[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Fri Sep 18 23:03:15 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
4aed2571 by Moritz Muehlenhoff at 2026-09-19T00:03:06+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -361,33 +361,33 @@ CVE-2026-77928 (ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection v
CVE-2026-77927 (ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnera ...)
TODO: check
CVE-2026-77616 (Semantic MediaWiki is a free, open-source extension to MediaWiki that ...)
- TODO: check
+ NOT-FOR-US: Semantic MediaWiki MediaWiki extension
CVE-2026-77610 (Semantic MediaWiki is a free, open-source extension to MediaWiki that ...)
- TODO: check
+ NOT-FOR-US: Semantic MediaWiki MediaWiki extension
CVE-2026-77609 (Semantic MediaWiki is a free, open-source extension to MediaWiki that ...)
- TODO: check
+ NOT-FOR-US: Semantic MediaWiki MediaWiki extension
CVE-2026-77608 (Semantic MediaWiki is a free, open-source extension to MediaWiki that ...)
- TODO: check
+ NOT-FOR-US: Semantic MediaWiki MediaWiki extension
CVE-2026-77607 (Semantic MediaWiki is a free, open-source extension to MediaWiki that ...)
- TODO: check
+ NOT-FOR-US: Semantic MediaWiki MediaWiki extension
CVE-2026-77606 (Semantic MediaWiki is a free, open-source extension to MediaWiki that ...)
- TODO: check
+ NOT-FOR-US: Semantic MediaWiki MediaWiki extension
CVE-2026-77568 (Mojolicious is a real-time web framework for Perl. Prior to 9.48, the ...)
TODO: check
CVE-2026-77396 (PJSIP is a free and open source multimedia communication library writt ...)
TODO: check
CVE-2026-77386 (Kyoo is a self-hosted media server focused on movies, series, and anim ...)
- TODO: check
+ NOT-FOR-US: check
CVE-2026-77385 (Kyoo is a self-hosted media server focused on movies, series, and anim ...)
- TODO: check
+ NOT-FOR-US: check
CVE-2026-77339 (Process Compose is a scheduler and orchestrator for non-containerized ...)
TODO: check
CVE-2026-77301 (adm-zip is a JavaScript library for creating and extracting ZIP archiv ...)
TODO: check
CVE-2026-77240 (WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 a ...)
- TODO: check
+ NOT-FOR-US: WACRM
CVE-2026-77239 (WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 a ...)
- TODO: check
+ NOT-FOR-US: WACRM
CVE-2026-75961 (The NEX-Forms \u2013 Ultimate Forms Plugin for WordPress plugin for Wo ...)
NOT-FOR-US: WordPress plugin
CVE-2026-75894 (In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found i ...)
@@ -431,9 +431,9 @@ CVE-2026-63638 (OpenImageIO is a toolset for reading, writing, and manipulating
CVE-2026-63635 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
TODO: check
CVE-2026-63458 (Perses is an open-source dashboard and visualization project for obser ...)
- TODO: check
+ NOT-FOR-US: Perses
CVE-2026-63445 (Perses is an open-source dashboard and visualization project for obser ...)
- TODO: check
+ NOT-FOR-US: Perses
CVE-2026-63422 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
TODO: check
CVE-2026-63420 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
@@ -447,15 +447,15 @@ CVE-2026-63405 (AnyCable is a realtime server for reliable two-way communication
CVE-2026-63349 (AnyIO is a high level asynchronous concurrency and networking framewor ...)
TODO: check
CVE-2026-63199 (Perses is an open-source dashboard and visualization project for obser ...)
- TODO: check
+ NOT-FOR-US: Perses
CVE-2026-62943 (btrbk is a tool for creating snapshots and remote backups of Btrfs sub ...)
TODO: check
CVE-2026-62282 (OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, Open ...)
TODO: check
CVE-2026-62279 (LubeLogger is a self-hosted, open-source, web-based vehicle maintenanc ...)
- TODO: check
+ NOT-FOR-US: LubeLogger
CVE-2026-62278 (LubeLogger is a self-hosted, open-source, web-based vehicle maintenanc ...)
- TODO: check
+ NOT-FOR-US: LubeLogger
CVE-2026-61833 (zot is a container image and artifact registry based on the Open Conta ...)
TODO: check
CVE-2026-61795 (Capsule is a multi-tenancy and policy-based framework for Kubernetes. ...)
@@ -479,7 +479,7 @@ CVE-2026-59163 (Mnemosyne is a memory layer for artificial intelligence agents.
CVE-2026-59156 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
TODO: check
CVE-2026-58197 (ToolHive is a utility designed to simplify the deployment and manageme ...)
- TODO: check
+ NOT-FOR-US: ToolHive
CVE-2026-56597 (HCL BigFix Service Management is affected by a Sensitive Information L ...)
NOT-FOR-US: HCL
CVE-2026-56595 (HCL BigFix Service Management is affected by a CORS Misconfiguration v ...)
