[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Sun Sep 20 22:18:30 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
72cf04ea by Moritz Muehlenhoff at 2026-09-20T23:17:57+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -100,7 +100,7 @@ CVE-2026-92253 (Improper link resolution before file access in the quarantine re
CVE-2026-92252 (Incorrect default permissions in the installation directory of WatchDo ...)
NOT-FOR-US: Watchdog
CVE-2026-90817 (An unauthenticated Remote Code Execution vulnerability was found in th ...)
- TODO: check
+ NOT-FOR-US: REDCap
CVE-2026-88857 (Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Cod ...)
NOT-FOR-US: Joomla
CVE-2026-88856 (Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Cod ...)
@@ -1923,7 +1923,7 @@ CVE-2026-53554 (SQLBot is an intelligent Text-to-SQL system based on large langu
CVE-2026-53534 (JabRef is a desktop application for managing BibTeX and BibLaTeX libra ...)
TODO: check
CVE-2026-52483 (The ping diagnostics and other similar functions of the MitraStar GPT- ...)
- TODO: check
+ NOT-FOR-US: MitraStar GPT-2741GNAC-N2-SV router
CVE-2026-50291 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
TODO: check
CVE-2026-50285 (Pomerium is an identity and context-aware access proxy. Prior to 0.32. ...)
@@ -1937,7 +1937,7 @@ CVE-2026-50158 (yutu is an AI-powered toolkit for managing and growing YouTube c
CVE-2026-50125 (MKP is a Model Context Protocol server for Kubernetes. Prior to 0.4.1, ...)
NOT-FOR-US: MKP
CVE-2026-50022 (Metacat is data repository software that helps researchers preserve, s ...)
- TODO: check
+ NOT-FOR-US: Metacat
CVE-2026-49137
REJECTED
CVE-2026-45726 (Omni manages Kubernetes on bare metal, virtual machines, or in a cloud ...)
@@ -2376,9 +2376,9 @@ CVE-2026-76781 (A flaw was found in libxml2. A local user or an attacker providi
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/c63248941708bc1d2e3a4292954593312212f6ca (master)
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/a34c084d7a576914c1424caabdaaf5e227bb39ef (v2.15.4)
CVE-2026-75588 (Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate the URL ...)
- TODO: check
+ NOT-FOR-US: Mattermost Desktop App
CVE-2026-75523 (Steeltoe is an open source project that provides a collection of libra ...)
- TODO: check
+ NOT-FOR-US: Steeltoe
CVE-2026-74017 (Unauthenticated Broken Access Control in User Registration <= 5.2.7 ve ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-74005 (Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Seri ...)
@@ -2390,9 +2390,9 @@ CVE-2026-74000 (Contributor Broken Access Control in Simple Membership <= 4.8.2
CVE-2026-73999 (Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16 ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-71568 (In BMCtest, Ironic is started without authentication and TLS for the d ...)
- TODO: check
+ NOT-FOR-US: BMCtest
CVE-2026-71538 (@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials ...)
- TODO: check
+ NOT-FOR-US: Node cyclonedx/cyclonedx-npm
CVE-2026-69197 (Umbraco is an ASP.NET CMS. Prior to 13.15.1, 17.5.3, and 18.0.2, the C ...)
NOT-FOR-US: Umbraco CMS
CVE-2026-66676 (Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 version ...)
@@ -2440,13 +2440,13 @@ CVE-2026-66571 (Unauthenticated Cross Site Request Forgery (CSRF) in Asset Clean
CVE-2026-66269 (Dell OpenManage Server Administrator, versions prior to 11.1.0.3, cont ...)
NOT-FOR-US: Dell / EMC
CVE-2026-63472 (Vendure is an open-source headless commerce platform. Prior to 3.7.0, ...)
- TODO: check
+ NOT-FOR-US: Vendure
CVE-2026-63461 (Vendure is an open-source headless commerce platform. Prior to 3.6.5, ...)
- TODO: check
+ NOT-FOR-US: Vendure
CVE-2026-63460 (Vendure is an open-source headless commerce platform. Prior to 3.6.5, ...)
- TODO: check
+ NOT-FOR-US: Vendure
CVE-2026-63459 (Vendure is an open-source headless commerce platform. Prior to 3.6.5, ...)
- TODO: check
+ NOT-FOR-US: Vendure
CVE-2026-62108 (Unauthenticated Broken Authentication in Headless Single Sign On <= 1. ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-62104 (Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 ...)
@@ -2454,23 +2454,23 @@ CVE-2026-62104 (Unauthenticated Remote Code Execution (RCE) in Migratico Lite <=
CVE-2026-62101 (Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 ver ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-61793 (Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0 ...)
- TODO: check
+ NOT-FOR-US: Nuxt OG Image
CVE-2026-61700 (MariaDB Connector/J is used to connect applications developed in Java ...)
TODO: check
CVE-2026-56795 (Dell Server Update Utility, versions prior to 26.07.01, contains an Un ...)
NOT-FOR-US: Dell / EMC
CVE-2026-55062 (uniget is a universal installer and updater for (container) tools. Pri ...)
- TODO: check
+ NOT-FOR-US: uniget
CVE-2026-55061 (uniget is a universal installer and updater for (container) tools. Pri ...)
- TODO: check
+ NOT-FOR-US: uniget
CVE-2026-54677 (Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1 ...)
- TODO: check
+ NOT-FOR-US: Scoold
CVE-2026-54676 (Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1 ...)
- TODO: check
+ NOT-FOR-US: Scoold
CVE-2026-54649 (punchin-email is a Cloudflare Email Worker that provides two-way role ...)
