[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Sep 16 22:33:42 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b49a0639 by Moritz Muehlenhoff at 2026-09-16T23:33:18+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -47,41 +47,41 @@ CVE-2026-92566 (DataGear through 6.0.0 contains a server-side request forgery vu
 CVE-2026-92565 (Rallly before 4.15.0 contains an information disclosure vulnerability  ...)
 	TODO: check
 CVE-2026-92472 (A vulnerability was determined in GPAC 26.08-DEV. The affected element ...)
-	TODO: check
+	- gpac <removed>
 CVE-2026-92469 (zlt2000 microservices-platform through 6.0.0 contains an authorization ...)
-	TODO: check
+	NOT-FOR-US: zlt2000 microservices-platform
 CVE-2026-92468 (zlt2000 microservices-platform through 6.0.0 contains an authorization ...)
-	TODO: check
+	NOT-FOR-US: zlt2000 microservices-platform
 CVE-2026-92467 (zlt2000 microservices-platform through 6.0.0 contains an unverified pa ...)
-	TODO: check
+	NOT-FOR-US: zlt2000 microservices-platform
 CVE-2026-92466 (zlt2000 microservices-platform through 6.0.0 contains a missing author ...)
-	TODO: check
+	NOT-FOR-US: zlt2000 microservices-platform
 CVE-2026-92465 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-92463 (yshop-crm through 2.1.3 contains an authorization failure in the GET / ...)
-	TODO: check
+	NOT-FOR-US: yshop-crm
 CVE-2026-92462 (yshop-crm through 2.1.3 fails to enforce authorization checks on the C ...)
-	TODO: check
+	NOT-FOR-US: yshop-crm
 CVE-2026-92461 (yshop-crm through 2.1.3 contains a missing authorization vulnerability ...)
-	TODO: check
+	NOT-FOR-US: yshop-crm
 CVE-2026-92460 (yshop-crm through 2.1.3 fails to enforce authorization on the GET /adm ...)
-	TODO: check
+	NOT-FOR-US: yshop-crm
 CVE-2026-92459 (yshop-crm through 2.1.3 contains a missing authorization vulnerability ...)
-	TODO: check
+	NOT-FOR-US: yshop-crm
 CVE-2026-92458 (yshop-crm through 2.1.3 contains a missing authorization vulnerability ...)
-	TODO: check
+	NOT-FOR-US: yshop-crm
 CVE-2026-92457 (yshop-crm through 2.1.3 contains a missing authorization vulnerability ...)
-	TODO: check
+	NOT-FOR-US: yshop-crm
 CVE-2026-92456 (yshop-crm through 2.1.3 fails to enforce authorization on the saveRedi ...)
-	TODO: check
+	NOT-FOR-US: yshop-crm
 CVE-2026-92455 (yshop-crm through 2.1.3 fails to enforce authorization on the sendSms  ...)
-	TODO: check
+	NOT-FOR-US: yshop-crm
 CVE-2026-92418 (A vulnerability was determined in ChangeWeDer crm up to c07bd4c9714152 ...)
 	TODO: check
 CVE-2026-92417 (A vulnerability was found in Open5GS up to 2.8.0. This affects the fun ...)
-	TODO: check
+	- open5gs <itp> (bug #1094791)
 CVE-2026-92416 (A vulnerability has been found in Open5GS up to 2.8.0. Affected by thi ...)
-	TODO: check
+	- open5gs <itp> (bug #1094791)
 CVE-2026-92413 (A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e7003698 ...)
 	TODO: check
 CVE-2026-92406 (A vulnerability was detected in SourceCodester Inventory and Monitorin ...)
@@ -93,21 +93,21 @@ CVE-2026-92402 (A security flaw has been discovered in ChangeWeDer crm up to c07
 CVE-2026-92401 (A vulnerability was identified in ChangeWeDer crm up to c07bd4c9714152 ...)
 	TODO: check
 CVE-2026-92399 (A vulnerability was determined in GPAC 26.07.0. This affects the funct ...)
-	TODO: check
+	- gpac <removed>
 CVE-2026-92398 (A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affe ...)
-	TODO: check
+	NOT-FOR-US: Ruijie
 CVE-2026-92397 (A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. ...)
-	TODO: check
+	NOT-FOR-US: Ruijie
 CVE-2026-92395 (@fastify/proxy-addr is a Fastify plugin that determines a request's cl ...)
-	TODO: check
+	NOT-FOR-US: Fastify plugin
 CVE-2026-92385 (A vulnerability has been found in SourceCodester Online Food Ordering  ...)
