[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sun Sep 20 19:21:46 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f2ad0668 by Moritz Muehlenhoff at 2026-09-20T20:21:21+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1061,7 +1061,7 @@ CVE-2026-75892 (In osmo-ggsn 1.14.0 an out of bounds write issue was found in th
 CVE-2026-75883 (The code in pppd that formats a response to a PEAP Request packet in p ...)
 	TODO: check
 CVE-2026-75157 (Apache Airflow's asset queued-events DELETE endpoints checked the call ...)
-	TODO: check
+	- airflow <itp> (bug #819700)
 CVE-2026-75031 (In the interchange/interchange project, a critical remote code executi ...)
 	NOT-FOR-US: Interchange
 CVE-2026-73863 (NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's broker-side MQTT  ...)
@@ -1129,9 +1129,9 @@ CVE-2026-63419 (OpenImageIO is a toolset for reading, writing, and manipulating
 	NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/5268
 	NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/9cda48b150294c7f024e680a6c9b0402e50f4816 (v3.2.0.3-beta1)
 CVE-2026-63406 (AnyCable is a realtime server for reliable two-way communication that  ...)
-	TODO: check
+	NOT-FOR-US: AnyCable
 CVE-2026-63405 (AnyCable is a realtime server for reliable two-way communication that  ...)
-	TODO: check
+	NOT-FOR-US: AnyCable
 CVE-2026-63349 (AnyIO is a high level asynchronous concurrency and networking framewor ...)
 	TODO: check
 CVE-2026-63199 (Perses is an open-source dashboard and visualization project for obser ...)
@@ -1139,23 +1139,23 @@ CVE-2026-63199 (Perses is an open-source dashboard and visualization project for
 CVE-2026-62943 (btrbk is a tool for creating snapshots and remote backups of Btrfs sub ...)
 	TODO: check
 CVE-2026-62282 (OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, Open ...)
-	TODO: check
+	NOT-FOR-US: OpenCVE
 CVE-2026-62279 (LubeLogger is a self-hosted, open-source, web-based vehicle maintenanc ...)
 	NOT-FOR-US: LubeLogger
 CVE-2026-62278 (LubeLogger is a self-hosted, open-source, web-based vehicle maintenanc ...)
 	NOT-FOR-US: LubeLogger
 CVE-2026-61833 (zot is a container image and artifact registry based on the Open Conta ...)
-	TODO: check
+	NOT-FOR-US: zot
 CVE-2026-61795 (Capsule is a multi-tenancy and policy-based framework for Kubernetes.  ...)
-	TODO: check
+	NOT-FOR-US: Capsule
 CVE-2026-61794 (Capsule is a multi-tenancy and policy-based framework for Kubernetes.  ...)
-	TODO: check
+	NOT-FOR-US: Capsule
 CVE-2026-61682 (kcp is a Kubernetes-like control plane for form-factors and use-cases  ...)
-	TODO: check
+	NOT-FOR-US: kcp
 CVE-2026-61672 (Capsule is a multi-tenancy and policy-based framework for Kubernetes.  ...)
-	TODO: check
+	NOT-FOR-US: Capsule
 CVE-2026-61633 (NanoMQ is an MQTT broker. Prior to 0.24.14, the NanoMQ client function ...)
-	TODO: check
+	NOT-FOR-US: NanoMQ
 CVE-2026-60115
 	REJECTED
 CVE-2026-59956 (OpenImageIO is a toolset for reading, writing, and manipulating image  ...)
@@ -1169,7 +1169,7 @@ CVE-2026-59181 (OpenImageIO is a toolset for reading, writing, and manipulating
 	NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/5250
 	NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/908f22f5528e88e5e96184c194caa26b54b2b85f (v3.2.0.3-beta1)
 CVE-2026-59163 (Mnemosyne is a memory layer for artificial intelligence agents. Prior  ...)
-	TODO: check
+	NOT-FOR-US: Mnemosyne
 CVE-2026-59156 (OpenImageIO is a toolset for reading, writing, and manipulating image  ...)
 	- openimageio <unfixed>
 	NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-xvwr-x6ch-v2fq
@@ -1192,7 +1192,7 @@ CVE-2026-54147 (http4k is a functional toolkit for Kotlin HTTP applications. Pri
 CVE-2026-4036 (An improper neutralization of special elements used in an SQL command  ...)
 	NOT-FOR-US: Synology
 CVE-2026-44639 (NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's MQTT v5 property  ...)
-	TODO: check
+	NOT-FOR-US: NanoMQ
 CVE-2026-40539 (An improper certificate validation vulnerability in Email API in Synol ...)
 	NOT-FOR-US: Synology
 CVE-2026-40538 (An improper restriction of excessive authentication attempts vulnerabi ...)
