[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Sep 18 23:03:15 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4aed2571 by Moritz Muehlenhoff at 2026-09-19T00:03:06+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -361,33 +361,33 @@ CVE-2026-77928 (ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection v
 CVE-2026-77927 (ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnera ...)
 	TODO: check
 CVE-2026-77616 (Semantic MediaWiki is a free, open-source extension to MediaWiki that  ...)
-	TODO: check
+	NOT-FOR-US: Semantic MediaWiki MediaWiki extension
 CVE-2026-77610 (Semantic MediaWiki is a free, open-source extension to MediaWiki that  ...)
-	TODO: check
+	NOT-FOR-US: Semantic MediaWiki MediaWiki extension
 CVE-2026-77609 (Semantic MediaWiki is a free, open-source extension to MediaWiki that  ...)
-	TODO: check
+	NOT-FOR-US: Semantic MediaWiki MediaWiki extension
 CVE-2026-77608 (Semantic MediaWiki is a free, open-source extension to MediaWiki that  ...)
-	TODO: check
+	NOT-FOR-US: Semantic MediaWiki MediaWiki extension
 CVE-2026-77607 (Semantic MediaWiki is a free, open-source extension to MediaWiki that  ...)
-	TODO: check
+	NOT-FOR-US: Semantic MediaWiki MediaWiki extension
 CVE-2026-77606 (Semantic MediaWiki is a free, open-source extension to MediaWiki that  ...)
-	TODO: check
+	NOT-FOR-US: Semantic MediaWiki MediaWiki extension
 CVE-2026-77568 (Mojolicious is a real-time web framework for Perl. Prior to 9.48, the  ...)
 	TODO: check
 CVE-2026-77396 (PJSIP is a free and open source multimedia communication library writt ...)
 	TODO: check
 CVE-2026-77386 (Kyoo is a self-hosted media server focused on movies, series, and anim ...)
-	TODO: check
+	NOT-FOR-US: check
 CVE-2026-77385 (Kyoo is a self-hosted media server focused on movies, series, and anim ...)
-	TODO: check
+	NOT-FOR-US: check
 CVE-2026-77339 (Process Compose is a scheduler and orchestrator for non-containerized  ...)
 	TODO: check
 CVE-2026-77301 (adm-zip is a JavaScript library for creating and extracting ZIP archiv ...)
 	TODO: check
 CVE-2026-77240 (WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 a ...)
-	TODO: check
+	NOT-FOR-US: WACRM
 CVE-2026-77239 (WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 a ...)
-	TODO: check
+	NOT-FOR-US: WACRM
 CVE-2026-75961 (The NEX-Forms \u2013 Ultimate Forms Plugin for WordPress plugin for Wo ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-75894 (In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found i ...)
@@ -431,9 +431,9 @@ CVE-2026-63638 (OpenImageIO is a toolset for reading, writing, and manipulating
 CVE-2026-63635 (OpenImageIO is a toolset for reading, writing, and manipulating image  ...)
 	TODO: check
 CVE-2026-63458 (Perses is an open-source dashboard and visualization project for obser ...)
-	TODO: check
+	NOT-FOR-US: Perses
 CVE-2026-63445 (Perses is an open-source dashboard and visualization project for obser ...)
-	TODO: check
+	NOT-FOR-US: Perses
 CVE-2026-63422 (OpenImageIO is a toolset for reading, writing, and manipulating image  ...)
 	TODO: check
 CVE-2026-63420 (OpenImageIO is a toolset for reading, writing, and manipulating image  ...)
@@ -447,15 +447,15 @@ CVE-2026-63405 (AnyCable is a realtime server for reliable two-way communication
 CVE-2026-63349 (AnyIO is a high level asynchronous concurrency and networking framewor ...)
 	TODO: check
 CVE-2026-63199 (Perses is an open-source dashboard and visualization project for obser ...)
-	TODO: check
+	NOT-FOR-US: Perses
 CVE-2026-62943 (btrbk is a tool for creating snapshots and remote backups of Btrfs sub ...)
