[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Sep 18 16:42:09 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0ffac605 by Moritz Muehlenhoff at 2026-09-18T17:41:23+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -281,17 +281,17 @@ CVE-2026-57846
 CVE-2026-55946 (Improper neutralization of special elements used in a command ('comman ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-54918 (NetBox Device Type Library is a collection of community-sourced device ...)
-	TODO: check
+	NOT-FOR-US: NetBox Device Type LibraryCubeCart
 CVE-2026-54916 (NetBox Device Type Library is a collection of community-sourced device ...)
-	TODO: check
+	NOT-FOR-US: NetBox Device Type LibraryCubeCart
 CVE-2026-54907 (Caddy Proxy Manager is a web interface for managing Caddy Server rever ...)
 	TODO: check
 CVE-2026-54767 (WeGIA is a web manager for charitable institutions. Prior to 3.8.5, we ...)
 	NOT-FOR-US: WeGIA
 CVE-2026-54752 (NetBox Device Type Library is a collection of community-sourced device ...)
-	TODO: check
+	NOT-FOR-US: NetBox Device Type LibraryCubeCart
 CVE-2026-54734 (Prebid Server Java is the Java version of Prebid Server. Prior to 3.43 ...)
-	TODO: check
+	NOT-FOR-US: Prebid Server Java
 CVE-2026-54716 (Valhalla is an open source routing engine and accompanying libraries f ...)
 	TODO: check
 CVE-2026-54692 (SAIL is a cross-platform library for loading and saving images with su ...)
@@ -301,19 +301,19 @@ CVE-2026-54671 (WeGIA is a web manager for charitable institutions. Prior to 3.8
 CVE-2026-54670 (WeGIA is a web manager for charitable institutions. Prior to 3.8.5, th ...)
 	NOT-FOR-US: WeGIA
 CVE-2026-54648 (CubeCart is an ecommerce software solution. Prior to 6.7.5, the GDPR t ...)
-	TODO: check
+	NOT-FOR-US: CubeCart
 CVE-2026-54647 (CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sour ...)
-	TODO: check
+	NOT-FOR-US: CubeCart
 CVE-2026-54646 (CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sour ...)
-	TODO: check
+	NOT-FOR-US: CubeCart
 CVE-2026-54645 (CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sour ...)
-	TODO: check
+	NOT-FOR-US: CubeCart
 CVE-2026-54644 (CubeCart is an ecommerce software solution. Prior to 6.7.5, the _error ...)
-	TODO: check
+	NOT-FOR-US: CubeCart
 CVE-2026-54643 (CubeCart is an ecommerce software solution. Prior to 6.7.5, the delete ...)
-	TODO: check
+	NOT-FOR-US: CubeCart
 CVE-2026-54642 (CubeCart is an ecommerce software solution. Prior to 6.7.5, the reset_ ...)
-	TODO: check
+	NOT-FOR-US: CubeCart
 CVE-2026-54634 (Hamlib is a ham radio control library for radios, rotators, and amplif ...)
 	TODO: check
 CVE-2026-54633 (PoDoFo is a C++17 PDF manipulation library. From version 1.0.0 until 1 ...)
@@ -367,13 +367,13 @@ CVE-2026-54339 (Glean is a self-hosted RSS reader and personal knowledge managem
 CVE-2026-54237 (Wavelog is web-based amateur radio logging software. From 1.8 until 2. ...)
 	TODO: check
 CVE-2026-53557 (SQLBot is an intelligent Text-to-SQL system based on large language mo ...)
-	TODO: check
+	NOT-FOR-US: SQLBot
 CVE-2026-53556 (SQLBot is an intelligent Text-to-SQL system based on large language mo ...)
-	TODO: check
+	NOT-FOR-US: SQLBot
 CVE-2026-53555 (SQLBot is an intelligent Text-to-SQL system based on large language mo ...)
-	TODO: check
+	NOT-FOR-US: SQLBot
 CVE-2026-53554 (SQLBot is an intelligent Text-to-SQL system based on large language mo ...)
-	TODO: check
+	NOT-FOR-US: SQLBot
 CVE-2026-53534 (JabRef is a desktop application for managing BibTeX and BibLaTeX libra ...)
