[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sun Sep 20 22:18:30 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
72cf04ea by Moritz Muehlenhoff at 2026-09-20T23:17:57+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -100,7 +100,7 @@ CVE-2026-92253 (Improper link resolution before file access in the quarantine re
 CVE-2026-92252 (Incorrect default permissions in the installation directory of WatchDo ...)
 	NOT-FOR-US: Watchdog
 CVE-2026-90817 (An unauthenticated Remote Code Execution vulnerability was found in th ...)
-	TODO: check
+	NOT-FOR-US: REDCap
 CVE-2026-88857 (Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Cod ...)
 	NOT-FOR-US: Joomla
 CVE-2026-88856 (Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Cod ...)
@@ -1923,7 +1923,7 @@ CVE-2026-53554 (SQLBot is an intelligent Text-to-SQL system based on large langu
 CVE-2026-53534 (JabRef is a desktop application for managing BibTeX and BibLaTeX libra ...)
 	TODO: check
 CVE-2026-52483 (The ping diagnostics and other similar functions of the MitraStar GPT- ...)
-	TODO: check
+	NOT-FOR-US: MitraStar GPT-2741GNAC-N2-SV router
 CVE-2026-50291 (OpenImageIO is a toolset for reading, writing, and manipulating image  ...)
 	TODO: check
 CVE-2026-50285 (Pomerium is an identity and context-aware access proxy. Prior to 0.32. ...)
@@ -1937,7 +1937,7 @@ CVE-2026-50158 (yutu is an AI-powered toolkit for managing and growing YouTube c
 CVE-2026-50125 (MKP is a Model Context Protocol server for Kubernetes. Prior to 0.4.1, ...)
 	NOT-FOR-US: MKP
 CVE-2026-50022 (Metacat is data repository software that helps researchers preserve, s ...)
-	TODO: check
+	NOT-FOR-US: Metacat
 CVE-2026-49137
 	REJECTED
 CVE-2026-45726 (Omni manages Kubernetes on bare metal, virtual machines, or in a cloud ...)
@@ -2376,9 +2376,9 @@ CVE-2026-76781 (A flaw was found in libxml2. A local user or an attacker providi
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/c63248941708bc1d2e3a4292954593312212f6ca (master)
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/a34c084d7a576914c1424caabdaaf5e227bb39ef (v2.15.4)
 CVE-2026-75588 (Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate the URL ...)
-	TODO: check
+	NOT-FOR-US: Mattermost Desktop App
 CVE-2026-75523 (Steeltoe is an open source project that provides a collection of libra ...)
-	TODO: check
+	NOT-FOR-US: Steeltoe
 CVE-2026-74017 (Unauthenticated Broken Access Control in User Registration <= 5.2.7 ve ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-74005 (Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Seri ...)
@@ -2390,9 +2390,9 @@ CVE-2026-74000 (Contributor Broken Access Control in Simple Membership <= 4.8.2
 CVE-2026-73999 (Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16 ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-71568 (In BMCtest, Ironic is started without authentication and TLS for the d ...)
-	TODO: check
+	NOT-FOR-US: BMCtest
 CVE-2026-71538 (@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials  ...)
-	TODO: check
+	NOT-FOR-US: Node cyclonedx/cyclonedx-npm
 CVE-2026-69197 (Umbraco is an ASP.NET CMS. Prior to 13.15.1, 17.5.3, and 18.0.2, the C ...)
 	NOT-FOR-US: Umbraco CMS
 CVE-2026-66676 (Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 version ...)
@@ -2440,13 +2440,13 @@ CVE-2026-66571 (Unauthenticated Cross Site Request Forgery (CSRF) in Asset Clean
 CVE-2026-66269 (Dell OpenManage Server Administrator, versions prior to 11.1.0.3, cont ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-63472 (Vendure is an open-source headless commerce platform. Prior to 3.7.0,  ...)
