[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 19 08:43:11 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a5d208de by Salvatore Bonaccorso at 2026-09-19T09:42:49+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -5,25 +5,25 @@ CVE-2026-93922 (SiYuan through 3.8.4 renders notebook names as raw HTML in the D
 CVE-2026-93921 (SiYuan versions through 3.8.4 fail to enforce publish access control i ...)
 	NOT-FOR-US: SiYuan
 CVE-2026-93873 (Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contac ...)
-	TODO: check
+	NOT-FOR-US: Cotonti
 CVE-2026-93872 (Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize()  ...)
-	TODO: check
+	NOT-FOR-US: Cotonti
 CVE-2026-93871 (Cotonti through 1.0.0 fails to validate redirect destinations in page  ...)
-	TODO: check
+	NOT-FOR-US: Cotonti
 CVE-2026-93870 (Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the rating ...)
-	TODO: check
+	NOT-FOR-US: Cotonti
 CVE-2026-93869 (Cotonti through 1.0.0 contains an open redirect vulnerability in the c ...)
-	TODO: check
+	NOT-FOR-US: Cotonti
 CVE-2026-93868 (Cotonti through 1.0.0 derives password recovery validation tokens from ...)
-	TODO: check
+	NOT-FOR-US: Cotonti
 CVE-2026-93841 (vLLM through 0.29.0 contains a memory corruption vulnerability in the  ...)
 	TODO: check
 CVE-2026-93840 (vLLM before 0.29.0 validates allowed_token_ids against tokenizer lengt ...)
 	TODO: check
 CVE-2026-93839 (LightLLM through 1.2.0 contains an authentication bypass vulnerability ...)
-	TODO: check
+	NOT-FOR-US: LightLLM
 CVE-2026-93838 (SGLang versions through 0.5.20 contain an unbounded memory allocation  ...)
-	TODO: check
+	NOT-FOR-US: SGLang
 CVE-2026-93741 (A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1 ...)
 	NOT-FOR-US: TOTOLINK
 CVE-2026-93740 (A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046.  ...)
@@ -43,7 +43,7 @@ CVE-2026-92967 (The Pochipp plugin for WordPress is vulnerable to Reflected Cros
 CVE-2026-92807 (The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-92708 (Svelte devalue is a JavaScript library that serializes values into str ...)
-	TODO: check
+	NOT-FOR-US: Svelte devalue
 CVE-2026-92435 (The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not v ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-92430 (The Rede Ita\xfa for WooCommerce \u2014 Payment PIX, Credit Card and D ...)
@@ -99,9 +99,9 @@ CVE-2026-85680 (The Ultimate Member  WordPress plugin before 2.13.1 does not esc
 CVE-2026-85574 (The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perf ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-85272 (Open edX Platform enables the authoring and delivery of online learnin ...)
-	TODO: check
+	NOT-FOR-US: Open edX Platform
 CVE-2026-85271 (Open edX Platform enables the authoring and delivery of online learnin ...)
-	TODO: check
+	NOT-FOR-US: Open edX Platform
 CVE-2026-84750 (The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 doe ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-84434 (The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File ...)
@@ -646,9 +646,9 @@ CVE-2026-84444 (libheif is a HEIF and AVIF file format decoder and encoder. Prio
 	NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-j264-xvrp-5v7q
 	NOTE: Fixed by: https://github.com/strukturag/libheif/commit/e65071f59a1ac08aa1eb0d07a831deaf6bb4d03b (v1.23.2)
 CVE-2026-84400 (CareCam CM2507 IP cameras contain an insufficiently protected network  ...)
-	TODO: check
+	NOT-FOR-US: CareCam CM2507 IP cameras
 CVE-2026-84398 (CM2507 IP cameras accept an empty password for a privileged account ex ...)
-	TODO: check
+	NOT-FOR-US: CM2507 IP cameras
 CVE-2026-84384 (libheif is a HEIF and AVIF file format decoder and encoder. From 1.19. ...)
 	- libheif 1.23.2-1
 	NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-24wx-9w62-c96w
@@ -656,45 +656,45 @@ CVE-2026-84384 (libheif is a HEIF and AVIF file format decoder and encoder. From
 CVE-2026-83561 (The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-81946 (PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware ve ...)
-	TODO: check
+	NOT-FOR-US: PLANET
 CVE-2026-81945 (PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware ve ...)
