[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Sep 17 10:37:08 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
83f65f78 by Salvatore Bonaccorso at 2026-09-17T11:35:52+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -56,19 +56,19 @@ CVE-2026-92790 (Higress before 2.2.4 panics when processing a Cookie header segm
CVE-2026-92789 (Graylog through 7.1.4 validates outbound URLs against an allowlist bef ...)
- graylog2 <itp> (bug #652273)
CVE-2026-92788 (Coze Studio through 0.5.1 fails to validate that table names in workfl ...)
- TODO: check
+ NOT-FOR-US: Coze Studio
CVE-2026-92787 (Feast through 0.66.0 fails to verify JWT token signatures before estab ...)
- TODO: check
+ NOT-FOR-US: Feast
CVE-2026-92786 (LightGBM through 4.7.0 fails to validate child and split array values ...)
- TODO: check
+ NOT-FOR-US: LightGBM
CVE-2026-92785 (Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload usin ...)
- TODO: check
+ NOT-FOR-US: Angel
CVE-2026-92784 (@refinedev/inferencer through 7.0.0 fails to escape API field names wh ...)
- TODO: check
+ NOT-FOR-US: refinedev/inferencer
CVE-2026-92783 (Yeti through 2.11.0 fails to validate caller permissions in the DELETE ...)
- TODO: check
+ NOT-FOR-US: Yeti
CVE-2026-92782 (Chroma through 1.5.9 fails to validate tenant and database segments wh ...)
- TODO: check
+ NOT-FOR-US: Chroma
CVE-2026-92781 (Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a pro ...)
TODO: check
CVE-2026-92780 (KnowStreaming through 3.4.1 fails to enforce role-based access control ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/83f65f78a84ba80c695faf22ee243b1b171e3a35
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/83f65f78a84ba80c695faf22ee243b1b171e3a35
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260917/2dc49718/attachment.htm>
More information about the debian-security-tracker-commits
mailing list