[Git][security-tracker-team/security-tracker][master] Process some NFUx
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Sep 19 06:46:32 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b57ab938 by Salvatore Bonaccorso at 2026-09-19T07:46:03+02:00
Process some NFUx
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -235,11 +235,11 @@ CVE-2026-93488 (A flaw was found in Netty. SpdySessionHandler accepts an unlimit
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536887
NOTE: https://github.com/netty/netty/security/advisories/GHSA-rmcw-9fcq-wjq7
CVE-2026-93432 (A flaw was found in the Quarkus Qute template engine. When the {#eval} ...)
- TODO: check
+ NOT-FOR-US: Quarkus
CVE-2026-93338 (Grandstream GWN7660ELR before firmware version 1.0.27.6 contains an in ...)
- TODO: check
+ NOT-FOR-US: Grandstream GWN7660ELR
CVE-2026-92976 (A stored Cross-Site Scripting (XSS) vulnerability in the profile manag ...)
- TODO: check
+ NOT-FOR-US: T-Systems TAO
CVE-2026-92768 (A flaw was found in cockpit-machines. This vulnerability allows a loca ...)
- cockpit-machines <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2469258
@@ -250,9 +250,9 @@ CVE-2026-92745 (A flaw was found in cockpit-machines. This vulnerability allows
- cockpit-machines <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2476266
CVE-2026-92702 (Cocos AI is a confidential computing system for running AI workloads i ...)
- TODO: check
+ NOT-FOR-US: Cocos AI
CVE-2026-92701 (trusted execution environments. In versions up to and including 0.8.2, ...)
- TODO: check
+ NOT-FOR-US: Cocos AI
CVE-2026-92622 (The Strong Testimonials plugin for WordPress is vulnerable to Stored C ...)
NOT-FOR-US: WordPress plugin
CVE-2026-92554 (The ShopLentor \u2013 All-in-One WooCommerce Growth & Store Enhancemen ...)
@@ -266,7 +266,7 @@ CVE-2026-91147 (A flaw was found in `cockpit-ws`. This vulnerability allows a re
CVE-2026-91142 (A flaw was found in Cockpit. An integer overflow vulnerability in the ...)
TODO: check
CVE-2026-91127 (File Viewer is a browser-native viewer for Office, PDF, CAD, archive, ...)
- TODO: check
+ NOT-FOR-US: File Viewer
CVE-2026-90981 (The Newsletter \u2013 Send awesome emails from WordPress plugin for Wo ...)
NOT-FOR-US: WordPress plugin
CVE-2026-90884 (The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross ...)
@@ -276,33 +276,33 @@ CVE-2026-89059 (A flaw was found in RESTEasy's IIOImageProvider, which decodes a
CVE-2026-89058 (A flaw was found in RESTEasy's CorsFilter, which, when configured to a ...)
TODO: check
CVE-2026-88623 (NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read ...)
- TODO: check
+ NOT-FOR-US: NUUO Network Video Recorder
CVE-2026-88622 (NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection i ...)
- TODO: check
+ NOT-FOR-US: NUUO Network Video Recorder
CVE-2026-88259 (CareCam CM2507 IP cameras do not require authentication for access to ...)
- TODO: check
+ NOT-FOR-US: CareCam CM2507 IP cameras
CVE-2026-87915 (The Popup Maker \u2013 Boost Sales, Conversions, Optins, Subscribers w ...)
NOT-FOR-US: WordPress plugin
CVE-2026-86689 (Bransys ELDis shipped with hardcoded MQTT credentials, which will gran ...)
- TODO: check
+ NOT-FOR-US: Bransys
CVE-2026-86520 (Bransys ELDis shipped with hardcoded MQTT credentials, which will gran ...)
- TODO: check
+ NOT-FOR-US: Bransys
CVE-2026-85705 (The Location Manager plugin for WordPress is vulnerable to generic SQL ...)
NOT-FOR-US: WordPress plugin
CVE-2026-85652 (The Photo Gallery by 10Web \u2013 Mobile-Friendly Image Gallery plugin ...)
NOT-FOR-US: WordPress plugin
CVE-2026-85511 (A flaw was found in EAP's Elytron. An EAP application whose security d ...)
- TODO: check
+ NOT-FOR-US: wildfly-elytron-realm-token
CVE-2026-85497 (CareCam CM2507 IP cameras store the device's root-account password usi ...)
- TODO: check
+ NOT-FOR-US: CareCam CM2507 IP cameras
CVE-2026-85478 (A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 ex ...)
