[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Wed Sep 16 22:33:42 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b49a0639 by Moritz Muehlenhoff at 2026-09-16T23:33:18+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -47,41 +47,41 @@ CVE-2026-92566 (DataGear through 6.0.0 contains a server-side request forgery vu
CVE-2026-92565 (Rallly before 4.15.0 contains an information disclosure vulnerability ...)
TODO: check
CVE-2026-92472 (A vulnerability was determined in GPAC 26.08-DEV. The affected element ...)
- TODO: check
+ - gpac <removed>
CVE-2026-92469 (zlt2000 microservices-platform through 6.0.0 contains an authorization ...)
- TODO: check
+ NOT-FOR-US: zlt2000 microservices-platform
CVE-2026-92468 (zlt2000 microservices-platform through 6.0.0 contains an authorization ...)
- TODO: check
+ NOT-FOR-US: zlt2000 microservices-platform
CVE-2026-92467 (zlt2000 microservices-platform through 6.0.0 contains an unverified pa ...)
- TODO: check
+ NOT-FOR-US: zlt2000 microservices-platform
CVE-2026-92466 (zlt2000 microservices-platform through 6.0.0 contains a missing author ...)
- TODO: check
+ NOT-FOR-US: zlt2000 microservices-platform
CVE-2026-92465 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-92463 (yshop-crm through 2.1.3 contains an authorization failure in the GET / ...)
- TODO: check
+ NOT-FOR-US: yshop-crm
CVE-2026-92462 (yshop-crm through 2.1.3 fails to enforce authorization checks on the C ...)
- TODO: check
+ NOT-FOR-US: yshop-crm
CVE-2026-92461 (yshop-crm through 2.1.3 contains a missing authorization vulnerability ...)
- TODO: check
+ NOT-FOR-US: yshop-crm
CVE-2026-92460 (yshop-crm through 2.1.3 fails to enforce authorization on the GET /adm ...)
- TODO: check
+ NOT-FOR-US: yshop-crm
CVE-2026-92459 (yshop-crm through 2.1.3 contains a missing authorization vulnerability ...)
- TODO: check
+ NOT-FOR-US: yshop-crm
CVE-2026-92458 (yshop-crm through 2.1.3 contains a missing authorization vulnerability ...)
- TODO: check
+ NOT-FOR-US: yshop-crm
CVE-2026-92457 (yshop-crm through 2.1.3 contains a missing authorization vulnerability ...)
- TODO: check
+ NOT-FOR-US: yshop-crm
CVE-2026-92456 (yshop-crm through 2.1.3 fails to enforce authorization on the saveRedi ...)
- TODO: check
+ NOT-FOR-US: yshop-crm
CVE-2026-92455 (yshop-crm through 2.1.3 fails to enforce authorization on the sendSms ...)
- TODO: check
+ NOT-FOR-US: yshop-crm
CVE-2026-92418 (A vulnerability was determined in ChangeWeDer crm up to c07bd4c9714152 ...)
TODO: check
CVE-2026-92417 (A vulnerability was found in Open5GS up to 2.8.0. This affects the fun ...)
- TODO: check
+ - open5gs <itp> (bug #1094791)
CVE-2026-92416 (A vulnerability has been found in Open5GS up to 2.8.0. Affected by thi ...)
- TODO: check
+ - open5gs <itp> (bug #1094791)
CVE-2026-92413 (A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e7003698 ...)
TODO: check
CVE-2026-92406 (A vulnerability was detected in SourceCodester Inventory and Monitorin ...)
@@ -93,21 +93,21 @@ CVE-2026-92402 (A security flaw has been discovered in ChangeWeDer crm up to c07
CVE-2026-92401 (A vulnerability was identified in ChangeWeDer crm up to c07bd4c9714152 ...)
TODO: check
CVE-2026-92399 (A vulnerability was determined in GPAC 26.07.0. This affects the funct ...)
- TODO: check
+ - gpac <removed>
CVE-2026-92398 (A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affe ...)
- TODO: check
+ NOT-FOR-US: Ruijie
CVE-2026-92397 (A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. ...)
- TODO: check
+ NOT-FOR-US: Ruijie
CVE-2026-92395 (@fastify/proxy-addr is a Fastify plugin that determines a request's cl ...)
- TODO: check
+ NOT-FOR-US: Fastify plugin
CVE-2026-92385 (A vulnerability has been found in SourceCodester Online Food Ordering ...)