@@ -489,9 +489,9 @@ CVE-2026-56592 (HCL BigFix Service Management is affected by an Improper Authent
CVE-2026-56590 (HCL BigFix Service Management is affected by an Unrestricted File Uplo ...)
NOT-FOR-US: HCL
CVE-2026-54148 (http4k is a functional toolkit for Kotlin HTTP applications. Prior to ...)
- TODO: check
+ NOT-FOR-US: http4k
CVE-2026-54147 (http4k is a functional toolkit for Kotlin HTTP applications. Prior to ...)
- TODO: check
+ NOT-FOR-US: http4k
CVE-2026-4036 (An improper neutralization of special elements used in an SQL command ...)
NOT-FOR-US: Synology
CVE-2026-44639 (NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's MQTT v5 property ...)
@@ -593,9 +593,9 @@ CVE-2026-12954 (The Mapster WP Maps plugin for WordPress is vulnerable to Arbitr
CVE-2026-12739 (The WP Easy Pay \u2013 Payment and Donation form Builder for Square pl ...)
NOT-FOR-US: WordPress plugin
CVE-2026-12384 (Authorization bypass through User-Controlled key vulnerability in TECH ...)
- TODO: check
+ NOT-FOR-US: TECHIN2B
CVE-2026-11757 (Improper neutralization of input during web page generation ('cross-si ...)
- TODO: check
+ NOT-FOR-US: KA Informatics Technologies
CVE-2026-11538 (IBM WebSphere Application Server 9.0 and 8.5 is affected by a log inje ...)
NOT-FOR-US: IBM
CVE-2026-11537 (IBM WebSphere Application Server 9.0, and 8.5 could allow a remote att ...)
@@ -627,9 +627,9 @@ CVE-2026-10030 (IBM MQ Console allows authenticated non-administrative users to
CVE-2026-10027 (IBM MQ could allow a remote attacker to cause a denial of service or e ...)
NOT-FOR-US: IBM
CVE-2025-66455 (LMDeploy is a toolkit for compressing, deploying, and serving large la ...)
- TODO: check
+ NOT-FOR-US: LMDeploy
CVE-2025-61682 (Semantic MediaWiki is a free, open-source extension to MediaWiki that ...)
- TODO: check
+ NOT-FOR-US: Semantic MediaWiki MediaWiki extension
CVE-2025-53837 (XWiki Rendering is a generic rendering system that converts textual in ...)
NOT-FOR-US: XWiki
CVE-2025-36421 (IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP ...)
@@ -663,11 +663,11 @@ CVE-2024-56344 (IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 throu
CVE-2023-5778 (Improper handling of length parameter inconsistency vulnerability in A ...)
NOT-FOR-US: ABB group
CVE-2023-54399 (Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the ...)
- TODO: check
+ NOT-FOR-US: Hongjing e-HR
CVE-2021-48008 (Chanjet CRM contains an unauthenticated SQL injection vulnerability th ...)
- TODO: check
+ NOT-FOR-US: Chanjet CRM
CVE-2019-25776 (Weaver E-cology contains an unauthenticated SQL injection vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: Weaver E-cology
CVE-2026-92828
NOT-FOR-US: OpenShift
CVE-2026-92218
@@ -968,7 +968,7 @@ CVE-2026-54918 (NetBox Device Type Library is a collection of community-sourced
CVE-2026-54916 (NetBox Device Type Library is a collection of community-sourced device ...)
NOT-FOR-US: NetBox Device Type LibraryCubeCart
CVE-2026-54907 (Caddy Proxy Manager is a web interface for managing Caddy Server rever ...)
- TODO: check
+ NOT-FOR-US: Caddy Proxy Manager
CVE-2026-54767 (WeGIA is a web manager for charitable institutions. Prior to 3.8.5, we ...)
NOT-FOR-US: WeGIA
CVE-2026-54752 (NetBox Device Type Library is a collection of community-sourced device ...)
@@ -1006,45 +1006,45 @@ CVE-2026-54627 (SAIL is a cross-platform library for loading and saving images w
CVE-2026-54626 (SAIL is a cross-platform library for loading and saving images with su ...)
TODO: check
CVE-2026-54618 (Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Pr ...)
- TODO: check
+ NOT-FOR-US: Obsidian Web MCP
CVE-2026-54613 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
- TODO: check
+ NOT-FOR-US: Vvveb
CVE-2026-54612 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
- TODO: check
+ NOT-FOR-US: Vvveb
CVE-2026-54608 (MythicalDash is a Pterodactyl client area. In 3.5.4-aurora and earlier ...)
- TODO: check
+ NOT-FOR-US: MythicalDash
CVE-2026-54597 (ITFlow provides an IT documentation, ticketing and accounting system f ...)
- TODO: check
+ NOT-FOR-US: ITFlow
CVE-2026-54596 (ITFlow provides an IT documentation, ticketing and accounting system f ...)
