[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Sep 18 15:47:27 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5ea37059 by Moritz Muehlenhoff at 2026-09-18T16:46:41+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -888,43 +888,43 @@ CVE-2026-54649 (punchin-email is a Cloudflare Email Worker that provides two-way
 CVE-2026-54617 (GravitLauncher is an open-source Minecraft launcher based on sashok724 ...)
 	TODO: check
 CVE-2026-54587 (mport is the MidnightBSD Package Manager. Prior to 2.7.8, directory as ...)
-	TODO: check
+	NOT-FOR-US: mport
 CVE-2026-54586 (mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fe ...)
-	TODO: check
+	NOT-FOR-US: mport
 CVE-2026-54585 (mport is the MidnightBSD Package Manager. Prior to 2.7.8, create_sampl ...)
-	TODO: check
+	NOT-FOR-US: mport
 CVE-2026-54583 (mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/fet ...)
-	TODO: check
+	NOT-FOR-US: mport
 CVE-2026-54582 (mport is the MidnightBSD Package Manager. Prior to 2.7.8, package inst ...)
-	TODO: check
+	NOT-FOR-US: mport
 CVE-2026-54581 (mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fe ...)
-	TODO: check
+	NOT-FOR-US: mport
 CVE-2026-54580 (mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/uti ...)
-	TODO: check
+	NOT-FOR-US: mport
 CVE-2026-54579 (mport is the MidnightBSD Package Manager. Prior to 2.7.8, ping() in li ...)
-	TODO: check
+	NOT-FOR-US: mport
 CVE-2026-54578 (mport is the MidnightBSD Package Manager. Prior to 2.7.8, mport_verify ...)
-	TODO: check
+	NOT-FOR-US: mport
 CVE-2026-54577 (mport is the MidnightBSD Package Manager. Prior to 2.7.8, the audit co ...)
-	TODO: check
+	NOT-FOR-US: mport
 CVE-2026-54576 (mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_actual_in ...)
-	TODO: check
+	NOT-FOR-US: mport
 CVE-2026-54575 (mport is the MidnightBSD Package Manager. Prior to 2.7.8, privileged p ...)
-	TODO: check
+	NOT-FOR-US: mport
 CVE-2026-54571 (ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library ...)
 	TODO: check
 CVE-2026-54551 (WireGuard Portal, or wg-portal, is a web-based configuration portal fo ...)
-	TODO: check
+	NOT-FOR-US: WireGuard Portal
 CVE-2026-54546 (CloudTAK is a browser-based Common Operating Picture and situational a ...)
 	TODO: check
 CVE-2026-54524 (Frappe HR is an open-source human resources management solution (HRMS) ...)
-	TODO: check
+	NOT-FOR-US: Frappe HR
 CVE-2026-54504 (MCP Documentation Server is a local-first document management and sema ...)
 	TODO: check
 CVE-2026-54471 (Dell SmartFabric Manager, versions prior to 2.2.1, contains an Imprope ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-54451 (Elixir protobuf is a pure Elixir implementation of Google Protobuf. Fr ...)
-	TODO: check
+	NOT-FOR-US: Elixir protobuf
 CVE-2026-54446 (NetLicensing MCP Server is a natural-language interface that enables a ...)
 	TODO: check
 CVE-2026-54253 (TS3 Manager is modern web interface for maintaining Teamspeak3 servers ...)
@@ -5784,15 +5784,15 @@ CVE-2026-66372 (The affected products use insufficiently random values, which al
 CVE-2026-63671 (MDC is a tool to take regular Markdown and write documents interacting ...)
 	TODO: check
 CVE-2026-63128 (RMCP is an official Rust SDK for the Model Context Protocol. Prior to  ...)
-	TODO: check
+	NOT-FOR-US: RCMP
 CVE-2026-63127 (RMCP is an official Rust SDK for the Model Context Protocol. Prior to  ...)
-	TODO: check
+	NOT-FOR-US: RCMP
 CVE-2026-63126 (Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, an ...)
 	TODO: check
 CVE-2026-62597 (Vulnerability in the Oracle Enterprise Manager Base Platform product o ...)
 	NOT-FOR-US: Oracle
 CVE-2026-61709 (OpenFGA is an authorization and permission engine built for developers ...)
-	TODO: check
+	NOT-FOR-US: OpenFGA
 CVE-2026-61598 (djust provides Phoenix LiveView-style reactive server-side rendering f ...)
 	NOT-FOR-US: djust
 CVE-2026-61595 (djust provides Phoenix LiveView-style reactive server-side rendering f ...)
@@ -5922,7 +5922,7 @@ CVE-2026-19640 (On affected platforms running Arista EOS, an authenticated user
 CVE-2026-19619 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-19607 (A flaw was found in the first-broker-login flow of the keycloak-servic ...)
-	TODO: check
+	- keycloak <itp> (bug #1088287)
 CVE-2026-19535 (Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery  ...)
 	NOT-FOR-US: Advantech
 CVE-2026-19248 (QDomDocument XML parsing is vulnerable to a remotely-triggerable denia ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5ea37059dd3c50305646fe8bccf8d9bdbc039e5c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5ea37059dd3c50305646fe8bccf8d9bdbc039e5c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/e0b1056e/attachment.htm>


More information about the debian-security-tracker-commits mailing list