@@ -1214,15 +1214,15 @@ CVE-2026-40531 (An integer overflow or wraparound vulnerability in File Operatio
 CVE-2026-40530 (An improper neutralization of CRLF sequences ('CRLF injection') vulner ...)
 	NOT-FOR-US: Synology
 CVE-2026-33625 (LMDeploy is a toolkit for compressing, deploying, and serving large la ...)
-	TODO: check
+	NOT-FOR-US: LMDeploy
 CVE-2026-32641 (Parseable is a log analytics platform built for high-volume data inges ...)
-	TODO: check
+	NOT-FOR-US: Parseable
 CVE-2026-28199 (An authenticated user with access to the NetBackup Flex OS management  ...)
-	TODO: check
+	NOT-FOR-US: NetBackup Flex OS
 CVE-2026-28198 (An authenticated, low-privileged user with access to the NetBackup Fle ...)
-	TODO: check
+	NOT-FOR-US: NetBackup Flex OS
 CVE-2026-28197 (An authenticated, low-privileged user with access to the NetBackup Fle ...)
-	TODO: check
+	NOT-FOR-US: NetBackup Flex OS
 CVE-2026-25684 (A file type attribution issue in Zscaler Internet Access File Type Con ...)
 	NOT-FOR-US: Zscaler
 CVE-2026-21848 (HCL BigFix Service Management is affected by a Security Misconfigurati ...)
@@ -1310,7 +1310,7 @@ CVE-2026-10853 (IBM MQ could allow an authenticated attacker with cluster access
 CVE-2026-10841 (IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable  ...)
 	NOT-FOR-US: IBM
 CVE-2026-10832 (A flaw was found in the DERDecoder class within wildfly-elytron-asn1.  ...)
-	TODO: check
+	NOT-FOR-US: wildfly-elytron-asn1
 CVE-2026-10751 (IBM MQ Java and JMS client libraries could allow an authenticated atta ...)
 	NOT-FOR-US: IBM
 CVE-2026-10747 (IBM MQ Appliance could allow a remote attacker to cause a denial of se ...)
@@ -1698,7 +1698,7 @@ CVE-2026-54752 (NetBox Device Type Library is a collection of community-sourced
 CVE-2026-54734 (Prebid Server Java is the Java version of Prebid Server. Prior to 3.43 ...)
 	NOT-FOR-US: Prebid Server Java
 CVE-2026-54716 (Valhalla is an open source routing engine and accompanying libraries f ...)
-	TODO: check
+	NOT-FOR-US: Valhalla
 CVE-2026-54692 (SAIL is a cross-platform library for loading and saving images with su ...)
 	TODO: check
 CVE-2026-54671 (WeGIA is a web manager for charitable institutions. Prior to 3.8.5, We ...)
@@ -1749,15 +1749,15 @@ CVE-2026-54596 (ITFlow provides an IT documentation, ticketing and accounting sy
 CVE-2026-54594 (OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June ...)
 	NOT-FOR-US: OmniBlocks
 CVE-2026-54565 (rhwp is an HWP viewer and editor implemented in Rust and WebAssembly.  ...)
-	TODO: check
+	NOT-FOR-US: rhwp
 CVE-2026-54521 (FairEmail is a fully featured, open source, privacy-friendly email app ...)
-	TODO: check
+	NOT-FOR-US: FairEmail
 CVE-2026-54520 (AI Agent Automation is a modular AI agent workflow automation platform ...)
 	NOT-FOR-US: AI Agent Automation
 CVE-2026-54519 (AI Agent Automation is a modular AI agent workflow automation platform ...)
 	NOT-FOR-US: AI Agent Automation
 CVE-2026-54510 (Speakr is a personal, self-hosted web application designed for transcr ...)
-	TODO: check
+	NOT-FOR-US: Speakr
 CVE-2026-54507 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
 	NOT-FOR-US: Vvveb
 CVE-2026-54506 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
@@ -1775,7 +1775,7 @@ CVE-2026-54354 (MapServer is a system for developing web-based GIS applications.
 CVE-2026-54343 (Frappe Learning Management System (LMS) is a learning system that help ...)
 	NOT-FOR-US: FRappe
 CVE-2026-54339 (Glean is a self-hosted RSS reader and personal knowledge management to ...)
-	TODO: check
+	NOT-FOR-US: Glean
 CVE-2026-54237 (Wavelog is web-based amateur radio logging software. From 1.8 until 2. ...)
 	TODO: check
 CVE-2026-53557 (SQLBot is an intelligent Text-to-SQL system based on large language mo ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f2ad06682963b87f4e8a4258d1ca79ba96eb350f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f2ad06682963b87f4e8a4258d1ca79ba96eb350f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260920/18d5b92f/attachment.htm>


More information about the debian-security-tracker-commits mailing list