- TODO: check
+ NOT-FOR-US: CM2507 IP camera
CVE-2026-85410 (The Master Addons for Elementor \u2013 Elementor Addons, Widgets, Mega ...)
NOT-FOR-US: WordPress plugin
CVE-2026-85058 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffic ...)
- TODO: check
+ NOT-FOR-US: Moquette
CVE-2026-84992 (md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeS ...)
- TODO: check
+ NOT-FOR-US: md-editor-v3
CVE-2026-84975 (PJSIP is a free and open source multimedia communication library writt ...)
TODO: check
CVE-2026-84449 (libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1 ...)
@@ -1360,9 +1360,9 @@ CVE-2026-86862 (pgAdmin 4's Restore and Maintenance tools passed the client-supp
CVE-2026-86861 (pgAdmin 4's File Manager save_file endpoint, which backs saving from t ...)
- pgadmin4 <itp> (bug #834129)
CVE-2026-86533 (Insufficient Session Expiration vulnerability in team-alembic AshAuthe ...)
- TODO: check
+ NOT-FOR-US: team-alembic
CVE-2026-86522 (Improper Output Neutralization for Logs vulnerability in team-alembic ...)
- TODO: check
+ NOT-FOR-US: team-alembic
CVE-2026-86040 (libp2p is a JavaScript implementation of the libp2p networking stack. ...)
NOT-FOR-US: Node libp2p
CVE-2026-86039 (libp2p is a JavaScript implementation of the libp2p networking stack. ...)
@@ -1386,9 +1386,9 @@ CVE-2026-85717 (The AsyncHttpClient (AHC) library allows Java applications to ea
CVE-2026-85716 (The AsyncHttpClient (AHC) library allows Java applications to easily e ...)
TODO: check
CVE-2026-85715 (ExifReader is a JavaScript Exif information parser. Prior to 4.41.1, E ...)
- TODO: check
+ NOT-FOR-US: ExifReader
CVE-2026-85500 (Authentication Bypass by Primary Weakness vulnerability in team-alembi ...)
- TODO: check
+ NOT-FOR-US: team-alembic
CVE-2026-85078 (Sanic is an opensource python web server/framework. In version 25.12.0 ...)
NOT-FOR-US: Sanic
CVE-2026-85077 (Sanic is an opensource python web server/framework. Prior to version 2 ...)
@@ -4052,7 +4052,7 @@ CVE-2026-88795 (The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 d
CVE-2026-88792 (The Dictionary WordPress plugin through 1.0 does not have authorisatio ...)
NOT-FOR-US: WordPress plugin
CVE-2026-88592 (kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF ...)
- TODO: check
+ NOT-FOR-US: kkFileView
CVE-2026-87976 (Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipula ...)
TODO: check
CVE-2026-87963 (The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or pa ...)
@@ -4100,7 +4100,7 @@ CVE-2026-86311 (The Photo Gallery by 10Web \u2013 Mobile-Friendly Image Gallery
CVE-2026-86089 (Apache NiFi 2.11.0 supports migrating the contents of a version-contro ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-86071 (Junrar is an open source Java RAR archive library. Prior to version 7. ...)
- TODO: check
+ NOT-FOR-US: Junrar
CVE-2026-85789
REJECTED
CVE-2026-85469 (A flaw was found in quay-builder-qemu. A remote attacker could exploit ...)
@@ -4510,7 +4510,7 @@ CVE-2026-92356 (A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1. T
CVE-2026-92355 (In affected versions of Octopus Server, a user with permission to modi ...)
NOT-FOR-US: Octopus Deploy
CVE-2026-92299 (@jitsi/electron-sdk before 10.0.5 exposes getDesktopSources() via cont ...)
- TODO: check
+ NOT-FOR-US: jitsi-meet-electron-sdk
CVE-2026-92298 (EspoCRM through 10.0.8 uses PHP's rand() function to generate tokens f ...)
NOT-FOR-US: EspoCRM
CVE-2026-92259 (Integer overflow or wraparound vulnerability in Samsung Opensource Esc ...)
@@ -4635,7 +4635,7 @@ CVE-2026-90971 (Server-Side Request Forgery (SSRF) in the VMware synchronization
CVE-2026-90969 (Improper access control in the vault entry listing feature inDevolutio ...)
NOT-FOR-US: Devolutions
CVE-2026-8462 (SQL injection in ClickHouse-backed meter definitions in OpenMeter Open ...)
