[Git][security-tracker-team/security-tracker][master] auto-nfu: Add rule for AVideo
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Sep 17 10:23:14 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
7c061b18 by Moritz Muehlenhoff at 2026-09-17T11:22:22+02:00
auto-nfu: Add rule for AVideo
- - - - -
2 changed files:
- data/CVE/list
- data/packages/nfu.yaml
Changes:
=====================================
data/CVE/list
=====================================
@@ -146,25 +146,25 @@ CVE-2026-92588 (n8n is a workflow automation platform. In n8n versions before 1.
CVE-2026-92587 (n8n is a workflow automation platform. In versions before 1.123.76, 2. ...)
NOT-FOR-US: n8n
CVE-2026-92586 (AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-92585 (AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-92584 (AVideo through 29.0 (current revision e01e41ecc) contains a stored cro ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-92583 (AVideo through 29.0 contains a race condition in the enforceRateLimit( ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-92582 (AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-92581 (In AVideo through 29.0, Like::__construct() performs counter arithmeti ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-92580 (In AVideo through 29.0, the CloneSite plugin is vulnerable to stored O ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-92579 (In AVideo through 29.0, the autoCSRFGuard() function maintains a hardc ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-92578 (WWBN AVideo through 29.0 contains an authentication bypass vulnerabili ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-92577 (In AVideo through 29.0, the API get_api_video endpoint contains a brok ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-92576 (HKUDS nanobot before 0.3.0 contains a server-side request forgery vuln ...)
TODO: check
CVE-2026-92527 (A vulnerability has been found in chatwoot up to 4.17.1. This impacts ...)
=====================================
data/packages/nfu.yaml
=====================================
@@ -1036,6 +1036,8 @@
description: '.*\bAdvantech\b.*'
- reason: Argo CD
description: '.*\b(?i:Argo CD)\b.*'
+- reason: WWBN AVideo
+ description: '.*\bAVideo\b.*'
- reason: Belkin
description: '.*\bBelkin\b.*'
- reason: Bento4
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7c061b18318e1d3e477118b22d335d6860d7b702
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7c061b18318e1d3e477118b22d335d6860d7b702
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260917/127d4644/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list