- TODO: check
+ NOT-FOR-US: ITFlow
CVE-2026-54594 (OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June ...)
- TODO: check
+ NOT-FOR-US: OmniBlocks
CVE-2026-54565 (rhwp is an HWP viewer and editor implemented in Rust and WebAssembly. ...)
TODO: check
CVE-2026-54521 (FairEmail is a fully featured, open source, privacy-friendly email app ...)
TODO: check
CVE-2026-54520 (AI Agent Automation is a modular AI agent workflow automation platform ...)
- TODO: check
+ NOT-FOR-US: AI Agent Automation
CVE-2026-54519 (AI Agent Automation is a modular AI agent workflow automation platform ...)
- TODO: check
+ NOT-FOR-US: AI Agent Automation
CVE-2026-54510 (Speakr is a personal, self-hosted web application designed for transcr ...)
TODO: check
CVE-2026-54507 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
- TODO: check
+ NOT-FOR-US: Vvveb
CVE-2026-54506 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
- TODO: check
+ NOT-FOR-US: Vvveb
CVE-2026-54501 (Browsertrix is a high-fidelity, browser-based crawling service for web ...)
- TODO: check
+ NOT-FOR-US: Browsertrix
CVE-2026-54495 (The OpenFeature Operator allows users to expose feature flags to appli ...)
- TODO: check
+ NOT-FOR-US: OpenFeature Operator
CVE-2026-54460 (OpenReception's appointment booking software provides an end-to-end en ...)
- TODO: check
+ NOT-FOR-US: OpenReception
CVE-2026-54355 (MapServer is a system for developing web-based GIS applications. From ...)
TODO: check
CVE-2026-54354 (MapServer is a system for developing web-based GIS applications. Prior ...)
TODO: check
CVE-2026-54343 (Frappe Learning Management System (LMS) is a learning system that help ...)
- TODO: check
+ NOT-FOR-US: FRappe
CVE-2026-54339 (Glean is a self-hosted RSS reader and personal knowledge management to ...)
TODO: check
CVE-2026-54237 (Wavelog is web-based amateur radio logging software. From 1.8 until 2. ...)
@@ -1064,15 +1064,15 @@ CVE-2026-52483 (The ping diagnostics and other similar functions of the MitraSta
CVE-2026-50291 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
TODO: check
CVE-2026-50285 (Pomerium is an identity and context-aware access proxy. Prior to 0.32. ...)
- TODO: check
+ NOT-FOR-US: Pomerium
CVE-2026-50277 (dd-trace-cpp is the Datadog distributed tracing library for C++. Prior ...)
- TODO: check
+ NOT-FOR-US: dd-trace-cpp
CVE-2026-50275 (The Datadog PHP Tracer provides application performance monitoring and ...)
NOT-FOR-US: Datadog PHP Tracer
CVE-2026-50158 (yutu is an AI-powered toolkit for managing and growing YouTube channel ...)
- TODO: check
+ NOT-FOR-US: yutu
CVE-2026-50125 (MKP is a Model Context Protocol server for Kubernetes. Prior to 0.4.1, ...)
- TODO: check
+ NOT-FOR-US: MKP
CVE-2026-50022 (Metacat is data repository software that helps researchers preserve, s ...)
TODO: check
CVE-2026-49137
@@ -1124,7 +1124,7 @@ CVE-2026-10594
CVE-2025-62167
REJECTED
CVE-2025-55787 (In MailData Email Archiving System v4.2 and earlier, a SQL injection v ...)
- TODO: check
+ NOT-FOR-US: MailData Email Archiving System
CVE-2024-38639 (An improper authentication vulnerability has been reported to affect p ...)
NOT-FOR-US: QNAP
CVE-2024-27123 (A cross-site scripting (XSS) vulnerability has been reported to affect ...)
@@ -1355,11 +1355,11 @@ CVE-2026-86533 (Insufficient Session Expiration vulnerability in team-alembic As
CVE-2026-86522 (Improper Output Neutralization for Logs vulnerability in team-alembic ...)
TODO: check
CVE-2026-86040 (libp2p is a JavaScript implementation of the libp2p networking stack. ...)
- TODO: check
+ NOT-FOR-US: Node libp2p
CVE-2026-86039 (libp2p is a JavaScript implementation of the libp2p networking stack. ...)
- TODO: check
+ NOT-FOR-US: Node libp2p
CVE-2026-86038 (libp2p is a JavaScript implementation of the libp2p networking stack. ...)
- TODO: check
+ NOT-FOR-US: Node libp2p
CVE-2026-86000 (Soup Sieve is a CSS selector library designed to be used with Beautifu ...)
TODO: check
CVE-2026-85999 (Soup Sieve is a CSS selector library designed to be used with Beautifu ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4aed2571dfe140eb56aff1fcb14d77aa454eea8b
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4aed2571dfe140eb56aff1fcb14d77aa454eea8b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/8f60a54e/attachment.htm>
More information about the debian-security-tracker-commits
mailing list