[Git][security-tracker-team/security-tracker][master] Process some more NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Sep 16 15:55:16 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
56a58e48 by Salvatore Bonaccorso at 2026-09-16T16:54:54+02:00
Process some more NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -804,7 +804,7 @@ CVE-2026-55302 (In multiple locations, there is a possible permission bypass due
 CVE-2026-55301 (In Wave6VpuDecFlush of wave6.c, there is a possible out-of-bounds writ ...)
 	NOT-FOR-US: Google devices
 CVE-2026-55211 (Surfio is a library for reading and writing surface files. Prior to 0. ...)
-	TODO: check
+	NOT-FOR-US: Surfio
 CVE-2026-55178 (GeoLens is a self-hosted geospatial data catalog with semantic search, ...)
 	NOT-FOR-US: GeoLens
 CVE-2026-55158 (Conflibot warns in advance when merging a pull request will cause conf ...)
@@ -1889,7 +1889,7 @@ CVE-2026-68489 (Static Code Injection in Plesk extensions "Ruby" before 1.6.6 an
 CVE-2026-67399 (Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0. ...)
 	NOT-FOR-US: WHMCS
 CVE-2026-65838 (Skipper is an HTTP router and reverse proxy for service composition. P ...)
-	TODO: check
+	NOT-FOR-US: Zalando Skipper
 CVE-2026-65415 (A race condition was addressed with additional validation. This issue  ...)
 	NOT-FOR-US: Apple
 CVE-2026-65414 (An out-of-bounds write issue was addressed with improved bounds checki ...)
@@ -2617,13 +2617,13 @@ CVE-2026-77051 (Improper Neutralization of Special Elements used in an SQL Comma
 CVE-2026-76461 (A vulnerability in the email parsing of Cisco AsyncOS Software for Cis ...)
 	NOT-FOR-US: Cisco
 CVE-2026-76443 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76442 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76441 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76440 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-75030 (Missing Authorization vulnerability in Apache Syncope.    An administr ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-75015 (Insufficiently Protected Credentials vulnerability in Apache Syncope.  ...)
@@ -2727,13 +2727,13 @@ CVE-2026-55795 (Craft Commerce is an ecommerce platform for Craft CMS. From 4.0.
 CVE-2026-55451 (gettext-converter provides gettext resource conversion utilities for J ...)
 	NOT-FOR-US: Node gettext-converter
 CVE-2026-55416 (Pimcore is an Open Source Data & Experience Management Platform. Prior ...)
-	TODO: check
+	NOT-FOR-US: Pimcore
 CVE-2026-55253 (LangChain MongoDB provides integrations between MongoDB, Atlas, LangCh ...)
-	TODO: check
+	NOT-FOR-US: LangChain MongoDB
 CVE-2026-55236 (langgraph-api implements the LangGraph API for rapid development and t ...)
-	TODO: check
+	NOT-FOR-US: langgraph-api
 CVE-2026-55235 (langgraph-api implements the LangGraph API for rapid development and t ...)
-	TODO: check
+	NOT-FOR-US: langgraph-api
 CVE-2026-55102 (hashi-vault-js is a Node.js module for interacting with the HashiCorp  ...)
 	TODO: check
 CVE-2026-55091 (flat-to-nested converts a hierarchy from a flat representation to a ne ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/56a58e4809d24c065ef9acca120c61117ebf4abd

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/56a58e4809d24c065ef9acca120c61117ebf4abd
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260916/d06365cf/attachment.htm>


More information about the debian-security-tracker-commits mailing list