-	TODO: check
+	NOT-FOR-US: PLANET
 CVE-2026-81944 (PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware ve ...)
-	TODO: check
+	NOT-FOR-US: PLANET
 CVE-2026-81943 (PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware ve ...)
-	TODO: check
+	NOT-FOR-US: PLANET
 CVE-2026-81942 (PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware ve ...)
-	TODO: check
+	NOT-FOR-US: PLANET
 CVE-2026-81627 (A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c ...)
 	TODO: check
 CVE-2026-81505 (Convoy is a cloud native webhooks gateway. Prior to 26.6.8, Convoy's G ...)
-	TODO: check
+	NOT-FOR-US: Convoy
 CVE-2026-81321 (CM2507 IP cameras store configured wireless network credentials in cle ...)
-	TODO: check
+	NOT-FOR-US: CM2507 IP cameras
 CVE-2026-81305 (CM2507 IP cameras automatically execute a predetermined script from re ...)
-	TODO: check
+	NOT-FOR-US: CM2507 IP cameras
 CVE-2026-81182 (SysReptor is a fully customizable pentest reporting platform. Prior to ...)
-	TODO: check
+	NOT-FOR-US: SysReptor
 CVE-2026-81181 (SysReptor is a fully customizable pentest reporting platform. Prior to ...)
-	TODO: check
+	NOT-FOR-US: SysReptor
 CVE-2026-81180 (SysReptor is a fully customizable pentest reporting platform. Prior to ...)
-	TODO: check
+	NOT-FOR-US: SysReptor
 CVE-2026-81179 (SysReptor is a fully customizable pentest reporting platform. Prior to ...)
-	TODO: check
+	NOT-FOR-US: SysReptor
 CVE-2026-81178 (SysReptor is a fully customizable pentest reporting platform. Prior to ...)
-	TODO: check
+	NOT-FOR-US: SysReptor
 CVE-2026-7006 (Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build ...)
 	TODO: check
 CVE-2026-79294 (Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2 ...)
-	TODO: check
+	NOT-FOR-US: Moonshot AI Kimi
 CVE-2026-77960 (Bransys ELDis shipped with hardcoded MQTT credentials, which will gran ...)
-	TODO: check
+	NOT-FOR-US: Bransys
 CVE-2026-77929 (ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability t ...)
-	TODO: check
+	NOT-FOR-US: ClipBucket
 CVE-2026-77928 (ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnera ...)
-	TODO: check
+	NOT-FOR-US: ClipBucket
 CVE-2026-77927 (ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnera ...)
-	TODO: check
+	NOT-FOR-US: ClipBucket
 CVE-2026-77616 (Semantic MediaWiki is a free, open-source extension to MediaWiki that  ...)
 	NOT-FOR-US: Semantic MediaWiki MediaWiki extension
 CVE-2026-77610 (Semantic MediaWiki is a free, open-source extension to MediaWiki that  ...)
@@ -1762,27 +1762,27 @@ CVE-2026-85078 (Sanic is an opensource python web server/framework. In version 2
 CVE-2026-85077 (Sanic is an opensource python web server/framework. Prior to version 2 ...)
 	NOT-FOR-US: Sanic
 CVE-2026-82761 (Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in tea ...)
-	TODO: check
+	NOT-FOR-US: team-alembic
 CVE-2026-82760 (Inefficient Algorithmic Complexity vulnerability in team-alembic AshAu ...)
-	TODO: check
+	NOT-FOR-US: team-alembic
 CVE-2026-82759 (Use of a One-Way Hash with a Predictable Salt vulnerability in team-al ...)
-	TODO: check
+	NOT-FOR-US: team-alembic
 CVE-2026-82723 (Insertion of Sensitive Information into Log File vulnerability in team ...)
-	TODO: check
+	NOT-FOR-US: team-alembic
 CVE-2026-82685 (Authorization Bypass Through User-Controlled Key vulnerability in team ...)
-	TODO: check
+	NOT-FOR-US: team-alembic
 CVE-2026-81868 (Steeltoe is an open source project that provides a collection of libra ...)
-	TODO: check
+	NOT-FOR-US: Steeltoe
 CVE-2026-81829 (A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by ...)
 	NOT-FOR-US: quarkus-smallrye-jwt
 CVE-2026-81637 (Insufficient Session Expiration vulnerability in team-alembic AshAuthe ...)
-	TODO: check
+	NOT-FOR-US: team-alembic
 CVE-2026-81632 (Use of HTTP Request With Sensitive Query String vulnerability in team- ...)