 	NOT-FOR-US: SourceCodester
 CVE-2026-92383 (A security vulnerability has been detected in PbootCMS up to 3.2.24. T ...)
-	TODO: check
+	NOT-FOR-US: PbootCMS
 CVE-2026-92381 (A weakness has been identified in PbootCMS up to 3.2.22. This affects  ...)
-	TODO: check
+	NOT-FOR-US: PbootCMS
 CVE-2026-92380 (A flaw has been found in WuzhiCMS up to 4.1.0. The impacted element is ...)
-	TODO: check
+	NOT-FOR-US: WuzhiCMS
 CVE-2026-92366 (A vulnerability was determined in code-projects Matrimonial System 1.0 ...)
 	NOT-FOR-US: code-projects
 CVE-2026-92365 (A vulnerability was found in vllm-project vllm up to 0.29.0. Affected  ...)
@@ -125,7 +125,7 @@ CVE-2026-92360 (A weakness has been identified in ag-ui-protocol ag-ui 1.0. The
 CVE-2026-92359 (A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. The ...)
 	TODO: check
 CVE-2026-92358 (A flaw was found in the first broker login flow of Keycloak. When a us ...)
-	TODO: check
+	- keycloak <itp> (bug #1088287)
 CVE-2026-92357 (A vulnerability was identified in a2ui-project a2ui 0.8/0.9/1.0. Impac ...)
 	TODO: check
 CVE-2026-92356 (A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1. This is ...)
@@ -153,19 +153,19 @@ CVE-2026-92234 (QloApps through 1.7.0 reflects unescaped child feature names int
 CVE-2026-92221 (A vulnerability was determined in gedelumbung HospitalManagement up to ...)
 	TODO: check
 CVE-2026-92220 (A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. Affected ...)
-	TODO: check
+	- vllm <itp> (bug #1095237)
 CVE-2026-92217 (A vulnerability was determined in a2ui-project a2ui up to 0.10.6. This ...)
-	TODO: check
+	NOT-FOR-US: a2ui-project a2ui
 CVE-2026-92216 (A vulnerability was found in a2ui-project a2ui up to 0.10.7. Affected  ...)
-	TODO: check
+	NOT-FOR-US: a2ui-project a2ui
 CVE-2026-92215 (A vulnerability has been found in a2ui-project a2ui up to 0.10.7. Affe ...)
-	TODO: check
+	NOT-FOR-US: a2ui-project a2ui
 CVE-2026-92214 (A flaw has been found in a2ui-project a2ui up to 0.10.7. Affected is a ...)
-	TODO: check
+	NOT-FOR-US: a2ui-project a2ui
 CVE-2026-92213 (A vulnerability was detected in a2ui-project a2ui up to 0.10.6. This i ...)
-	TODO: check
+	NOT-FOR-US: a2ui-project a2ui
 CVE-2026-92184 (A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. Aff ...)
-	TODO: check
+	NOT-FOR-US: a2ui-project a2ui
 CVE-2026-92141 (Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not rest ...)
 	NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-92140 (Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape th ...)
@@ -207,11 +207,11 @@ CVE-2026-92123 (Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier
 CVE-2026-92122 (Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does  ...)
 	NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-92114 (A vulnerability was identified in a2ui-project a2ui up to 0.10.6. Affe ...)
-	TODO: check
+	NOT-FOR-US: a2ui-project a2ui
 CVE-2026-92091 (A flaw was found in jwcrypto. The JWK.import_key() function validates  ...)
 	TODO: check
 CVE-2026-92087 (@fastify/auth is a Fastify plugin that composes multiple authenticatio ...)
-	TODO: check
+	NOT-FOR-US: Fastify plugin
 CVE-2026-92081 (fastify is a fast and low-overhead web framework for Node.js. In versi ...)
 	TODO: check
 CVE-2026-91939 (Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unseriali ...)
@@ -261,11 +261,11 @@ CVE-2026-89063 (The Online Scheduling and Appointment Booking System \u2013 Book
 CVE-2026-89040 (Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthe ...)
 	TODO: check
 CVE-2026-89031 (Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-89030 (Adenion Blog2Social plugin for WordPress before 9.1.0 exposes the emai ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-89029 (Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-89028 (MikroTik RouterOS before 7.24 contains a heap memory corruption vulner ...)
 	NOT-FOR-US: MikroTik
 CVE-2026-89027 (miniOrange JWT Authentication for WP REST APIs plugin for WordPress be ...)
@@ -273,7 +273,7 @@ CVE-2026-89027 (miniOrange JWT Authentication for WP REST APIs plugin for WordPr
 CVE-2026-88976 (Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, a ...)
