236 (langgraph-api implements the LangGraph API for rapid development and t ...)
- TODO: check
+ NOT-FOR-US: langgraph-api
CVE-2026-55235 (langgraph-api implements the LangGraph API for rapid development and t ...)
- TODO: check
+ NOT-FOR-US: langgraph-api
CVE-2026-55102 (hashi-vault-js is a Node.js module for interacting with the HashiCorp ...)
TODO: check
CVE-2026-55091 (flat-to-nested converts a hierarchy from a flat representation to a ne ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/56a58e4809d24c065ef9acca120c61117ebf4abd
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/56a58e4809d24c065ef9acca120c61117ebf4abd
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260916/d06365cf/attachment.htm>
More information about the debian-security-tracker-commits
mailing list