NOT-FOR-US: SourceCodester
CVE-2026-92383 (A security vulnerability has been detected in PbootCMS up to 3.2.24. T ...)
- TODO: check
+ NOT-FOR-US: PbootCMS
CVE-2026-92381 (A weakness has been identified in PbootCMS up to 3.2.22. This affects ...)
- TODO: check
+ NOT-FOR-US: PbootCMS
CVE-2026-92380 (A flaw has been found in WuzhiCMS up to 4.1.0. The impacted element is ...)
- TODO: check
+ NOT-FOR-US: WuzhiCMS
CVE-2026-92366 (A vulnerability was determined in code-projects Matrimonial System 1.0 ...)
NOT-FOR-US: code-projects
CVE-2026-92365 (A vulnerability was found in vllm-project vllm up to 0.29.0. Affected ...)
@@ -125,7 +125,7 @@ CVE-2026-92360 (A weakness has been identified in ag-ui-protocol ag-ui 1.0. The
CVE-2026-92359 (A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. The ...)
TODO: check
CVE-2026-92358 (A flaw was found in the first broker login flow of Keycloak. When a us ...)
- TODO: check
+ - keycloak <itp> (bug #1088287)
CVE-2026-92357 (A vulnerability was identified in a2ui-project a2ui 0.8/0.9/1.0. Impac ...)
TODO: check
CVE-2026-92356 (A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1. This is ...)
@@ -153,19 +153,19 @@ CVE-2026-92234 (QloApps through 1.7.0 reflects unescaped child feature names int
CVE-2026-92221 (A vulnerability was determined in gedelumbung HospitalManagement up to ...)
TODO: check
CVE-2026-92220 (A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. Affected ...)
- TODO: check
+ - vllm <itp> (bug #1095237)
CVE-2026-92217 (A vulnerability was determined in a2ui-project a2ui up to 0.10.6. This ...)
- TODO: check
+ NOT-FOR-US: a2ui-project a2ui
CVE-2026-92216 (A vulnerability was found in a2ui-project a2ui up to 0.10.7. Affected ...)
- TODO: check
+ NOT-FOR-US: a2ui-project a2ui
CVE-2026-92215 (A vulnerability has been found in a2ui-project a2ui up to 0.10.7. Affe ...)
- TODO: check
+ NOT-FOR-US: a2ui-project a2ui
CVE-2026-92214 (A flaw has been found in a2ui-project a2ui up to 0.10.7. Affected is a ...)
- TODO: check
+ NOT-FOR-US: a2ui-project a2ui
CVE-2026-92213 (A vulnerability was detected in a2ui-project a2ui up to 0.10.6. This i ...)
- TODO: check
+ NOT-FOR-US: a2ui-project a2ui
CVE-2026-92184 (A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. Aff ...)
- TODO: check
+ NOT-FOR-US: a2ui-project a2ui
CVE-2026-92141 (Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not rest ...)
NOT-FOR-US: Jenkins (core or plugin)
CVE-2026-92140 (Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape th ...)
@@ -207,11 +207,11 @@ CVE-2026-92123 (Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier
CVE-2026-92122 (Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does ...)
NOT-FOR-US: Jenkins (core or plugin)
CVE-2026-92114 (A vulnerability was identified in a2ui-project a2ui up to 0.10.6. Affe ...)
- TODO: check
+ NOT-FOR-US: a2ui-project a2ui
CVE-2026-92091 (A flaw was found in jwcrypto. The JWK.import_key() function validates ...)
TODO: check
CVE-2026-92087 (@fastify/auth is a Fastify plugin that composes multiple authenticatio ...)
- TODO: check
+ NOT-FOR-US: Fastify plugin
CVE-2026-92081 (fastify is a fast and low-overhead web framework for Node.js. In versi ...)
TODO: check
CVE-2026-91939 (Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unseriali ...)
@@ -261,11 +261,11 @@ CVE-2026-89063 (The Online Scheduling and Appointment Booking System \u2013 Book
CVE-2026-89040 (Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthe ...)
TODO: check
CVE-2026-89031 (Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-89030 (Adenion Blog2Social plugin for WordPress before 9.1.0 exposes the emai ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-89029 (Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-89028 (MikroTik RouterOS before 7.24 contains a heap memory corruption vulner ...)
NOT-FOR-US: MikroTik
CVE-2026-89027 (miniOrange JWT Authentication for WP REST APIs plugin for WordPress be ...)
@@ -273,7 +273,7 @@ CVE-2026-89027 (miniOrange JWT Authentication for WP REST APIs plugin for WordPr
CVE-2026-88976 (Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, a ...)