 	TODO: check
 CVE-2026-88975 (Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1. ...)
-	TODO: check
+	NOT-FOR-US: Http4s
 CVE-2026-88922 (The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to  ...)
 	TODO: check
 CVE-2026-88910 (The kboard WordPress plugin before 6.7 does not verify ownership or co ...)
@@ -1659,7 +1659,7 @@ CVE-2026-79993 (The `deleteContainer` opcode (0x14/20) is processed without veri
 CVE-2026-79708 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-79651 (A flaw was found in the theme localization endpoints of the keycloak-s ...)
-	TODO: check
+	- keycloak <itp> (bug #1088287)
 CVE-2026-79298 (An issue in Howyar Technologies Inc SysReturn Versions prior to 11.3.0 ...)
 	TODO: check
 CVE-2026-78474 (The Ni WooCommerce Sales Report  WordPress plugin before 4.2.0 does no ...)
@@ -1859,11 +1859,11 @@ CVE-2026-76104 (Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorre
 CVE-2026-75516 (The RabbitMQ Java client library allows Java and JVM-based application ...)
 	TODO: check
 CVE-2026-75025 (Mattermost Desktop App versions <=6.2 6.2.2.0 Fixed an issue where Mat ...)
-	TODO: check
+	NOT-FOR-US: Mattermost Desktop App
 CVE-2026-74926 (The MultiVendorX  WordPress plugin before 5.0.16 does not verify that  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-74909 (Keycloak provides a policy enforcer to protect applications by matchin ...)
-	TODO: check
+	- keycloak <itp> (bug #1088287)
 CVE-2026-73966 (Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel  ...)
 	NOT-FOR-US: Oracle
 CVE-2026-73965 (Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CR ...)
@@ -2031,35 +2031,35 @@ CVE-2026-70416 (Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserial
 CVE-2026-69486 (Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows a ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-69218 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
-	TODO: check
+	NOT-FOR-US: Http4s
 CVE-2026-69217 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
-	TODO: check
+	NOT-FOR-US: Http4s
 CVE-2026-69216 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
-	TODO: check
+	NOT-FOR-US: Http4s
 CVE-2026-69215 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
-	TODO: check
+	NOT-FOR-US: Http4s
 CVE-2026-69214 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
-	TODO: check
+	NOT-FOR-US: Http4s
 CVE-2026-69213 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
-	TODO: check
+	NOT-FOR-US: Http4s
 CVE-2026-69212 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
-	TODO: check
+	NOT-FOR-US: Http4s
 CVE-2026-69210 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
-	TODO: check
+	NOT-FOR-US: Http4s
 CVE-2026-69206 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
-	TODO: check
+	NOT-FOR-US: Http4s
 CVE-2026-69205 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
-	TODO: check
+	NOT-FOR-US: Http4s
 CVE-2026-69203 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
-	TODO: check
+	NOT-FOR-US: Http4s
 CVE-2026-69202 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
-	TODO: check
+	NOT-FOR-US: Http4s
 CVE-2026-69201 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
-	TODO: check
+	NOT-FOR-US: Http4s
 CVE-2026-69200 (node-opcua is an OPC UA implementation for TypeScript and Node.js. Pri ...)
 	TODO: check
 CVE-2026-69147 (vLLM is an inference and serving engine for large language models. Pri ...)
-	TODO: check
+	- vllm <itp> (bug #1095237)
 CVE-2026-68953 (The affected products are vulnerable to an authentication bypass that  ...)
 	TODO: check
 CVE-2026-68950 (The affected products use hard-coded credentials, which could allow an ...)
@@ -2101,19 +2101,19 @@ CVE-2026-62597 (Vulnerability in the Oracle Enterprise Manager Base Platform pro
 CVE-2026-61709 (OpenFGA is an authorization and permission engine built for developers ...)
 	TODO: check
 CVE-2026-61598 (djust provides Phoenix LiveView-style reactive server-side rendering f ...)
-	TODO: check
+	NOT-FOR-US: djust
 CVE-2026-61595 (djust provides Phoenix LiveView-style reactive server-side rendering f ...)
-	TODO: check
+	NOT-FOR-US: djust
 CVE-2026-61593 (djust provides Phoenix LiveView-style reactive server-side rendering f ...)
-	TODO: check
+	NOT-FOR-US: djust
 CVE-2026-61590 (djust provides Phoenix LiveView-style reactive server-side rendering f ...)
-	TODO: check
+	NOT-FOR-US: djust
 CVE-2026-61568 (`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab.  ...)
