[Git][security-tracker-team/security-tracker][master] 2 commits: auto-nfu: Fix entry for HP CNA NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 18 05:20:53 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
afc1b9fc by Salvatore Bonaccorso at 2026-09-18T06:19:53+02:00
auto-nfu: Fix entry for HP CNA NFUs

- - - - -
7fdda328 by Salvatore Bonaccorso at 2026-09-18T06:20:33+02:00
Process some NFUs

- - - - -


2 changed files:

- data/CVE/list
- data/packages/nfu.yaml


Changes:

=====================================
data/CVE/list
=====================================
@@ -45,9 +45,9 @@ CVE-2026-92992 (A security vulnerability has been detected in Dromara mayfly-go
 CVE-2026-92987 (roxmltree through 0.21.1 performs quadratic-time attribute and namespa ...)
 	TODO: check
 CVE-2026-92986 (SiYuan before 3.8.4 renders document titles as HTML in the backlink do ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-92985 (SiYuan versions before 3.8.4 fail to escape bookmark labels imported f ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-92984 (HUBzero CMS through 2.2.32 accepts session identifiers from query stri ...)
 	TODO: check
 CVE-2026-92983 (InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggreg ...)
@@ -103,7 +103,7 @@ CVE-2026-92945 (vm2 before 3.11.7 contains a module allowlist bypass vulnerabili
 CVE-2026-92944 (vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerabil ...)
 	TODO: check
 CVE-2026-92943 (Improper validation of certificate with host mismatch in the MQTT clie ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-92942 (vm2 before 3.11.7 (affected versions <= 3.11.6) does not enforce the V ...)
 	TODO: check
 CVE-2026-92941 (vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to N ...)
@@ -127,9 +127,9 @@ CVE-2026-92933 (vm2 is a sandbox for running untrusted Node.js code. In versions
 CVE-2026-92932 (In the MISP sachertortephp library, the Xml::build() static method in  ...)
 	- misp <itp> (bug #1144317)
 CVE-2026-92927 (A vulnerability was found in SourceCodester Drug Recommendation System ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-92926 (A vulnerability has been found in code-projects Matrimonial System 1.0 ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2026-92925 (A flaw was found in Redis community. The cluster bus packet parser, re ...)
 	TODO: check
 CVE-2026-92921 (admin3 through 3.0.0 stores account passwords using single-round MD5 w ...)
@@ -145,13 +145,13 @@ CVE-2026-92917 (Grav is a flat-file CMS. In versions 2.0.0-rc.1 through 2.0.21,
 CVE-2026-92916 (Grav is a flat-file CMS. In Grav 1.7.0 through 1.7.53.2 and 2.0.0 thro ...)
 	TODO: check
 CVE-2026-92915 (WWBN AVideo through commit e01e41ecc (no patched version available) co ...)
-	TODO: check
+	NOT-FOR-US: WWBN AVideo
 CVE-2026-92914 (AVideo LoginControl contains an authentication bypass vulnerability in ...)
-	TODO: check
+	NOT-FOR-US: WWBN AVideo
 CVE-2026-92913 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a  ...)
-	TODO: check
+	NOT-FOR-US: WWBN AVideo
 CVE-2026-92912 (AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptogra ...)
-	TODO: check
+	NOT-FOR-US: WWBN AVideo
 CVE-2026-92904 (A flaw was found in the foreman_remote_execution plugin's template inv ...)
 	TODO: check
 CVE-2026-92903 (Improper input validation in Snowflake CLI versions prior to 3.27.0 al ...)
@@ -181,9 +181,9 @@ CVE-2026-91039 (Authentication Bypass by Spoofing vulnerability in team-alembic
 CVE-2026-90997 (A flaw was found in Keycloak. When deployed in stateless mode with MyS ...)
 	TODO: check
 CVE-2026-90986 (Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Tim ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-90887 (Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <=  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-90823 (FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firm ...)
 	TODO: check
 CVE-2026-90822 (FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firm ...)
@@ -197,9 +197,9 @@ CVE-2026-89036 (Appwrite before 2.0.0 contains an argument injection vulnerabili
 CVE-2026-88952 (Improper Authentication vulnerability in team-alembic AshAuthenticatio ...)
 	TODO: check
 CVE-2026-87831 (The Checkout Field Manager (Checkout Manager) for WooCommerce WordPres ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-87829 (The Checkout Field Manager (Checkout Manager) for WooCommerce WordPres ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-87742 (A flaw was found in quarkus-websockets-next. This vulnerability allows ...)
 	TODO: check
 CVE-2026-86864 (pgAdmin 4's Backup tool appended the client-supplied 'database' field  ...)
@@ -267,51 +267,51 @@ CVE-2026-81516 (Steeltoe is an open source project that provides a collection of
 CVE-2026-81515 (Steeltoe is an open source project that provides a collection of libra ...)
 	TODO: check
