[Git][security-tracker-team/security-tracker][master] 2 commits: NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sat Sep 19 20:31:25 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f9f09cdd by Moritz Muehlenhoff at 2026-09-19T21:27:07+02:00
NFUs

- - - - -
4e425daf by Moritz Muehlenhoff at 2026-09-19T21:27:09+02:00
phppgadmin issues forwarded upstream

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -226,7 +226,7 @@ CVE-2026-76554 (The WP Import Export Lite WordPress plugin before 3.9.35 does no
 CVE-2026-75895 (In libsmpp35 from 0.1.0 through 1.8.0 out of bound read issue was foun ...)
 	TODO: check
 CVE-2026-75885 (A flaw was found in the OpenShift console. Unauthenticated access to t ...)
-	TODO: check
+	NOT-FOR-US: OpenShift
 CVE-2026-75878 (IBM Sterling File Gateway could allow a remote attacker to bypass auth ...)
 	NOT-FOR-US: IBM
 CVE-2026-71855 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
@@ -239,11 +239,11 @@ CVE-2026-71418 (Suricata is a network Intrusion Detection System, Intrusion Prev
 	NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-xjgq-3qw4-jp5f
 	NOTE: Fixed by: https://github.com/OISF/suricata/commit/26c26dea84f00de95151a0e16d21c1fcafac9648 (suricata-8.0.6)
 CVE-2026-68928 (Acode is a powerful text and code editor for Android. From 1.11.6 unti ...)
-	TODO: check
+	NOT-FOR-US: ACode
 CVE-2026-63647 (CordysCRM is an open source AI-powered customer relationship managemen ...)
-	TODO: check
+	NOT-FOR-US: CordysCRM
 CVE-2026-63646 (CordysCRM is an open source AI-powered customer relationship managemen ...)
-	TODO: check
+	NOT-FOR-US: CordysCRM
 CVE-2026-63452 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
 	- suricata 1:8.0.6-1
 	NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-j9cx-w9xm-5x84
@@ -322,9 +322,9 @@ CVE-2026-61781 (pg_partman is a PostgreSQL extension that manages partitioned ta
 	NOTE: https://github.com/pgpartman/pg_partman/security/advisories/GHSA-742w-3j7c-qwvp
 	NOTE: Fixed by: https://github.com/pgpartman/pg_partman/commit/ba9405542acf24dd881845b935cab8b165854361 (v5.5.0)
 CVE-2026-61670 (microsandbox is an easy, fast, local-first microVM runtime and library ...)
-	TODO: check
+	NOT-FOR-US: microsandbox
 CVE-2026-52745 (CordysCRM is an open source AI-powered customer relationship managemen ...)
-	TODO: check
+	NOT-FOR-US: CordysCRM
 CVE-2026-19860 (The JetFormBuilder \u2014 Dynamic Blocks Form Builder WordPress plugin ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-18869 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
@@ -370,7 +370,7 @@ CVE-2026-11539 (IBM WebSphere Application Server 9.0 and 8.5 is affected by an a
 CVE-2025-15698 (The Business Name Generator WordPress plugin through 1.3 does not sani ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2017-20284 (Caucho Resin contains a path traversal vulnerability in the documentat ...)
-	TODO: check
+	NOT-FOR-US: Caucho Resin
 CVE-2026-93854 (In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce o ...)
 	- blazar <unfixed> (bug #1148408)
 	NOTE: https://launchpad.net/bugs/2162719
@@ -774,7 +774,7 @@ CVE-2026-81179 (SysReptor is a fully customizable pentest reporting platform. Pr
 CVE-2026-81178 (SysReptor is a fully customizable pentest reporting platform. Prior to ...)
 	NOT-FOR-US: SysReptor
 CVE-2026-7006 (Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build ...)
-	TODO: check
+	NOT-FOR-US: Sublime
 CVE-2026-79294 (Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2 ...)
 	NOT-FOR-US: Moonshot AI Kimi
 CVE-2026-77960 (Bransys ELDis shipped with hardcoded MQTT credentials, which will gran ...)
@@ -829,11 +829,11 @@ CVE-2026-75883 (The code in pppd that formats a response to a PEAP Request packe