 	TODO: check
 CVE-2026-62282 (OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, Open ...)
 	TODO: check
 CVE-2026-62279 (LubeLogger is a self-hosted, open-source, web-based vehicle maintenanc ...)
-	TODO: check
+	NOT-FOR-US: LubeLogger
 CVE-2026-62278 (LubeLogger is a self-hosted, open-source, web-based vehicle maintenanc ...)
-	TODO: check
+	NOT-FOR-US: LubeLogger
 CVE-2026-61833 (zot is a container image and artifact registry based on the Open Conta ...)
 	TODO: check
 CVE-2026-61795 (Capsule is a multi-tenancy and policy-based framework for Kubernetes.  ...)
@@ -479,7 +479,7 @@ CVE-2026-59163 (Mnemosyne is a memory layer for artificial intelligence agents.
 CVE-2026-59156 (OpenImageIO is a toolset for reading, writing, and manipulating image  ...)
 	TODO: check
 CVE-2026-58197 (ToolHive is a utility designed to simplify the deployment and manageme ...)
-	TODO: check
+	NOT-FOR-US: ToolHive
 CVE-2026-56597 (HCL BigFix Service Management is affected by a Sensitive Information L ...)
 	NOT-FOR-US: HCL
 CVE-2026-56595 (HCL BigFix Service Management is affected by a CORS Misconfiguration v ...)
@@ -489,9 +489,9 @@ CVE-2026-56592 (HCL BigFix Service Management is affected by an Improper Authent
 CVE-2026-56590 (HCL BigFix Service Management is affected by an Unrestricted File Uplo ...)
 	NOT-FOR-US: HCL
 CVE-2026-54148 (http4k is a functional toolkit for Kotlin HTTP applications. Prior to  ...)
-	TODO: check
+	NOT-FOR-US: http4k
 CVE-2026-54147 (http4k is a functional toolkit for Kotlin HTTP applications. Prior to  ...)
-	TODO: check
+	NOT-FOR-US: http4k
 CVE-2026-4036 (An improper neutralization of special elements used in an SQL command  ...)
 	NOT-FOR-US: Synology
 CVE-2026-44639 (NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's MQTT v5 property  ...)
@@ -593,9 +593,9 @@ CVE-2026-12954 (The Mapster WP Maps plugin for WordPress is vulnerable to Arbitr
 CVE-2026-12739 (The WP Easy Pay \u2013 Payment and Donation form Builder for Square pl ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-12384 (Authorization bypass through User-Controlled key vulnerability in TECH ...)
-	TODO: check
+	NOT-FOR-US: TECHIN2B
 CVE-2026-11757 (Improper neutralization of input during web page generation ('cross-si ...)
-	TODO: check
+	NOT-FOR-US: KA Informatics Technologies 
 CVE-2026-11538 (IBM WebSphere Application Server 9.0 and 8.5 is affected by a log inje ...)
 	NOT-FOR-US: IBM
 CVE-2026-11537 (IBM WebSphere Application Server 9.0, and 8.5 could allow a remote att ...)
@@ -627,9 +627,9 @@ CVE-2026-10030 (IBM MQ Console allows authenticated non-administrative users to
 CVE-2026-10027 (IBM MQ could allow a remote attacker to cause a denial of service or e ...)
 	NOT-FOR-US: IBM
 CVE-2025-66455 (LMDeploy is a toolkit for compressing, deploying, and serving large la ...)
-	TODO: check
+	NOT-FOR-US: LMDeploy
 CVE-2025-61682 (Semantic MediaWiki is a free, open-source extension to MediaWiki that  ...)
-	TODO: check
+	NOT-FOR-US: Semantic MediaWiki MediaWiki extension
 CVE-2025-53837 (XWiki Rendering is a generic rendering system that converts textual in ...)
 	NOT-FOR-US: XWiki
 CVE-2025-36421 (IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP ...)