-	TODO: check
+	NOT-FOR-US: Vendure
 CVE-2026-63461 (Vendure is an open-source headless commerce platform. Prior to 3.6.5,  ...)
-	TODO: check
+	NOT-FOR-US: Vendure
 CVE-2026-63460 (Vendure is an open-source headless commerce platform. Prior to 3.6.5,  ...)
-	TODO: check
+	NOT-FOR-US: Vendure
 CVE-2026-63459 (Vendure is an open-source headless commerce platform. Prior to 3.6.5,  ...)
-	TODO: check
+	NOT-FOR-US: Vendure
 CVE-2026-62108 (Unauthenticated Broken Authentication in Headless Single Sign On <= 1. ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62104 (Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 ...)
@@ -2454,23 +2454,23 @@ CVE-2026-62104 (Unauthenticated Remote Code Execution (RCE) in Migratico Lite <=
 CVE-2026-62101 (Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 ver ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61793 (Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0 ...)
-	TODO: check
+	NOT-FOR-US: Nuxt OG Image
 CVE-2026-61700 (MariaDB Connector/J is used to connect applications developed in Java  ...)
 	TODO: check
 CVE-2026-56795 (Dell Server Update Utility, versions prior to 26.07.01, contains an Un ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-55062 (uniget is a universal installer and updater for (container) tools. Pri ...)
-	TODO: check
+	NOT-FOR-US: uniget
 CVE-2026-55061 (uniget is a universal installer and updater for (container) tools. Pri ...)
-	TODO: check
+	NOT-FOR-US: uniget
 CVE-2026-54677 (Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1 ...)
-	TODO: check
+	NOT-FOR-US: Scoold
 CVE-2026-54676 (Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1 ...)
-	TODO: check
+	NOT-FOR-US: Scoold
 CVE-2026-54649 (punchin-email is a Cloudflare Email Worker that provides two-way role  ...)
-	TODO: check
+	NOT-FOR-US: punchin-email
 CVE-2026-54617 (GravitLauncher is an open-source Minecraft launcher based on sashok724 ...)
-	TODO: check
+	NOT-FOR-US: GravitLauncher
 CVE-2026-54587 (mport is the MidnightBSD Package Manager. Prior to 2.7.8, directory as ...)
 	NOT-FOR-US: mport
 CVE-2026-54586 (mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fe ...)
@@ -2496,35 +2496,35 @@ CVE-2026-54576 (mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_act
 CVE-2026-54575 (mport is the MidnightBSD Package Manager. Prior to 2.7.8, privileged p ...)
 	NOT-FOR-US: mport
 CVE-2026-54571 (ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library ...)
-	TODO: check
+	NOT-FOR-US: ESPAsyncWebServer
 CVE-2026-54551 (WireGuard Portal, or wg-portal, is a web-based configuration portal fo ...)
 	NOT-FOR-US: WireGuard Portal
 CVE-2026-54546 (CloudTAK is a browser-based Common Operating Picture and situational a ...)
-	TODO: check
+	NOT-FOR-US: CloudTAK
 CVE-2026-54524 (Frappe HR is an open-source human resources management solution (HRMS) ...)
 	NOT-FOR-US: Frappe HR
 CVE-2026-54504 (MCP Documentation Server is a local-first document management and sema ...)
-	TODO: check
+	NOT-FOR-US: MCP Documentation Server
 CVE-2026-54471 (Dell SmartFabric Manager, versions prior to 2.2.1, contains an Imprope ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-54451 (Elixir protobuf is a pure Elixir implementation of Google Protobuf. Fr ...)
 	NOT-FOR-US: Elixir protobuf
 CVE-2026-54446 (NetLicensing MCP Server is a natural-language interface that enables a ...)
-	TODO: check
+	NOT-FOR-US: NetLicensing MCP Server
 CVE-2026-54253 (TS3 Manager is modern web interface for maintaining Teamspeak3 servers ...)