-	TODO: check
+	NOT-FOR-US: team-alembic
 CVE-2026-81516 (Steeltoe is an open source project that provides a collection of libra ...)
-	TODO: check
+	NOT-FOR-US: Steeltoe
 CVE-2026-81515 (Steeltoe is an open source project that provides a collection of libra ...)
-	TODO: check
+	NOT-FOR-US: Steeltoe
 CVE-2026-81481 (Dell OpenManage Server Administrator, versions prior to 11.1.0.3, cont ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-81480 (Dell OpenManage Server Administrator, versions prior to 11.1.0.3, cont ...)
@@ -1824,19 +1824,19 @@ CVE-2026-80356 (Dell OpenManage Server Administrator, versions prior to 11.1.0.3
 CVE-2026-80355 (Dell OpenManage Server Administrator, versions prior to 11.1.0.3, cont ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-80218 (Improper Authentication vulnerability in team-alembic AshAuthenticatio ...)
-	TODO: check
+	NOT-FOR-US: team-alembic
 CVE-2026-79752 (CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6 ...)
 	TODO: check
 CVE-2026-78528 (Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions.)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78428 (For users authenticated through SAML or OpenID Connect (OIDC), this vu ...)
-	TODO: check
+	NOT-FOR-US: NeuVector
 CVE-2026-78427 (The NeuVector admission webhook silently excludes containers from poli ...)
-	TODO: check
+	NOT-FOR-US: NeuVector
 CVE-2026-78426 (The NeuVector JWT verifier accepts noncanonical Base64URL encodings of ...)
-	TODO: check
+	NOT-FOR-US: NeuVector
 CVE-2026-78425 (Authorised users of outside applications behind the same corporate ide ...)
-	TODO: check
+	NOT-FOR-US: NeuVector
 CVE-2026-78296 (Insufficient Verification of Data Authenticity vulnerability in WP Man ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78295 (Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1. ...)
@@ -1844,9 +1844,9 @@ CVE-2026-78295 (Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <
 CVE-2026-78294 (Contributor Cross Site Scripting (XSS) in  Geo Mashup <= 1.13.21 versi ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78223 (Improper Verification of Cryptographic Signature vulnerability in team ...)
-	TODO: check
+	NOT-FOR-US: team-alembic
 CVE-2026-77614 (Opencast is a free, open-source platform to support the management of  ...)
-	TODO: check
+	NOT-FOR-US: Opencast
 CVE-2026-76834 (b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix ...)
 	TODO: check
 CVE-2026-76781 (A flaw was found in libxml2. A local user or an attacker providing a s ...)
@@ -4490,7 +4490,7 @@ CVE-2026-81869 (OpenTelemetry-Go is the Go implementation of OpenTelemetry. From
 CVE-2026-81866 (Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration updat ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-81546 (The Affinity by Canva application before 3.3.0 (September 2026 release ...)
-	TODO: check
+	NOT-FOR-US: Canva application
 CVE-2026-76646 (A remote attacker could cause excessive resource consumption by supply ...)
 	TODO: check
 CVE-2026-76460 (A vulnerability in an API of Cisco Identity Services Engine (ISE) coul ...)
@@ -5504,7 +5504,7 @@ CVE-2026-84501 (An unauthenticated attacker can inject arbitrary fake log lines
 CVE-2026-84439 (When audit logging is enabled (zookeeper.audit.enable=true), an unauth ...)
 	TODO: check
 CVE-2026-84408 (QND contains an improper access control vulnerability in a named pipe, ...)
-	TODO: check
+	NOT-FOR-US: QND
 CVE-2026-84397 (Adobe Experience Manager is affected by a stored Cross-Site Scripting  ...)
 	NOT-FOR-US: Adobe
 CVE-2026-84088 (The Xpro Addons \u2014 140+ Widgets for Elementor WordPress plugin bef ...)
@@ -6380,11 +6380,11 @@ CVE-2026-82993 (Vulnerability in the PeopleSoft Enterprise PeopleTools product o
 CVE-2026-82992 (Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CR ...)
 	NOT-FOR-US: Oracle
 CVE-2026-82964 (Improper preservation of permissions in the Avast sandbox minifilter d ...)
-	TODO: check
+	NOT-FOR-US: Avast
 CVE-2026-82567 (The myPRO Manager notification gateway exposes an unauthenticated HTTP ...)