 	TODO: check
 CVE-2026-52483 (The ping diagnostics and other similar functions of the MitraStar GPT- ...)
@@ -385,7 +385,7 @@ CVE-2026-50285 (Pomerium is an identity and context-aware access proxy. Prior to
 CVE-2026-50277 (dd-trace-cpp is the Datadog distributed tracing library for C++. Prior ...)
 	TODO: check
 CVE-2026-50275 (The Datadog PHP Tracer provides application performance monitoring and ...)
-	TODO: check
+	NOT-FOR-US: Datadog PHP Tracer
 CVE-2026-50158 (yutu is an AI-powered toolkit for managing and growing YouTube channel ...)
 	TODO: check
 CVE-2026-50125 (MKP is a Model Context Protocol server for Kubernetes. Prior to 0.4.1, ...)
@@ -395,11 +395,11 @@ CVE-2026-50022 (Metacat is data repository software that helps researchers prese
 CVE-2026-49137
 	REJECTED
 CVE-2026-45726 (Omni manages Kubernetes on bare metal, virtual machines, or in a cloud ...)
-	TODO: check
+	NOT-FOR-US: Omni
 CVE-2026-45723 (Omni manages Kubernetes on bare metal, virtual machines, or in a cloud ...)
-	TODO: check
+	NOT-FOR-US: Omni
 CVE-2026-45720 (Omni manages Kubernetes on bare metal, virtual machines, or in a cloud ...)
-	TODO: check
+	NOT-FOR-US: Omni
 CVE-2026-45143 (Chamilo LMS is an open-source learning management system. From 2.0.0 t ...)
 	NOT-FOR-US: Chamilo LMS
 CVE-2026-45140 (Chamilo LMS is an open-source learning management system. Prior to 2.0 ...)
@@ -610,7 +610,7 @@ CVE-2026-92913 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 u
 CVE-2026-92912 (AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptogra ...)
 	NOT-FOR-US: WWBN AVideo
 CVE-2026-92904 (A flaw was found in the foreman_remote_execution plugin's template inv ...)
-	TODO: check
+	NOT-FOR-US: foreman_remote_execution
 CVE-2026-92903 (Improper input validation in Snowflake CLI versions prior to 3.27.0 al ...)
 	NOT-FOR-US: nowflake CLI
 CVE-2026-92894 (A flaw was found in the foreman_ansible plugin's Ansible override valu ...)
@@ -658,7 +658,7 @@ CVE-2026-87831 (The Checkout Field Manager (Checkout Manager) for WooCommerce Wo
 CVE-2026-87829 (The Checkout Field Manager (Checkout Manager) for WooCommerce WordPres ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-87742 (A flaw was found in quarkus-websockets-next. This vulnerability allows ...)
-	TODO: check
+	NOT-FOR-US: quarkus-websockets-next
 CVE-2026-86864 (pgAdmin 4's Backup tool appended the client-supplied 'database' field  ...)
 	- pgadmin4 <itp> (bug #834129)
 CVE-2026-86863 (pgAdmin 4's Webserver authentication source is intended to accept an i ...)
@@ -3412,7 +3412,7 @@ CVE-2026-86071 (Junrar is an open source Java RAR archive library. Prior to vers
 CVE-2026-85789
 	REJECTED
 CVE-2026-85469 (A flaw was found in quay-builder-qemu. A remote attacker could exploit ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Quay
 CVE-2026-85130 (The WPLP Cookie Consent  WordPress plugin before 4.4.4 does not escape ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-85128 (The Choose User Role at Registration WordPress plugin before 1.3.3 doe ...)
@@ -3434,7 +3434,7 @@ CVE-2026-81546 (The Affinity by Canva application before 3.3.0 (September 2026 r
 CVE-2026-76646 (A remote attacker could cause excessive resource consumption by supply ...)
 	TODO: check
 CVE-2026-76460 (A vulnerability in an API of Cisco Identity Services Engine (ISE) coul ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76451 (A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE  ...)
 	NOT-FOR-US: Cisco
 CVE-2026-76450 (A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE  ...)