TODO: check
CVE-2026-88975 (Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1. ...)
- TODO: check
+ NOT-FOR-US: Http4s
CVE-2026-88922 (The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to ...)
TODO: check
CVE-2026-88910 (The kboard WordPress plugin before 6.7 does not verify ownership or co ...)
@@ -1659,7 +1659,7 @@ CVE-2026-79993 (The `deleteContainer` opcode (0x14/20) is processed without veri
CVE-2026-79708 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-79651 (A flaw was found in the theme localization endpoints of the keycloak-s ...)
- TODO: check
+ - keycloak <itp> (bug #1088287)
CVE-2026-79298 (An issue in Howyar Technologies Inc SysReturn Versions prior to 11.3.0 ...)
TODO: check
CVE-2026-78474 (The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does no ...)
@@ -1859,11 +1859,11 @@ CVE-2026-76104 (Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorre
CVE-2026-75516 (The RabbitMQ Java client library allows Java and JVM-based application ...)
TODO: check
CVE-2026-75025 (Mattermost Desktop App versions <=6.2 6.2.2.0 Fixed an issue where Mat ...)
- TODO: check
+ NOT-FOR-US: Mattermost Desktop App
CVE-2026-74926 (The MultiVendorX WordPress plugin before 5.0.16 does not verify that ...)
NOT-FOR-US: WordPress plugin
CVE-2026-74909 (Keycloak provides a policy enforcer to protect applications by matchin ...)
- TODO: check
+ - keycloak <itp> (bug #1088287)
CVE-2026-73966 (Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel ...)
NOT-FOR-US: Oracle
CVE-2026-73965 (Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CR ...)
@@ -2031,35 +2031,35 @@ CVE-2026-70416 (Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserial
CVE-2026-69486 (Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows a ...)
NOT-FOR-US: Microsoft
CVE-2026-69218 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
- TODO: check
+ NOT-FOR-US: Http4s
CVE-2026-69217 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
- TODO: check
+ NOT-FOR-US: Http4s
CVE-2026-69216 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
- TODO: check
+ NOT-FOR-US: Http4s
CVE-2026-69215 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
- TODO: check
+ NOT-FOR-US: Http4s
CVE-2026-69214 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
- TODO: check
+ NOT-FOR-US: Http4s
CVE-2026-69213 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
- TODO: check
+ NOT-FOR-US: Http4s
CVE-2026-69212 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
- TODO: check
+ NOT-FOR-US: Http4s
CVE-2026-69210 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
- TODO: check
+ NOT-FOR-US: Http4s
CVE-2026-69206 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
- TODO: check
+ NOT-FOR-US: Http4s
CVE-2026-69205 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
- TODO: check
+ NOT-FOR-US: Http4s
CVE-2026-69203 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
- TODO: check
+ NOT-FOR-US: Http4s
CVE-2026-69202 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
- TODO: check
+ NOT-FOR-US: Http4s
CVE-2026-69201 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
- TODO: check
+ NOT-FOR-US: Http4s
CVE-2026-69200 (node-opcua is an OPC UA implementation for TypeScript and Node.js. Pri ...)
TODO: check
CVE-2026-69147 (vLLM is an inference and serving engine for large language models. Pri ...)
- TODO: check
+ - vllm <itp> (bug #1095237)
CVE-2026-68953 (The affected products are vulnerable to an authentication bypass that ...)
TODO: check
CVE-2026-68950 (The affected products use hard-coded credentials, which could allow an ...)
@@ -2101,19 +2101,19 @@ CVE-2026-62597 (Vulnerability in the Oracle Enterprise Manager Base Platform pro
CVE-2026-61709 (OpenFGA is an authorization and permission engine built for developers ...)
TODO: check
CVE-2026-61598 (djust provides Phoenix LiveView-style reactive server-side rendering f ...)
- TODO: check
+ NOT-FOR-US: djust
CVE-2026-61595 (djust provides Phoenix LiveView-style reactive server-side rendering f ...)
- TODO: check
+ NOT-FOR-US: djust
CVE-2026-61593 (djust provides Phoenix LiveView-style reactive server-side rendering f ...)
- TODO: check
+ NOT-FOR-US: djust
CVE-2026-61590 (djust provides Phoenix LiveView-style reactive server-side rendering f ...)
- TODO: check
+ NOT-FOR-US: djust
CVE-2026-61568 (`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. ...)