-	TODO: check
+	NOT-FOR-US: myPRO Manager
 CVE-2026-82410 (Pocketbase is an open source web backend written in go. Prior to 0.22. ...)
-	TODO: check
+	NOT-FOR-US: Pocketbase
 CVE-2026-82399 (CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-H ...)
 	- coredns <itp> (bug #880676)
 CVE-2026-82311 (Apache Airflow FAB provider: resetting a user's password does not dele ...)
@@ -6404,13 +6404,13 @@ CVE-2026-81926 (Concrete CMS 9.4.0 through 9.5.2 did not escape colliding page p
 CVE-2026-81925 (Concrete CMS before 9.5.3 improperly neutralized a user-supplied custo ...)
 	NOT-FOR-US: Concrete CMS
 CVE-2026-81876 (HAPI FHIR is a complete implementation of the HL7 FHIR standard for he ...)
-	TODO: check
+	NOT-FOR-US: HAPI FHIR
 CVE-2026-81875 (HAPI FHIR is a complete implementation of the HL7 FHIR standard for he ...)
-	TODO: check
+	NOT-FOR-US: HAPI FHIR
 CVE-2026-81855 (A hardcoded cryptographic client authentication key vulnerability exis ...)
-	TODO: check
+	NOT-FOR-US: Wartsila
 CVE-2026-81326 (QND uses a hard-coded cryptographic key, which may allow a local attac ...)
-	TODO: check
+	NOT-FOR-US: QND
 CVE-2026-81176 (Svelte devalue is a JavaScript library that serializes values into str ...)
 	NOT-FOR-US: Sveltejs devalue
 CVE-2026-7514 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
@@ -6424,7 +6424,7 @@ CVE-2026-79708 (GitLab has remediated an issue in GitLab EE affecting all versio
 CVE-2026-79651 (A flaw was found in the theme localization endpoints of the keycloak-s ...)
 	- keycloak <itp> (bug #1088287)
 CVE-2026-79298 (An issue in Howyar Technologies Inc SysReturn Versions prior to 11.3.0 ...)
-	TODO: check
+	NOT-FOR-US: Howyar Technologies Inc SysReturn
 CVE-2026-78474 (The Ni WooCommerce Sales Report  WordPress plugin before 4.2.0 does no ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-78472 (The Ni WooCommerce Sales Report  WordPress plugin before 4.2.0 does no ...)
@@ -6432,7 +6432,7 @@ CVE-2026-78472 (The Ni WooCommerce Sales Report  WordPress plugin before 4.2.0 d
 CVE-2026-78252 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-78225 (A hardcoded cryptographic server key vulnerability exists in the deplo ...)
-	TODO: check
+	NOT-FOR-US: Wartsila
 CVE-2026-78088 (The Contest Gallery \u2013 Upload & Vote Photos, Media, Sell with PayP ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-77702 (The Eventin  WordPress plugin before 4.1.24 does not prevent the token ...)
@@ -6488,7 +6488,7 @@ CVE-2026-77403 (RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0,
 	NOTE: https://github.com/rabbitmq/amqp091-go/pull/353
 	NOTE: https://github.com/rabbitmq/amqp091-go/commit/2e0a919b89f337dbf58db2bb34ab206dac354a06 (v1.13.0)
 CVE-2026-77401 (Zope AccessControl provides a general security framework for use in Zo ...)
-	TODO: check
+	NOT-FOR-US: Zope
 CVE-2026-77360 (oRPC is an tool that helps build APIs that are end-to-end type-safe an ...)
 	TODO: check
 CVE-2026-77190 (On affected platforms running Arista EOS, an unauthenticated attacker  ...)
@@ -10849,7 +10849,7 @@ CVE-2026-90463 (A flaw was found in the sssd NSS responder. This input validatio
 CVE-2026-8821 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7 ...)
 	- mattermost-server <itp> (bug #823556)
 CVE-2026-89321 (Publishing limits the compressed size of a VSIX (ovsx.publishing.max-c ...)
-	TODO: check
+	NOT-FOR-US: Eclipse
 CVE-2026-89180 (EFence developed by Thinking Software Technology has a SQL Injection v ...)
 	NOT-FOR-US: Thinking Software Technology
 CVE-2026-89023 (ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contain ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a5d208de8694491b4fd5b5c9e67c82663b3ea81c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a5d208de8694491b4fd5b5c9e67c82663b3ea81c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260919/3dee2959/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list