-	TODO: check
+	NOT-FOR-US: TS3 Manager
 CVE-2026-54239 (Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP ...)
-	TODO: check
+	NOT-FOR-US: Faust.js
 CVE-2026-54053 (Many Notes is a Markdown note-taking web application designed for simp ...)
-	TODO: check
+	NOT-FOR-US: Many Notes
 CVE-2026-53681
 	REJECTED
 CVE-2026-53679
 	REJECTED
 CVE-2026-52852 (Traccar is an open source GPS tracking system. Prior to 6.14.0, an aut ...)
-	TODO: check
+	NOT-FOR-US: Traccar
 CVE-2026-52851 (Traccar is an open source GPS tracking system. Prior to 6.14.0, an aut ...)
-	TODO: check
+	NOT-FOR-US: Traccar
 CVE-2026-52836 (OpenDDS is an open source C++ implementation of the Object Management  ...)
 	TODO: check
 CVE-2026-52727 (lxc-ci contains continuous integration and image-build scripts for LXC ...)
@@ -2542,7 +2542,7 @@ CVE-2026-50606 (A vulnerability has been identified in the Acer System Monitorin
 CVE-2026-50605 (A vulnerability has been identified in the Acer Agent Service componen ...)
 	NOT-FOR-US: Acer
 CVE-2026-49292 (Kiwi TCMS is an open source test management system. Prior to 16.0, the ...)
-	TODO: check
+	NOT-FOR-US: Kiwi TCMS
 CVE-2026-47252 (Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5 ...)
 	TODO: check
 CVE-2026-28326 (SolarWinds Access Rights Manager was reported to be affected by an una ...)
@@ -2554,9 +2554,9 @@ CVE-2026-19477 (There is stack-based buffer overflow vulnerability recently disc
 CVE-2026-15688 (Incorrect Implementation of Authentication Algorithm Vulnerability in  ...)
 	NOT-FOR-US: Mitsubishi
 CVE-2026-14850 (The password reset funcionality is vulnerable to unauthorized account  ...)
-	TODO: check
+	NOT-FOR-US: MobiAPParc
 CVE-2026-12284 (Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IP ...)
-	TODO: check
+	NOT-FOR-US: Mattermost Desktop App
 CVE-2026-11874
 	REJECTED
 CVE-2026-8674 (Initializing the DNS stub resolver from an /etc/resolv.conf file, or a ...)
@@ -5247,15 +5247,15 @@ CVE-2026-20192 (As part of Cisco's ongoing commitment to proactive security and
 CVE-2026-20176 (A vulnerability in Cisco ISE could allow an authenticated, remote atta ...)
 	NOT-FOR-US: Cisco
 CVE-2026-20154 (A vulnerability in the system rate-limiting process for syslog message ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20135 (A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall ...)
 	NOT-FOR-US: Cisco
 CVE-2026-20130 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20121 (A vulnerability in the access control list (ACL) Object Group Search ( ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20120 (A vulnerability in the access control list (ACL) Object Group Search ( ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20072 (A vulnerability in the web-based management interface of Cisco ISE cou ...)
 	NOT-FOR-US: Cisco
 CVE-2026-20071 (A vulnerability in the SSID bring-your-own-device (BYOD) onboarding wo ...)
@@ -5267,7 +5267,7 @@ CVE-2025-56566 (MikroTik firmware 7.19.4 stores sensitive authentication credent
 CVE-2025-56565 (DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardwa ...)
 	NOT-FOR-US: TP-Link
 CVE-2025-56563 (A Server-Side Request Forgery vulnerability exists in sat_proxy.php in ...)
-	TODO: check
+	NOT-FOR-US: Zenith Satellite Tracker
 CVE-2025-15697 (The Dictionary WordPress plugin through 1.0 does not escape user input ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-XXXX [SQUID-2026:8]
@@ -6968,7 +6968,7 @@ CVE-2026-81176 (Svelte devalue is a JavaScript library that serializes values in
 CVE-2026-7514 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-79994 (The guest-to-host Unix-domain socket relay in Docker Sandboxes validat ...)
