[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Fri Sep 18 16:59:03 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
988aa341 by Moritz Muehlenhoff at 2026-09-18T17:58:37+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,11 @@
+CVE-2026-92828
+ NOT-FOR-US: OpenShift
+CVE-2026-92218
+ NOT-FOR-US: release-service-utils
+CVE-2026-87743
+ NOT-FOR-US: quarkus-vertx-http
+CVE-2026-77874
+ NOT-FOR-US: Hibernate ORM
CVE-2026-93019 [TGA: don't interpret large color map sizes as negative]
- libimager-perl 1.036+dfsg-1
NOTE: https://github.com/tonycoz/imager/security/advisories/GHSA-p4vw-rc54-p2c2
@@ -175,7 +183,7 @@ CVE-2026-86800 (The Hide My WP Ghost WordPress plugin before 7.0.11 does not pro
CVE-2026-86796 (The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify th ...)
NOT-FOR-US: WordPress plugin
CVE-2026-86688 (Session Fixation vulnerability in team-alembic ash_authentication allo ...)
- TODO: check
+ NOT-FOR-US: team-alembic ash_authentication
CVE-2026-86049 (Jupyter Server is the backend for Jupyter web applications. Prior to v ...)
TODO: check
CVE-2026-85917 (Server-side request forgery (ssrf) in Azure AI Foundry allows an unaut ...)
@@ -213,17 +221,17 @@ CVE-2026-83946 (Improper neutralization of input during web page generation ('cr
CVE-2026-83944 (Improper access control in Azure Logic Apps allows an unauthorized att ...)
NOT-FOR-US: Microsoft
CVE-2026-82985 (The Photos app's filter-based "smart albums" build their file listing ...)
- TODO: check
+ - nextcloud-server <itp> (bug #941708)
CVE-2026-82982 (The Approval app's approve/reject endpoint is meant to require the fil ...)
- TODO: check
+ NOT-FOR-US: Nextcloud Approval
CVE-2026-82980 (Any authenticated user can lock or unlock files they do not own by tar ...)
- TODO: check
+ NOT-FOR-US: Nextcloud Files Lock
CVE-2026-81810 (The All-in-One WP Migration and Backup WordPress plugin before 7.111 d ...)
NOT-FOR-US: WordPress plugin
CVE-2026-81340 (The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 d ...)
NOT-FOR-US: WordPress plugin
CVE-2026-79954 (NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: NASA CryptoLib
CVE-2026-79713 (The Breeze Cache WordPress plugin before 2.5.15 does not include a set ...)
NOT-FOR-US: WordPress plugin
CVE-2026-78668
@@ -233,17 +241,17 @@ CVE-2026-78501 (Improper neutralization of special elements used in a command ('
CVE-2026-77903 (Authentication bypass by spoofing in Microsoft Dataverse allows an una ...)
NOT-FOR-US: Microsoft
CVE-2026-77615 (Paella Player is a set of libraries to create a multi stream video pla ...)
- TODO: check
+ NOT-FOR-US: Paella Player
CVE-2026-77281 (Caddy is an extensible server platform that uses TLS by default. In ve ...)
TODO: check
CVE-2026-77170 (The Deck config API allows authenticated users to set board-scoped con ...)
- TODO: check
+ NOT-FOR-US: Nextcloud Deck
CVE-2026-77169 (A vulnerability in the team folders (formerly group folders) app when ...)
- TODO: check
+ NOT-FOR-US: Nextcloud Team Folders
CVE-2026-77164 (Circles' remote-instance signature verification fetches the attacker-s ...)
- TODO: check
+ - nextcloud-server <itp> (bug #941708)
CVE-2026-76949 (Authentication Bypass by Spoofing vulnerability in team-alembic ash_au ...)
- TODO: check
+ NOT-FOR-US: team-alembic ash_authentication
CVE-2026-76154 (A stored cross-site scripting vulnerability in the Geomap panel's MapL ...)
NOT-FOR-US: Grafana
CVE-2026-75017 (The Magazine Blocks \u2013 Blog Designer, Magazine & Newspaper Website ...)
@@ -263,11 +271,11 @@ CVE-2026-69399 (Azure Arc Elevation of Privilege Vulnerability)
CVE-2026-68791 (Incorrect authorization in Azure Machine Learning allows an unauthoriz ...)
NOT-FOR-US: Microsoft
CVE-2026-68537 (`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server th ...)
- TODO: check
+ NOT-FOR-US: fulgur
CVE-2026-68523 (`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server th ...)
- TODO: check
+ NOT-FOR-US: fulgur
CVE-2026-68493 (After guessing a 62^15 complex unique identifier, a malicious logged i ...)
- TODO: check
+ - nextcloud-server <itp> (bug #941708)
CVE-2026-67071 (HCL DevOps Deploy / HCL Launch is susceptible to an information disclo ...)
NOT-FOR-US: HCL
CVE-2026-65323
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/988aa3411fa46a2839a34c7000b696996899059c
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/988aa3411fa46a2839a34c7000b696996899059c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/7c8d3d05/attachment.htm>
More information about the debian-security-tracker-commits
mailing list