[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Sep 18 16:59:03 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
988aa341 by Moritz Muehlenhoff at 2026-09-18T17:58:37+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,11 @@
+CVE-2026-92828
+	NOT-FOR-US: OpenShift
+CVE-2026-92218
+	NOT-FOR-US: release-service-utils
+CVE-2026-87743
+	NOT-FOR-US: quarkus-vertx-http
+CVE-2026-77874
+	NOT-FOR-US: Hibernate ORM
 CVE-2026-93019 [TGA: don't interpret large color map sizes as negative]
 	- libimager-perl 1.036+dfsg-1
 	NOTE: https://github.com/tonycoz/imager/security/advisories/GHSA-p4vw-rc54-p2c2
@@ -175,7 +183,7 @@ CVE-2026-86800 (The Hide My WP Ghost WordPress plugin before 7.0.11 does not pro
 CVE-2026-86796 (The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify th ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-86688 (Session Fixation vulnerability in team-alembic ash_authentication allo ...)
-	TODO: check
+	NOT-FOR-US: team-alembic ash_authentication
 CVE-2026-86049 (Jupyter Server is the backend for Jupyter web applications. Prior to v ...)
 	TODO: check
 CVE-2026-85917 (Server-side request forgery (ssrf) in Azure AI Foundry allows an unaut ...)
@@ -213,17 +221,17 @@ CVE-2026-83946 (Improper neutralization of input during web page generation ('cr
 CVE-2026-83944 (Improper access control in Azure Logic Apps allows an unauthorized att ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-82985 (The Photos app's filter-based "smart albums" build their file listing  ...)
-	TODO: check
+	- nextcloud-server <itp> (bug #941708)
 CVE-2026-82982 (The Approval app's approve/reject endpoint is meant to require the fil ...)
-	TODO: check
+	NOT-FOR-US: Nextcloud Approval
 CVE-2026-82980 (Any authenticated user can lock or unlock files they do not own by tar ...)
-	TODO: check
+	NOT-FOR-US: Nextcloud Files Lock
 CVE-2026-81810 (The All-in-One WP Migration and Backup WordPress plugin before 7.111 d ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-81340 (The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.50 d ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-79954 (NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerabilit ...)
-	TODO: check
+	NOT-FOR-US: NASA CryptoLib
 CVE-2026-79713 (The Breeze Cache WordPress plugin before 2.5.15 does not include a set ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-78668
@@ -233,17 +241,17 @@ CVE-2026-78501 (Improper neutralization of special elements used in a command ('
 CVE-2026-77903 (Authentication bypass by spoofing in Microsoft Dataverse allows an una ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-77615 (Paella Player is a set of libraries to create a multi stream video pla ...)
-	TODO: check
+	NOT-FOR-US: Paella Player
 CVE-2026-77281 (Caddy is an extensible server platform that uses TLS by default. In ve ...)
 	TODO: check
 CVE-2026-77170 (The Deck config API allows authenticated users to set board-scoped con ...)
-	TODO: check
+	NOT-FOR-US: Nextcloud Deck
 CVE-2026-77169 (A vulnerability in the team folders (formerly group folders) app when  ...)
-	TODO: check
+	NOT-FOR-US: Nextcloud Team Folders
 CVE-2026-77164 (Circles' remote-instance signature verification fetches the attacker-s ...)
-	TODO: check
+	- nextcloud-server <itp> (bug #941708)
 CVE-2026-76949 (Authentication Bypass by Spoofing vulnerability in team-alembic ash_au ...)
-	TODO: check
+	NOT-FOR-US: team-alembic ash_authentication
 CVE-2026-76154 (A stored cross-site scripting vulnerability in the Geomap panel's MapL ...)
 	NOT-FOR-US: Grafana
 CVE-2026-75017 (The Magazine Blocks \u2013 Blog Designer, Magazine & Newspaper Website ...)
@@ -263,11 +271,11 @@ CVE-2026-69399 (Azure Arc Elevation of Privilege Vulnerability)
 CVE-2026-68791 (Incorrect authorization in Azure Machine Learning allows an unauthoriz ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-68537 (`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server th ...)
-	TODO: check
+	NOT-FOR-US: fulgur
 CVE-2026-68523 (`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server th ...)
-	TODO: check
+	NOT-FOR-US: fulgur
 CVE-2026-68493 (After guessing a 62^15 complex unique identifier, a malicious logged i ...)
-	TODO: check
+	- nextcloud-server <itp> (bug #941708)
 CVE-2026-67071 (HCL DevOps Deploy / HCL Launch is susceptible to an information disclo ...)
 	NOT-FOR-US: HCL
 CVE-2026-65323



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/988aa3411fa46a2839a34c7000b696996899059c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/988aa3411fa46a2839a34c7000b696996899059c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/7c8d3d05/attachment.htm>


More information about the debian-security-tracker-commits mailing list