[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 18 08:28:35 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
42ccbf55 by Salvatore Bonaccorso at 2026-09-18T09:28:12+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2,23 +2,23 @@ CVE-2026-93485 (Improper neutralization of input during web page generation ('cr
 	- wordpress <unfixed>
 	NOTE: https://wordpress.org/news/2026/09/wordpress-7-1-1-maintenance-and-security-release/
 CVE-2026-93468 (The OAKlouds developed by HGiga has an Arbitrary File Read vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: HGiga
 CVE-2026-93467 (The OAKlouds developed by HGiga has a Insecure Deserialization vulnera ...)
-	TODO: check
+	NOT-FOR-US: HGiga
 CVE-2026-93456 (django-page-cms through 2.0.13 exempts five admin mutation views from  ...)
-	TODO: check
+	NOT-FOR-US: django-page-cms
 CVE-2026-93455 (django-page-cms through 2.0.13 fails to properly validate page permiss ...)
-	TODO: check
+	NOT-FOR-US: django-page-cms
 CVE-2026-93454 (Aureus ERP through 1.6.0 stores the Payment Term note field unsanitize ...)
-	TODO: check
+	NOT-FOR-US: Aureus ERP
 CVE-2026-93453 (SOGo before 5.12.11 constructs password-reset links using the client-s ...)
 	TODO: check
 CVE-2026-93452 (snappy-java through 1.1.10.8 contains a buffer overflow vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: snappy-java
 CVE-2026-93451 (snappy-java through 1.1.10.8 contains a buffer overflow vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: snappy-java
 CVE-2026-93450 (go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vuln ...)
-	TODO: check
+	NOT-FOR-US: go-openapi/swag jsonutils
 CVE-2026-93436 (vLLM through 0.29.0 fails to properly clean up decode-side metadata fo ...)
 	TODO: check
 CVE-2026-93435 (redis-parser through 3.0.0 contains a denial of service vulnerability  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/42ccbf55de0f69b34c2487350af9d323c1151888

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/42ccbf55de0f69b34c2487350af9d323c1151888
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/ea566f4c/attachment.htm>


More information about the debian-security-tracker-commits mailing list