 CVE-2026-75157 (Apache Airflow's asset queued-events DELETE endpoints checked the call ...)
 	TODO: check
 CVE-2026-75031 (In the interchange/interchange project, a critical remote code executi ...)
-	TODO: check
+	NOT-FOR-US: Interchange
 CVE-2026-73863 (NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's broker-side MQTT  ...)
-	TODO: check
+	NOT-FOR-US: NanoMQ
 CVE-2026-71537 (Paymenter is a free and open-source webshop solution for management of ...)
-	TODO: check
+	NOT-FOR-US: Paymenter
 CVE-2026-6205 (An external control of file name or path vulnerability in Upload API i ...)
 	NOT-FOR-US: Synology
 CVE-2026-68914 (Mojolicious is a real-time web framework for Perl. Prior to 9.47, the  ...)
@@ -176490,6 +176490,7 @@ CVE-2020-37182 (Redir 3.3 contains a stack overflow vulnerability in the doproxy
 	[bookworm] - redir <postponed> (Minor issue; the overflowed connect_str is only ever set from the operator's own -x/--connect command line argument, never from network input)
 	[bullseye] - redir <postponed> (Minor issue; the overflowed connect_str is only ever set from the operator's own -x/--connect command line argument, never from network input)
 	NOTE: https://www.exploit-db.com/exploits/47919
+	NOTE: https://github.com/troglobit/redir/issues/15
 	NOTE: Fixed by: https://github.com/troglobit/redir/commit/372c792e9d320012490d8eca170f0462a92013fa (master)
 CVE-2020-37181 (Torrent FLV Converter 1.51 Build 117 contains a stack overflow vulnera ...)
 	NOT-FOR-US: Torrent FLV Converter
@@ -210633,21 +210634,21 @@ CVE-2025-62294 (SOPlanning is vulnerable to Predictable Generation of Password R
 CVE-2025-62293 (SOPlanning is vulnerable to Broken Access Control in /statusendpoint.  ...)
 	NOT-FOR-US: SOPlanning
 CVE-2025-60799 (phpPgAdmin 7.13.0 and earlier contains an incorrect access control vul ...)
-	- phppgadmin <undetermined>
+	- phppgadmin <unfixed>
 	NOTE: https://github.com/pr0wl1ng/security-advisories/blob/main/CVE-2025-60799.md
-	TODO: check, possibly not reported upstream
+	NOTE: https://github.com/ReimuHakurei/phpPgAdmin/issues/38
 CVE-2025-60798 (phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ...)
-	- phppgadmin <undetermined>
-	NOTE: https://github.com/pr0wl1ng/security-advisories/blob/main/CVE-2025-60797.md
-	TODO: check, possibly not reported upstream
+	- phppgadmin <unfixed>
+	NOTE: https://github.com/pr0wl1ng/security-advisories/blob/main/CVE-2025-60798.md
+	NOTE: https://github.com/ReimuHakurei/phpPgAdmin/issues/38
 CVE-2025-60797 (phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ...)
-	- phppgadmin <undetermined>
+	- phppgadmin <unfixed>
 	NOTE: https://github.com/pr0wl1ng/security-advisories/blob/main/CVE-2025-60797.md
-	TODO: check, possibly not reported upstream
+	NOTE: https://github.com/ReimuHakurei/phpPgAdmin/issues/38
 CVE-2025-60796 (phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting ( ...)
-	- phppgadmin <undetermined>
+	- phppgadmin <unfixed>
 	NOTE: https://github.com/pr0wl1ng/security-advisories/blob/main/CVE-2025-60796.md
-	TODO: check, possibly not reported upstream
+	NOTE: https://github.com/ReimuHakurei/phpPgAdmin/issues/38
 CVE-2025-60794 (Session tokens and passwords in couch-auth 0.21.2 are stored in JavaSc ...)
 	NOT-FOR-US: couch-auth
 CVE-2025-60738 (An issue in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and b ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/9eb6faca0b3bed828f74d0c992edfedfd1584361...4e425daf64d5dd271314e0051f47d161111a6c7d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/9eb6faca0b3bed828f74d0c992edfedfd1584361...4e425daf64d5dd271314e0051f47d161111a6c7d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260919/b994017f/attachment.htm>


More information about the debian-security-tracker-commits mailing list