- TODO: check
+ NOT-FOR-US: zereight/mcp-gitlab
CVE-2026-61560 (`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. ...)
- TODO: check
+ NOT-FOR-US: zereight/mcp-gitlab
CVE-2026-61559 (`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. ...)
- TODO: check
+ NOT-FOR-US: zereight/mcp-gitlab
CVE-2026-61554 (emp3r0r is a C2 designed by Linux users for Linux environments. Prior ...)
TODO: check
CVE-2026-61544 (libp2p-rust is the official Rust language implementation of the libp2p ...)
@@ -2127,15 +2127,15 @@ CVE-2026-59974 (Stanza is a Stanford NLP Python library for tokenization, senten
CVE-2026-59969 (Apache ZooKeeper quorum TLS fails to enforce peer hostname verificatio ...)
TODO: check
CVE-2026-59823 (LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or ...)
- TODO: check
+ NOT-FOR-US: LiteLLM
CVE-2026-59739 (Information disclosure via SetWatches reconnect replay in Apache ZooKe ...)
TODO: check
CVE-2026-58147 (WNC T-Mobile 5G Box IDU routercontains an OS command injection vulnera ...)
- TODO: check
+ NOT-FOR-US: WNC T-Mobile 5G Box
CVE-2026-58146 (WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection v ...)
- TODO: check
+ NOT-FOR-US: WNC T-Mobile 5G Box
CVE-2026-57173 (vLLM is an inference and serving engine for large language models. Pri ...)
- TODO: check
+ - vllm <itp> (bug #1095237)
CVE-2026-56719 (MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerabi ...)
NOT-FOR-US: MikroTik
CVE-2026-54544 (Fireshare facilitates self-hosted media and link sharing. Prior to ver ...)
@@ -2151,13 +2151,13 @@ CVE-2026-51133 (Cross Site Scripting vulnerability in za-internet GmbH C-MOR Vid
CVE-2026-47094 (SIMAC MyPHR 1.1 contains an insecure direct object reference (IDOR) vu ...)
TODO: check
CVE-2026-40857 (WNC T-Mobile 5G Box IDU router contains a cross-site request forgery ( ...)
- TODO: check
+ NOT-FOR-US: WNC T-Mobile 5G Box
CVE-2026-40856 (WNC T-Mobile 5G Box IDU router is vulnerable to improper access contro ...)
- TODO: check
+ NOT-FOR-US: WNC T-Mobile 5G Box
CVE-2026-40855 (WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. T ...)
- TODO: check
+ NOT-FOR-US: WNC T-Mobile 5G Box
CVE-2026-40854 (WNC T-Mobile 5G Box IDU router contains an authentication bypass vulne ...)
- TODO: check
+ NOT-FOR-US: WNC T-Mobile 5G Box
CVE-2026-3855 (GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-38999 (A Null Pointer Dereference in the mk_sched_event_close function (mk_se ...)
@@ -2213,11 +2213,11 @@ CVE-2026-20331 (As part of Cisco's ongoing commitment to proactive security and
CVE-2026-20307 (A vulnerability in the web-based management interface of Cisco ISE cou ...)
NOT-FOR-US: Cisco
CVE-2026-20306 (A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow a ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20305 (A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20234 (As part of Cisco's ongoing commitment to proactive security and produc ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-1168 (GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-19857 (The Formidable Forms WordPress plugin before 6.35 does not prevent a r ...)
@@ -2251,11 +2251,11 @@ CVE-2026-18422 (Concrete CMS before 9.5.3 did not enforce a destination-side aut
CVE-2026-18421 (Concrete CMS 9 through 9.5.2 does not perform an authorization check i ...)
NOT-FOR-US: Concrete CMS
CVE-2026-18212 (A flaw was found in the SAML Redirect Binding implementation of Keyclo ...)
- TODO: check
+ - keycloak <itp> (bug #1088287)
CVE-2026-18120 (Concrete CMS before 9.5.3 exposed a legacy Express entry search endpoi ...)
NOT-FOR-US: Concrete CMS
CVE-2026-17526 (Keycloak is an open-source identity and access management solution. A ...)
- TODO: check
+ - keycloak <itp> (bug #1088287)
CVE-2026-16794 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-16588 (The WP Directory Kit plugin for WordPress is vulnerable to blind SQL I ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b49a06395b49389cf68252ff425af34704f7df03
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b49a06395b49389cf68252ff425af34704f7df03
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260916/8e8f8c6d/attachment.htm>
More information about the debian-security-tracker-commits
mailing list