[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Sep 17 10:37:08 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
83f65f78 by Salvatore Bonaccorso at 2026-09-17T11:35:52+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -56,19 +56,19 @@ CVE-2026-92790 (Higress before 2.2.4 panics when processing a Cookie header segm
 CVE-2026-92789 (Graylog through 7.1.4 validates outbound URLs against an allowlist bef ...)
 	- graylog2 <itp> (bug #652273)
 CVE-2026-92788 (Coze Studio through 0.5.1 fails to validate that table names in workfl ...)
-	TODO: check
+	NOT-FOR-US: Coze Studio
 CVE-2026-92787 (Feast through 0.66.0 fails to verify JWT token signatures before estab ...)
-	TODO: check
+	NOT-FOR-US: Feast
 CVE-2026-92786 (LightGBM through 4.7.0 fails to validate child and split array values  ...)
-	TODO: check
+	NOT-FOR-US: LightGBM
 CVE-2026-92785 (Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload usin ...)
-	TODO: check
+	NOT-FOR-US: Angel
 CVE-2026-92784 (@refinedev/inferencer through 7.0.0 fails to escape API field names wh ...)
-	TODO: check
+	NOT-FOR-US: refinedev/inferencer
 CVE-2026-92783 (Yeti through 2.11.0 fails to validate caller permissions in the DELETE ...)
-	TODO: check
+	NOT-FOR-US: Yeti
 CVE-2026-92782 (Chroma through 1.5.9 fails to validate tenant and database segments wh ...)
-	TODO: check
+	NOT-FOR-US: Chroma
 CVE-2026-92781 (Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a pro ...)
 	TODO: check
 CVE-2026-92780 (KnowStreaming through 3.4.1 fails to enforce role-based access control ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/83f65f78a84ba80c695faf22ee243b1b171e3a35

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/83f65f78a84ba80c695faf22ee243b1b171e3a35
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260917/2dc49718/attachment.htm>


More information about the debian-security-tracker-commits mailing list