[Git][security-tracker-team/security-tracker][master] Process more NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 18 09:48:10 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
51af73fe by Salvatore Bonaccorso at 2026-09-18T10:47:35+02:00
Process more NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -75,7 +75,7 @@ CVE-2026-93373 (Use after free in Extensions in Google Chrome prior to 153.0.801
 CVE-2026-93372 (Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0 ...)
 	- chromium <unfixed>
 CVE-2026-93371 (A security vulnerability has been detected in marcopiovanello yt-dlp-w ...)
-	TODO: check
+	NOT-FOR-US: yt-dlp-web-ui
 CVE-2026-93331 (A vulnerability was identified in GPAC 26.08-DEV. This vulnerability a ...)
 	TODO: check
 CVE-2026-93314 (A vulnerability was determined in Freedesktop Poppler 26.07.0. This af ...)
@@ -87,13 +87,13 @@ CVE-2026-93312 (A flaw has been found in Freedesktop Poppler 26.07.0. Impacted i
 CVE-2026-93311 (A vulnerability was detected in Freedesktop Poppler 26.07.0. This issu ...)
 	TODO: check
 CVE-2026-93310 (A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This af ...)
-	TODO: check
+	NOT-FOR-US: O-RAN-SC SMO OAM
 CVE-2026-93309 (A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affecte ...)
-	TODO: check
+	NOT-FOR-US: O-RAN-SC SMO OAM
 CVE-2026-93308 (A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by  ...)
-	TODO: check
+	NOT-FOR-US: O-RAN-SC SMO OAM
 CVE-2026-93307 (A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affecte ...)
-	TODO: check
+	NOT-FOR-US: O-RAN-SC SMO OAM
 CVE-2026-92991 (The Biggop Library is vulnerable to Cross-Site Scripting via the \u201 ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-92757 (Applications built on MongoDB Entity Framework Core Provider which pla ...)
@@ -468,29 +468,29 @@ CVE-2026-93296 (MISP contains a stored cross-site scripting (XSS) vulnerability
 CVE-2026-93295 (MISP contains a vulnerability in its background job dispatch mechanism ...)
 	- misp <itp> (bug #1144317)
 CVE-2026-93292 (SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vul ...)
-	TODO: check
+	NOT-FOR-US: SigNoz
 CVE-2026-93015 (BlueKitchen BTstack through 1.8.2 fails to validate the peer-reported  ...)
-	TODO: check
+	NOT-FOR-US: BlueKitchen BTstack
 CVE-2026-93014 (RosarioSIS versions before 12.9 fail to validate the filename request  ...)
-	TODO: check
+	NOT-FOR-US: RosarioSIS
 CVE-2026-93013 (RAGFlow through 0.27.2 contains a path traversal vulnerability in the  ...)
-	TODO: check
+	NOT-FOR-US: RAGFlow
 CVE-2026-92993 (A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The im ...)
-	TODO: check
+	NOT-FOR-US: Dromara mayfly-go
 CVE-2026-92992 (A security vulnerability has been detected in Dromara mayfly-go up to  ...)
-	TODO: check
+	NOT-FOR-US: Dromara mayfly-go
 CVE-2026-92987 (roxmltree through 0.21.1 performs quadratic-time attribute and namespa ...)
-	TODO: check
+	NOT-FOR-US: roxmltree
 CVE-2026-92986 (SiYuan before 3.8.4 renders document titles as HTML in the backlink do ...)
 	NOT-FOR-US: SiYuan
 CVE-2026-92985 (SiYuan versions before 3.8.4 fail to escape bookmark labels imported f ...)
 	NOT-FOR-US: SiYuan
 CVE-2026-92984 (HUBzero CMS through 2.2.32 accepts session identifiers from query stri ...)
-	TODO: check
+	NOT-FOR-US: HUBzero CMS
 CVE-2026-92983 (InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggreg ...)
-	TODO: check
+	NOT-FOR-US: InternLM LMDeploy
 CVE-2026-92980 (HortusFox-Web prior to version 6.1 contains a remote code execution vu ...)
-	TODO: check
+	NOT-FOR-US: HortusFox-Web
 CVE-2026-92973 (ansi2html versions 1.7.0a0 through 1.9.3 contain a cross-site scriptin ...)
 	TODO: check
 CVE-2026-92972 (SGLang through 0.5.19 in prefill/decode disaggregation mode contains a ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/51af73fe182a0959233205176a65718b0441fa4f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/51af73fe182a0959233205176a65718b0441fa4f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/3cef01db/attachment.htm>


More information about the debian-security-tracker-commits mailing list