@@ -3560,39 +3560,39 @@ CVE-2026-20360 (As part of Cisco's ongoing commitment to proactive security and
 CVE-2026-20352 (A vulnerability in the RADIUS feature of Cisco Identity Services Engin ...)
 	NOT-FOR-US: Cisco
 CVE-2026-20350 (A vulnerability in the web-based management interface of Cisco Thousan ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20344 (A vulnerability in the web-based management interface of Cisco Secure  ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20343 (A vulnerability in a critical API for Cisco Secure FMC Software could  ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20342 (A vulnerability in a specific file download API of Cisco Secure FMC So ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20341 (A vulnerability in the sftunnel inter-device communication protocol of ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20340 (A vulnerability in Cisco Secure FMC Software could allow an authentica ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20336 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20335 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20334 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20333 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20332 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20330 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20329 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20326 (As part of Cisco's ongoing commitment to proactive security and produc ...)
 	NOT-FOR-US: Cisco
 CVE-2026-20325 (As part of Cisco's ongoing commitment to proactive security and produc ...)
 	NOT-FOR-US: Cisco
 CVE-2026-20324 (A vulnerability in the sftunnel inter-device communication protocol of ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20323 (A vulnerability in the sftunnel inter-device communication protocol of ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20322 (As part of Cisco's ongoing commitment to proactive security and produc ...)
 	NOT-FOR-US: Cisco
 CVE-2026-20309 (A vulnerability in the web-based management interface of Cisco Identit ...)
@@ -3600,15 +3600,15 @@ CVE-2026-20309 (A vulnerability in the web-based management interface of Cisco I
 CVE-2026-20300 (A vulnerability in Cisco ISE could allow an authenticated, remote atta ...)
 	NOT-FOR-US: Cisco
 CVE-2026-20295 (A vulnerability in the sftunnel inter-device communication protocol of ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20290 (A vulnerability in SSL/TLS certificate parsing in the Snort 2 Detectio ...)
 	NOT-FOR-US: Cisco
 CVE-2026-20287 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20286 (A vulnerability in the web-based management interface of Cisco Identif ...)
 	NOT-FOR-US: Cisco
 CVE-2026-20285 (A vulnerability in the web-based management interface of Cisco Identit ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20284 (A vulnerability in the SXP REST API of Cisco ISE could allow an authen ...)
 	NOT-FOR-US: Cisco
 CVE-2026-20283 (A vulnerability in the IPsec Open API endpoint of Cisco ISE could allo ...)
@@ -3616,27 +3616,27 @@ CVE-2026-20283 (A vulnerability in the IPsec Open API endpoint of Cisco ISE coul
 CVE-2026-20282 (A vulnerability in Cisco ISE could allow an authenticated, remote atta ...)
 	NOT-FOR-US: Cisco
 CVE-2026-20250 (A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secur ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20249 (A vulnerability in the certification authentication feature of Interne ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20248 (A vulnerability in the DNS over TCP implementation of Cisco Secure Fir ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20247 (A vulnerability in Cisco ISE could allow an unauthenticated, remote at ...)
 	NOT-FOR-US: Cisco
 CVE-2026-20242 (A vulnerability in the External Database Access feature of Cisco Secur ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20237 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20235 (A vulnerability in the API of Cisco Identity Services Engine (ISE) cou ...)
 	NOT-FOR-US: Cisco
 CVE-2026-20222 (A vulnerability in the EIGRP implementation in Cisco Secure Firewall A ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20211 (A vulnerability in Cisco ISE could allow an authenticated, remote atta ...)
 	NOT-FOR-US: Cisco
 CVE-2026-20194 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20192 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20176 (A vulnerability in Cisco ISE could allow an authenticated, remote atta ...)
 	NOT-FOR-US: Cisco
 CVE-2026-20154 (A vulnerability in the system rate-limiting process for syslog message ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0ffac6059b113dad358f8ed481f8811333fe4ef7

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0ffac6059b113dad358f8ed481f8811333fe4ef7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/ece80842/attachment.htm>


More information about the debian-security-tracker-commits mailing list