- TODO: check
+ NOT-FOR-US: OpenMeter
CVE-2026-8030 (GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-89328 (The FluentBoards WordPress plugin before 2.0.15 does not properly ver ...)
@@ -5063,7 +5063,7 @@ CVE-2026-86358 (Dell Update Package Framework, versions prior to 26.07.03, conta
CVE-2026-86341 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-86338 (Ash field_policies are documented to protect against filter-based info ...)
- TODO: check
+ NOT-FOR-US: ash-project
CVE-2026-86109 (The VeloCloud Edge software update workflow may accept update bundles ...)
NOT-FOR-US: Arista Networks
CVE-2026-86108 (Insufficient validation of inputs supplied through affected VeloCloud ...)
@@ -5073,13 +5073,13 @@ CVE-2026-86107 (The VeloCloud Edge and Gateway exhibit an out-of-bounds write vu
CVE-2026-86106 (An unauthenticated actor with network access to the private HA interco ...)
NOT-FOR-US: Arista Networks
CVE-2026-86043 (Skipper is an HTTP router and reverse proxy for service composition. P ...)
- TODO: check
+ NOT-FOR-US: Zalando Skipper
CVE-2026-86003 (CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-H ...)
- coredns <itp> (bug #880676)
CVE-2026-85893 (Use after free in Microsoft Edge (Chromium-based) allows an unauthoriz ...)
NOT-FOR-US: Microsoft
CVE-2026-85756 (SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2026.0.0, S ...)
- TODO: check
+ NOT-FOR-US: SSH.NET
CVE-2026-85732 (oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, th ...)
TODO: check
CVE-2026-85731 (oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, co ...)
@@ -5105,11 +5105,11 @@ CVE-2026-85349 (The FluentBoards WordPress plugin before 2.0.15 does not proper
CVE-2026-85131 (The WPLP Cookie Consent WordPress plugin before 4.4.4 does not perfor ...)
NOT-FOR-US: WordPress plugin
CVE-2026-85104 (In Sooma 2GEN brain stimulator, an attacker within Bluetooth range can ...)
- TODO: check
+ NOT-FOR-US: Sooma 2GEN brain stimulator
CVE-2026-84997 (react/http is an event-driven, streaming HTTP client and server implem ...)
- TODO: check
+ NOT-FOR-US: react/http
CVE-2026-84993 (MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of ...)
- TODO: check
+ NOT-FOR-US: MikroORM
CVE-2026-84907 (The Eventin WordPress plugin before 4.1.24 does not properly authoris ...)
NOT-FOR-US: WordPress plugin
CVE-2026-84906 (The Eventin WordPress plugin before 4.1.24 does not verify that a comp ...)
@@ -5117,11 +5117,11 @@ CVE-2026-84906 (The Eventin WordPress plugin before 4.1.24 does not verify that
CVE-2026-84905 (The Eventin WordPress plugin before 4.1.24 does not verify a user's c ...)
NOT-FOR-US: WordPress plugin
CVE-2026-84860 (ScadaLTS 2.8.1-release-candidate build 0 is affected by anAuthorizatio ...)
- TODO: check
+ NOT-FOR-US: ScadaLTS
CVE-2026-84859 (ScadaLTS 2.8.1-release-candidate build 0 is affected by anAuthenticate ...)
- TODO: check
+ NOT-FOR-US: ScadaLTS
CVE-2026-84858 (ScadaLTS 2.8.1-release-candidate build 0 is affected by anAuthenticate ...)
- TODO: check
+ NOT-FOR-US: ScadaLTS
CVE-2026-84850 (Improper certificate validation in the shared HTTP client used by sync ...)
NOT-FOR-US: Devolutions
CVE-2026-84829 (The Optimole WordPress plugin before 4.2.12 does not properly escape ...)
@@ -10488,7 +10488,7 @@ CVE-2026-89020 (MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable)
CVE-2026-88932 (multer is a Node.js middleware for handling multipart/form-data upload ...)
NOT-FOR-US: Node multer
CVE-2026-88819 (In Siglet current and past versions the refresh token handler do not e ...)
- TODO: check
+ NOT-FOR-US: Siglet
CVE-2026-87802 (Improper verification of cryptographic signature vulnerability in Apac ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-87785 (Authentication bypass by spoofing vulnerability in Apache Syncope. ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b57ab938a1f4d98898f8c4186209d2592ae12fa5
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b57ab938a1f4d98898f8c4186209d2592ae12fa5
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260919/12c09f24/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list