[Git][security-tracker-team/security-tracker][master] auto-nfu: Extend Apache rule

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Sep 16 22:26:04 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
2eba3b1a by Moritz Muehlenhoff at 2026-09-16T23:25:41+02:00
auto-nfu: Extend Apache rule

- - - - -


2 changed files:

- data/CVE/list
- data/packages/nfu.yaml


Changes:

=====================================
data/CVE/list
=====================================
@@ -639,7 +639,7 @@ CVE-2026-87028 (Concrete CMS 9 through 9.5.3 did not confirm that a board Instan
 CVE-2026-86823 (The Newsletter  WordPress plugin before 9.3.7 does not validate the de ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-86792 (Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 reso ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-86784 (The Visualizer  WordPress plugin before 4.0.8 does not sanitise and es ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-86585 (The lack of signature verification of firmware update packages in VEO  ...)
@@ -651,7 +651,7 @@ CVE-2026-86474 (The lack of TLS certificate validation when downloading firmware
 CVE-2026-86466 (Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth  ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-86465 (Apache Airflow Akeyless provider: the Akeyless secrets backend's team- ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-86462 (Apache Airflow FAB provider: changing a user's password through the Ad ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-86449 (The LearnPress  WordPress plugin before 4.4.7 does not check the user' ...)


=====================================
data/packages/nfu.yaml
=====================================
@@ -357,6 +357,8 @@
       - product: Apache Accumulo
       - product: Apache ActiveMQ Artemis
       - product: Apache ActiveMQ Artemis Stomp Protocol
+      - product: Apache Airflow Akeyless provider
+      - product: Apache Airflow Apache Kafka provider
       - product: Apache Airflow FAB provider
       - product: Apache Allura
       - product: Apache Answer



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2eba3b1a9e8e2fb441858b9af5aab10da00ae514

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2eba3b1a9e8e2fb441858b9af5aab10da00ae514
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260916/d6f28f5b/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list