-	TODO: check
+	NOT-FOR-US: zereight/mcp-gitlab
 CVE-2026-61560 (`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab.  ...)
-	TODO: check
+	NOT-FOR-US: zereight/mcp-gitlab
 CVE-2026-61559 (`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab.  ...)
-	TODO: check
+	NOT-FOR-US: zereight/mcp-gitlab
 CVE-2026-61554 (emp3r0r is a C2 designed by Linux users for Linux environments. Prior  ...)
 	TODO: check
 CVE-2026-61544 (libp2p-rust is the official Rust language implementation of the libp2p ...)
@@ -2127,15 +2127,15 @@ CVE-2026-59974 (Stanza is a Stanford NLP Python library for tokenization, senten
 CVE-2026-59969 (Apache ZooKeeper quorum TLS fails to enforce peer hostname verificatio ...)
 	TODO: check
 CVE-2026-59823 (LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or  ...)
-	TODO: check
+	NOT-FOR-US: LiteLLM
 CVE-2026-59739 (Information disclosure via SetWatches reconnect replay in Apache ZooKe ...)
 	TODO: check
 CVE-2026-58147 (WNC T-Mobile 5G Box IDU routercontains an OS command injection vulnera ...)
-	TODO: check
+	NOT-FOR-US: WNC T-Mobile 5G Box
 CVE-2026-58146 (WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection v ...)
-	TODO: check
+	NOT-FOR-US: WNC T-Mobile 5G Box
 CVE-2026-57173 (vLLM is an inference and serving engine for large language models. Pri ...)
-	TODO: check
+	- vllm <itp> (bug #1095237)
 CVE-2026-56719 (MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerabi ...)
 	NOT-FOR-US: MikroTik
 CVE-2026-54544 (Fireshare facilitates self-hosted media and link sharing. Prior to ver ...)
@@ -2151,13 +2151,13 @@ CVE-2026-51133 (Cross Site Scripting vulnerability in za-internet GmbH C-MOR Vid
 CVE-2026-47094 (SIMAC MyPHR 1.1 contains an insecure direct object reference (IDOR) vu ...)
 	TODO: check
 CVE-2026-40857 (WNC T-Mobile 5G Box IDU router contains a cross-site request forgery ( ...)
-	TODO: check
+	NOT-FOR-US: WNC T-Mobile 5G Box
 CVE-2026-40856 (WNC T-Mobile 5G Box IDU router is vulnerable to improper access contro ...)
-	TODO: check
+	NOT-FOR-US: WNC T-Mobile 5G Box
 CVE-2026-40855 (WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. T ...)
-	TODO: check
+	NOT-FOR-US: WNC T-Mobile 5G Box
 CVE-2026-40854 (WNC T-Mobile 5G Box IDU router contains an authentication bypass vulne ...)
-	TODO: check
+	NOT-FOR-US: WNC T-Mobile 5G Box
 CVE-2026-3855 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-38999 (A Null Pointer Dereference in the mk_sched_event_close function (mk_se ...)
@@ -2213,11 +2213,11 @@ CVE-2026-20331 (As part of Cisco's ongoing commitment to proactive security and
 CVE-2026-20307 (A vulnerability in the web-based management interface of Cisco ISE cou ...)
 	NOT-FOR-US: Cisco
 CVE-2026-20306 (A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow a ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20305 (A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20234 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-1168 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-19857 (The Formidable Forms WordPress plugin before 6.35 does not prevent a r ...)
@@ -2251,11 +2251,11 @@ CVE-2026-18422 (Concrete CMS before 9.5.3 did not enforce a destination-side aut
 CVE-2026-18421 (Concrete CMS 9 through 9.5.2 does not perform an authorization check i ...)
 	NOT-FOR-US: Concrete CMS
 CVE-2026-18212 (A flaw was found in the SAML Redirect Binding implementation of Keyclo ...)
-	TODO: check
+	- keycloak <itp> (bug #1088287)
 CVE-2026-18120 (Concrete CMS before 9.5.3 exposed a legacy Express entry search endpoi ...)
 	NOT-FOR-US: Concrete CMS
 CVE-2026-17526 (Keycloak is an open-source identity and access management solution. A  ...)
-	TODO: check
+	- keycloak <itp> (bug #1088287)
 CVE-2026-16794 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-16588 (The WP Directory Kit plugin for WordPress is vulnerable to blind SQL I ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b49a06395b49389cf68252ff425af34704f7df03

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b49a06395b49389cf68252ff425af34704f7df03
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260916/8e8f8c6d/attachment.htm>


More information about the debian-security-tracker-commits mailing list