@@ -663,11 +663,11 @@ CVE-2024-56344 (IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 throu
 CVE-2023-5778 (Improper handling of length parameter inconsistency vulnerability in A ...)
 	NOT-FOR-US: ABB group
 CVE-2023-54399 (Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the ...)
-	TODO: check
+	NOT-FOR-US: Hongjing e-HR
 CVE-2021-48008 (Chanjet CRM contains an unauthenticated SQL injection vulnerability th ...)
-	TODO: check
+	NOT-FOR-US: Chanjet CRM
 CVE-2019-25776 (Weaver E-cology contains an unauthenticated SQL injection vulnerabilit ...)
-	TODO: check
+	NOT-FOR-US: Weaver E-cology
 CVE-2026-92828
 	NOT-FOR-US: OpenShift
 CVE-2026-92218
@@ -968,7 +968,7 @@ CVE-2026-54918 (NetBox Device Type Library is a collection of community-sourced
 CVE-2026-54916 (NetBox Device Type Library is a collection of community-sourced device ...)
 	NOT-FOR-US: NetBox Device Type LibraryCubeCart
 CVE-2026-54907 (Caddy Proxy Manager is a web interface for managing Caddy Server rever ...)
-	TODO: check
+	NOT-FOR-US: Caddy Proxy Manager
 CVE-2026-54767 (WeGIA is a web manager for charitable institutions. Prior to 3.8.5, we ...)
 	NOT-FOR-US: WeGIA
 CVE-2026-54752 (NetBox Device Type Library is a collection of community-sourced device ...)
@@ -1006,45 +1006,45 @@ CVE-2026-54627 (SAIL is a cross-platform library for loading and saving images w
 CVE-2026-54626 (SAIL is a cross-platform library for loading and saving images with su ...)
 	TODO: check
 CVE-2026-54618 (Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Pr ...)
-	TODO: check
+	NOT-FOR-US: Obsidian Web MCP
 CVE-2026-54613 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
-	TODO: check
+	NOT-FOR-US: Vvveb
 CVE-2026-54612 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
-	TODO: check
+	NOT-FOR-US: Vvveb
 CVE-2026-54608 (MythicalDash is a Pterodactyl client area. In 3.5.4-aurora and earlier ...)
-	TODO: check
+	NOT-FOR-US: MythicalDash
 CVE-2026-54597 (ITFlow provides an IT documentation, ticketing and accounting system f ...)
-	TODO: check
+	NOT-FOR-US: ITFlow
 CVE-2026-54596 (ITFlow provides an IT documentation, ticketing and accounting system f ...)
-	TODO: check
+	NOT-FOR-US: ITFlow
 CVE-2026-54594 (OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June ...)
-	TODO: check
+	NOT-FOR-US: OmniBlocks
 CVE-2026-54565 (rhwp is an HWP viewer and editor implemented in Rust and WebAssembly.  ...)
 	TODO: check
 CVE-2026-54521 (FairEmail is a fully featured, open source, privacy-friendly email app ...)
 	TODO: check
 CVE-2026-54520 (AI Agent Automation is a modular AI agent workflow automation platform ...)
-	TODO: check
+	NOT-FOR-US: AI Agent Automation
 CVE-2026-54519 (AI Agent Automation is a modular AI agent workflow automation platform ...)
-	TODO: check
+	NOT-FOR-US: AI Agent Automation
 CVE-2026-54510 (Speakr is a personal, self-hosted web application designed for transcr ...)
 	TODO: check
 CVE-2026-54507 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
-	TODO: check
+	NOT-FOR-US: Vvveb
 CVE-2026-54506 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
-	TODO: check
+	NOT-FOR-US: Vvveb
 CVE-2026-54501 (Browsertrix is a high-fidelity, browser-based crawling service for web ...)
-	TODO: check
+	NOT-FOR-US: Browsertrix
 CVE-2026-54495 (The OpenFeature Operator allows users to expose feature flags to appli ...)