-	TODO: check
+	NOT-FOR-US: Docker Sandboxes
 CVE-2026-79993 (The `deleteContainer` opcode (0x14/20) is processed without verifying  ...)
 	- zookeeper 3.9.6-1 (bug #1148409)
 	NOTE: https://lists.apache.org/thread/9cw3rmrzhqpct26v8j18fy41bghlq8y5
@@ -7105,11 +7105,11 @@ CVE-2026-76825 (RestrictedPython is a tool that helps define a subset of the Pyt
 	NOTE: https://github.com/zopefoundation/RestrictedPython/security/advisories/GHSA-hp3v-5vw7-fx9w
 	NOTE: Fixed by: https://github.com/zopefoundation/RestrictedPython/commit/3b47440070b91f8807c2b2998aca99e94783639a (8.4)
 CVE-2026-76821 (OpenCTI is an open source platform for managing cyber threat intellige ...)
-	TODO: check
+	NOT-FOR-US: OpenCTI
 CVE-2026-76820 (OpenCTI is an open source platform for managing cyber threat intellige ...)
-	TODO: check
+	NOT-FOR-US: OpenCTI
 CVE-2026-76796 (The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect De ...)
-	TODO: check
+	NOT-FOR-US: Newell Brands DYMO Connect Desktop local web service
 CVE-2026-76707 (A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could al ...)
 	NOT-FOR-US: HPE
 CVE-2026-76706 (A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-W ...)
@@ -7277,7 +7277,7 @@ CVE-2026-73940 (Vulnerability in the Oracle Access Manager product of Oracle Fus
 CVE-2026-73926 (Vulnerability in the Oracle Access Manager product of Oracle Fusion Mi ...)
 	NOT-FOR-US: Oracle
 CVE-2026-73807 (The mySCADA myPRO Manager command API does not properly enforce authen ...)
-	TODO: check
+	NOT-FOR-US: mySCADA myPRO Manager
 CVE-2026-73469 (When specific platforms are using Arista EOS with a loose Unicast Reve ...)
 	NOT-FOR-US: Arista Networks
 CVE-2026-73468 (A specially crafted packet can cause the premature expiry of multicast ...)
@@ -7654,9 +7654,9 @@ CVE-2026-10149
 CVE-2026-10145
 	REJECTED
 CVE-2026-10144 (Rsbuild before 2.0.9 contains a command injection vulnerability that a ...)
-	TODO: check
+	NOT-FOR-US: Rsbuild
 CVE-2025-59953 (LMDeploy is a toolkit for compressing, deploying, and serving large la ...)
-	TODO: check
+	NOT-FOR-US: LMDeploy
 CVE-2025-43936 (Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an I ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2025-36591 (Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versio ...)
@@ -11019,9 +11019,9 @@ CVE-2026-54559 (PocketSphinx is a small speech recognizer. Prior to 5.1.1, the t
 CVE-2026-54447 (garminconnect is a Python 3 API wrapper for Garmin Connect that retrie ...)
 	TODO: check
 CVE-2026-54334 (UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structur ...)
-	TODO: check
+	NOT-FOR-US: uefi-firmware-parser
 CVE-2026-54333 (UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structur ...)
-	TODO: check
+	NOT-FOR-US: uefi-firmware-parser
 CVE-2026-54247 (Skipper is an HTTP router and reverse proxy for service composition. P ...)
 	TODO: check
 CVE-2026-54246 (Skipper is an HTTP router and reverse proxy for service composition. P ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/72cf04ea99b18d07a3e94f9f607d6969c70adcc0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/72cf04ea99b18d07a3e94f9f607d6969c70adcc0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260920/b5a10ff1/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list