 CVE-2026-81481 (Dell OpenManage Server Administrator, versions prior to 11.1.0.3, cont ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81480 (Dell OpenManage Server Administrator, versions prior to 11.1.0.3, cont ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81479 (Dell OpenManage Server Administrator, versions prior to 11.1.0.3, cont ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81478 (Dell OpenManage Server Administrator, versions prior to 11.1.0.3, cont ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81477 (Dell OpenManage Server Administrator, versions prior to 11.1.0.3, cont ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81476 (Dell OpenManage Server Administrator, versions prior to 11.1.0.3, cont ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81475 (Dell OpenManage Server Administrator, versions prior to 11.1.0.3, cont ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81474 (Dell OpenManage Server Administrator, versions prior to 11.1.0.3, cont ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81453 (Dell OpenManage Server Administrator, versions prior to 11.1.0.3, cont ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81447 (Dell OpenManage Server Administrator, versions prior to 11.1.0.3, cont ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81446 (Dell OpenManage Server Administrator, versions prior to 11.1.0.3, cont ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81445 (Dell OpenManage Server Administrator, versions prior to 11.1.0.3, cont ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81443 (Dell OpenManage Server Administrator, versions prior to 11.1.0.3, cont ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81442 (Dell OpenManage Server Administrator, versions prior to 11.1.0.3, cont ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81441 (Dell OpenManage Server Administrator, versions prior to 11.1.0.3, cont ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81440 (Dell OpenManage Server Administrator, versions prior to 11.1.0.3, cont ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81439 (Dell OpenManage Server Administrator, versions prior to 11.1.0.3, cont ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81438 (Dell OpenManage Server Administrator, versions prior to 11.1.0.3, cont ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-80356 (Dell OpenManage Server Administrator, versions prior to 11.1.0.3, cont ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-80355 (Dell OpenManage Server Administrator, versions prior to 11.1.0.3, cont ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-80218 (Improper Authentication vulnerability in team-alembic AshAuthenticatio ...)
 	TODO: check
 CVE-2026-79752 (CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6 ...)
 	TODO: check
 CVE-2026-78528 (Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78428 (For users authenticated through SAML or OpenID Connect (OIDC), this vu ...)
 	TODO: check
 CVE-2026-78427 (The NeuVector admission webhook silently excludes containers from poli ...)
@@ -321,11 +321,11 @@ CVE-2026-78426 (The NeuVector JWT verifier accepts noncanonical Base64URL encodi
 CVE-2026-78425 (Authorised users of outside applications behind the same corporate ide ...)
 	TODO: check
 CVE-2026-78296 (Insufficient Verification of Data Authenticity vulnerability in WP Man ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78295 (Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78294 (Contributor Cross Site Scripting (XSS) in  Geo Mashup <= 1.13.21 versi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78223 (Improper Verification of Cryptographic Signature vulnerability in team ...)
 	TODO: check
 CVE-2026-77614 (Opencast is a free, open-source platform to support the management of  ...)
@@ -339,65 +339,65 @@ CVE-2026-75588 (Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate t
 CVE-2026-75523 (Steeltoe is an open source project that provides a collection of libra ...)
 	TODO: check
 CVE-2026-74017 (Unauthenticated Broken Access Control in User Registration <= 5.2.7 ve ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-74005 (Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Seri ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-74002 (Unauthenticated Broken Access Control in Booking Calendar <= 11.7 vers ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-74000 (Contributor Broken Access Control in Simple Membership <= 4.8.2 versio ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73999 (Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-71568 (In BMCtest, Ironic is started without authentication and TLS for the d ...)
 	TODO: check
 CVE-2026-71538 (@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials  ...)
 	TODO: check
 CVE-2026-69197 (Umbraco is an ASP.NET CMS. Prior to 13.15.1, 17.5.3, and 18.0.2, the C ...)
-	TODO: check
+	NOT-FOR-US: Umbraco CMS
 CVE-2026-66676 (Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 version ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66631 (Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66630 (Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66628 (Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versio ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66626 (Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66625 (Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66624 (Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66619 (Administrator SQL Injection in Newsletters <= 4.18 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66618 (Administrator SQL Injection in WP Maps <= 4.9.9 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66617 (Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66608 (Contributor Server Side Request Forgery (SSRF) in Unlimited Elements F ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66580 (Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66579 (Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66578 (Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versio ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66577 (Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66576 (Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66575 (Unauthenticated Insecure Direct Object References (IDOR) in King Addon ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66574 (Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addon ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66573 (Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66572 (Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66571 (Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Pa ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66269 (Dell OpenManage Server Administrator, versions prior to 11.1.0.3, cont ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-63472 (Vendure is an open-source headless commerce platform. Prior to 3.7.0,  ...)
 	TODO: check
 CVE-2026-63461 (Vendure is an open-source headless commerce platform. Prior to 3.6.5,  ...)
@@ -407,17 +407,17 @@ CVE-2026-63460 (Vendure is an open-source headless commerce platform. Prior to 3
 CVE-2026-63459 (Vendure is an open-source headless commerce platform. Prior to 3.6.5,  ...)
 	TODO: check
 CVE-2026-62108 (Unauthenticated Broken Authentication in Headless Single Sign On <= 1. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62104 (Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62101 (Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 ver ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61793 (Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0 ...)
 	TODO: check
 CVE-2026-61700 (MariaDB Connector/J is used to connect applications developed in Java  ...)
 	TODO: check
 CVE-2026-56795 (Dell Server Update Utility, versions prior to 26.07.01, contains an Un ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-55062 (uniget is a universal installer and updater for (container) tools. Pri ...)
 	TODO: check
 CVE-2026-55061 (uniget is a universal installer and updater for (container) tools. Pri ...)
@@ -465,7 +465,7 @@ CVE-2026-54524 (Frappe HR is an open-source human resources management solution
 CVE-2026-54504 (MCP Documentation Server is a local-first document management and sema ...)
 	TODO: check
 CVE-2026-54471 (Dell SmartFabric Manager, versions prior to 2.2.1, contains an Imprope ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-54451 (Elixir protobuf is a pure Elixir implementation of Google Protobuf. Fr ...)
 	TODO: check
 CVE-2026-54446 (NetLicensing MCP Server is a natural-language interface that enables a ...)
@@ -489,29 +489,29 @@ CVE-2026-52836 (OpenDDS is an open source C++ implementation of the Object Manag
 CVE-2026-52727 (lxc-ci contains continuous integration and image-build scripts for LXC ...)
 	TODO: check
 CVE-2026-50610 (A vulnerability has been identified in the Acer System Monitoring comp ...)
-	TODO: check
+	NOT-FOR-US: Acer
 CVE-2026-50609 (A vulnerability has been identified in the Acer System Monitoring comp ...)
-	TODO: check
+	NOT-FOR-US: Acer
 CVE-2026-50608 (A vulnerability has been identified in the Acer System Monitoring comp ...)
-	TODO: check
+	NOT-FOR-US: Acer
 CVE-2026-50607 (A vulnerability has been identified in the Acer System Monitoring comp ...)
-	TODO: check
+	NOT-FOR-US: Acer
 CVE-2026-50606 (A vulnerability has been identified in the Acer System Monitoring comp ...)
-	TODO: check
+	NOT-FOR-US: Acer
 CVE-2026-50605 (A vulnerability has been identified in the Acer Agent Service componen ...)
-	TODO: check
+	NOT-FOR-US: Acer
 CVE-2026-49292 (Kiwi TCMS is an open source test management system. Prior to 16.0, the ...)
 	TODO: check
 CVE-2026-47252 (Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5 ...)
 	TODO: check
 CVE-2026-28326 (SolarWinds Access Rights Manager was reported to be affected by an una ...)
-	TODO: check
+	NOT-FOR-US: SolarWinds
 CVE-2026-26950 (Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insuffi ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-19477 (There is stack-based buffer overflow vulnerability recently discovered ...)
-	TODO: check
+	NOT-FOR-US: National Instruments
 CVE-2026-15688 (Incorrect Implementation of Authentication Algorithm Vulnerability in  ...)
-	TODO: check
+	NOT-FOR-US: Mitsubishi
 CVE-2026-14850 (The password reset funcionality is vulnerable to unauthorized account  ...)
 	TODO: check
 CVE-2026-12284 (Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IP ...)


=====================================
data/packages/nfu.yaml
=====================================
@@ -585,7 +585,7 @@
   allOf:
     - cna: hp
     - anyOf:
-        product: HP AC Print & Scan
+        - product: HP AC Print & Scan
 - reason: Intel
   allOf:
     - cna: intel



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/0c9550c66c3cef5936fcaf7c937caf84e0f6fde4...7fdda328e770a59877124f50e2a5253e47045f11

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/0c9550c66c3cef5936fcaf7c937caf84e0f6fde4...7fdda328e770a59877124f50e2a5253e47045f11
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/fea38dcd/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list