[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Sep 18 15:12:30 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b093c516 by Moritz Muehlenhoff at 2026-09-18T16:11:17+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -646,7 +646,7 @@ CVE-2026-90823 (FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-lif
 CVE-2026-90822 (FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firm ...)
 	NOT-FOR-US: FatPipe MPVPN, WARP, and IPVPN appliances
 CVE-2026-89418 (google-protobuf contains an unbounded recursion when parsing unknown p ...)
-	TODO: check
+	NOT-FOR-US: Node protobuf-javascript
 CVE-2026-89038 (Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 cont ...)
 	NOT-FOR-US: Verizon Cloud for Android (com.vcast.mediamanager)
 CVE-2026-89036 (Appwrite before 2.0.0 contains an argument injection vulnerability tha ...)
@@ -698,9 +698,9 @@ CVE-2026-85715 (ExifReader is a JavaScript Exif information parser. Prior to 4.4
 CVE-2026-85500 (Authentication Bypass by Primary Weakness vulnerability in team-alembi ...)
 	TODO: check
 CVE-2026-85078 (Sanic is an opensource python web server/framework. In version 25.12.0 ...)
-	TODO: check
+	NOT-FOR-US: Sanic
 CVE-2026-85077 (Sanic is an opensource python web server/framework. Prior to version 2 ...)
-	TODO: check
+	NOT-FOR-US: Sanic
 CVE-2026-82761 (Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in tea ...)
 	TODO: check
 CVE-2026-82760 (Inefficient Algorithmic Complexity vulnerability in team-alembic AshAu ...)
@@ -714,7 +714,7 @@ CVE-2026-82685 (Authorization Bypass Through User-Controlled Key vulnerability i
 CVE-2026-81868 (Steeltoe is an open source project that provides a collection of libra ...)
 	TODO: check
 CVE-2026-81829 (A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by ...)
-	TODO: check
+	NOT-FOR-US: quarkus-smallrye-jwt
 CVE-2026-81637 (Insufficient Session Expiration vulnerability in team-alembic AshAuthe ...)
 	TODO: check
 CVE-2026-81632 (Use of HTTP Request With Sensitive Query String vulnerability in team- ...)
@@ -4378,7 +4378,7 @@ CVE-2026-86106 (An unauthenticated actor with network access to the private HA i
 CVE-2026-86043 (Skipper is an HTTP router and reverse proxy for service composition. P ...)
 	TODO: check
 CVE-2026-86003 (CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-H ...)
-	TODO: check
+	- coredns <itp> (bug #880676)
 CVE-2026-85893 (Use after free in Microsoft Edge (Chromium-based) allows an unauthoriz ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-85756 (SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2026.0.0, S ...)
@@ -5316,7 +5316,7 @@ CVE-2026-82567 (The myPRO Manager notification gateway exposes an unauthenticate
 CVE-2026-82410 (Pocketbase is an open source web backend written in go. Prior to 0.22. ...)
 	TODO: check
 CVE-2026-82399 (CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-H ...)
-	TODO: check
+	- coredns <itp> (bug #880676)
 CVE-2026-82311 (Apache Airflow FAB provider: resetting a user's password does not dele ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-82310 (Apache Airflow FAB provider: deactivating a user account does not stop ...)
@@ -5342,7 +5342,7 @@ CVE-2026-81855 (A hardcoded cryptographic client authentication key vulnerabilit
 CVE-2026-81326 (QND uses a hard-coded cryptographic key, which may allow a local attac ...)
 	TODO: check
 CVE-2026-81176 (Svelte devalue is a JavaScript library that serializes values into str ...)
-	TODO: check
+	NOT-FOR-US: Sveltejs devalue
 CVE-2026-7514 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-79994 (The guest-to-host Unix-domain socket relay in Docker Sandboxes validat ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b093c5166014405b00f9ca859b015abfe746bae9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b093c5166014405b00f9ca859b015abfe746bae9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/ebe23caf/attachment.htm>


More information about the debian-security-tracker-commits mailing list