-	TODO: check
+	NOT-FOR-US: OpenFeature Operator
 CVE-2026-54460 (OpenReception's appointment booking software provides an end-to-end en ...)
-	TODO: check
+	NOT-FOR-US: OpenReception
 CVE-2026-54355 (MapServer is a system for developing web-based GIS applications. From  ...)
 	TODO: check
 CVE-2026-54354 (MapServer is a system for developing web-based GIS applications. Prior ...)
 	TODO: check
 CVE-2026-54343 (Frappe Learning Management System (LMS) is a learning system that help ...)
-	TODO: check
+	NOT-FOR-US: FRappe
 CVE-2026-54339 (Glean is a self-hosted RSS reader and personal knowledge management to ...)
 	TODO: check
 CVE-2026-54237 (Wavelog is web-based amateur radio logging software. From 1.8 until 2. ...)
@@ -1064,15 +1064,15 @@ CVE-2026-52483 (The ping diagnostics and other similar functions of the MitraSta
 CVE-2026-50291 (OpenImageIO is a toolset for reading, writing, and manipulating image  ...)
 	TODO: check
 CVE-2026-50285 (Pomerium is an identity and context-aware access proxy. Prior to 0.32. ...)
-	TODO: check
+	NOT-FOR-US: Pomerium
 CVE-2026-50277 (dd-trace-cpp is the Datadog distributed tracing library for C++. Prior ...)
-	TODO: check
+	NOT-FOR-US: dd-trace-cpp
 CVE-2026-50275 (The Datadog PHP Tracer provides application performance monitoring and ...)
 	NOT-FOR-US: Datadog PHP Tracer
 CVE-2026-50158 (yutu is an AI-powered toolkit for managing and growing YouTube channel ...)
-	TODO: check
+	NOT-FOR-US: yutu
 CVE-2026-50125 (MKP is a Model Context Protocol server for Kubernetes. Prior to 0.4.1, ...)
-	TODO: check
+	NOT-FOR-US: MKP
 CVE-2026-50022 (Metacat is data repository software that helps researchers preserve, s ...)
 	TODO: check
 CVE-2026-49137
@@ -1124,7 +1124,7 @@ CVE-2026-10594
 CVE-2025-62167
 	REJECTED
 CVE-2025-55787 (In MailData Email Archiving System v4.2 and earlier, a SQL injection v ...)
-	TODO: check
+	NOT-FOR-US: MailData Email Archiving System
 CVE-2024-38639 (An improper authentication vulnerability has been reported to affect p ...)
 	NOT-FOR-US: QNAP
 CVE-2024-27123 (A cross-site scripting (XSS) vulnerability has been reported to affect ...)
@@ -1355,11 +1355,11 @@ CVE-2026-86533 (Insufficient Session Expiration vulnerability in team-alembic As
 CVE-2026-86522 (Improper Output Neutralization for Logs vulnerability in team-alembic  ...)
 	TODO: check
 CVE-2026-86040 (libp2p is a JavaScript implementation of the libp2p networking stack.  ...)
-	TODO: check
+	NOT-FOR-US: Node libp2p
 CVE-2026-86039 (libp2p is a JavaScript implementation of the libp2p networking stack.  ...)
-	TODO: check
+	NOT-FOR-US: Node libp2p
 CVE-2026-86038 (libp2p is a JavaScript implementation of the libp2p networking stack.  ...)
-	TODO: check
+	NOT-FOR-US: Node libp2p
 CVE-2026-86000 (Soup Sieve is a CSS selector library designed to be used with Beautifu ...)
 	TODO: check
 CVE-2026-85999 (Soup Sieve is a CSS selector library designed to be used with Beautifu ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4aed2571dfe140eb56aff1fcb14d77aa454eea8b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4aed2571dfe140eb56aff1fcb14d77aa454eea8b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/8f60a54e/attachment.htm>


More information about the debian-security-tracker-commits mailing list