- TODO: check
+ NOT-FOR-US: punchin-email
CVE-2026-54617 (GravitLauncher is an open-source Minecraft launcher based on sashok724 ...)
- TODO: check
+ NOT-FOR-US: GravitLauncher
CVE-2026-54587 (mport is the MidnightBSD Package Manager. Prior to 2.7.8, directory as ...)
NOT-FOR-US: mport
CVE-2026-54586 (mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fe ...)
@@ -2496,35 +2496,35 @@ CVE-2026-54576 (mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_act
CVE-2026-54575 (mport is the MidnightBSD Package Manager. Prior to 2.7.8, privileged p ...)
NOT-FOR-US: mport
CVE-2026-54571 (ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library ...)
- TODO: check
+ NOT-FOR-US: ESPAsyncWebServer
CVE-2026-54551 (WireGuard Portal, or wg-portal, is a web-based configuration portal fo ...)
NOT-FOR-US: WireGuard Portal
CVE-2026-54546 (CloudTAK is a browser-based Common Operating Picture and situational a ...)
- TODO: check
+ NOT-FOR-US: CloudTAK
CVE-2026-54524 (Frappe HR is an open-source human resources management solution (HRMS) ...)
NOT-FOR-US: Frappe HR
CVE-2026-54504 (MCP Documentation Server is a local-first document management and sema ...)
- TODO: check
+ NOT-FOR-US: MCP Documentation Server
CVE-2026-54471 (Dell SmartFabric Manager, versions prior to 2.2.1, contains an Imprope ...)
NOT-FOR-US: Dell / EMC
CVE-2026-54451 (Elixir protobuf is a pure Elixir implementation of Google Protobuf. Fr ...)
NOT-FOR-US: Elixir protobuf
CVE-2026-54446 (NetLicensing MCP Server is a natural-language interface that enables a ...)
- TODO: check
+ NOT-FOR-US: NetLicensing MCP Server
CVE-2026-54253 (TS3 Manager is modern web interface for maintaining Teamspeak3 servers ...)
- TODO: check
+ NOT-FOR-US: TS3 Manager
CVE-2026-54239 (Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP ...)
- TODO: check
+ NOT-FOR-US: Faust.js
CVE-2026-54053 (Many Notes is a Markdown note-taking web application designed for simp ...)
- TODO: check
+ NOT-FOR-US: Many Notes
CVE-2026-53681
REJECTED
CVE-2026-53679
REJECTED
CVE-2026-52852 (Traccar is an open source GPS tracking system. Prior to 6.14.0, an aut ...)
- TODO: check
+ NOT-FOR-US: Traccar
CVE-2026-52851 (Traccar is an open source GPS tracking system. Prior to 6.14.0, an aut ...)
- TODO: check
+ NOT-FOR-US: Traccar
CVE-2026-52836 (OpenDDS is an open source C++ implementation of the Object Management ...)
TODO: check
CVE-2026-52727 (lxc-ci contains continuous integration and image-build scripts for LXC ...)
@@ -2542,7 +2542,7 @@ CVE-2026-50606 (A vulnerability has been identified in the Acer System Monitorin
CVE-2026-50605 (A vulnerability has been identified in the Acer Agent Service componen ...)
NOT-FOR-US: Acer
CVE-2026-49292 (Kiwi TCMS is an open source test management system. Prior to 16.0, the ...)
- TODO: check
+ NOT-FOR-US: Kiwi TCMS
CVE-2026-47252 (Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5 ...)
TODO: check
CVE-2026-28326 (SolarWinds Access Rights Manager was reported to be affected by an una ...)
@@ -2554,9 +2554,9 @@ CVE-2026-19477 (There is stack-based buffer overflow vulnerability recently disc
CVE-2026-15688 (Incorrect Implementation of Authentication Algorithm Vulnerability in ...)
NOT-FOR-US: Mitsubishi
CVE-2026-14850 (The password reset funcionality is vulnerable to unauthorized account ...)
- TODO: check
+ NOT-FOR-US: MobiAPParc
CVE-2026-12284 (Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IP ...)
- TODO: check
+ NOT-FOR-US: Mattermost Desktop App
CVE-2026-11874
REJECTED
CVE-2026-8674 (Initializing the DNS stub resolver from an /etc/resolv.conf file, or a ...)
@@ -5247,15 +5247,15 @@ CVE-2026-20192 (As part of Cisco's ongoing commitment to proactive security and
CVE-2026-20176 (A vulnerability in Cisco ISE could allow an authenticated, remote atta ...)
NOT-FOR-US: Cisco
CVE-2026-20154 (A vulnerability in the system rate-limiting process for syslog message ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20135 (A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall ...)
NOT-FOR-US: Cisco
CVE-2026-20130 (As part of Cisco's ongoing commitment to proactive security and produc ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20121 (A vulnerability in the access control list (ACL) Object Group Search ( ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20120 (A vulnerability in the access control list (ACL) Object Group Search ( ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20072 (A vulnerability in the web-based management interface of Cisco ISE cou ...)
NOT-FOR-US: Cisco
CVE-2026-20071 (A vulnerability in the SSID bring-your-own-device (BYOD) onboarding wo ...)
@@ -5267,7 +5267,7 @@ CVE-2025-56566 (MikroTik firmware 7.19.4 stores sensitive authentication credent
CVE-2025-56565 (DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardwa ...)
NOT-FOR-US: TP-Link
CVE-2025-56563 (A Server-Side Request Forgery vulnerability exists in sat_proxy.php in ...)
- TODO: check
+ NOT-FOR-US: Zenith Satellite Tracker
CVE-2025-15697 (The Dictionary WordPress plugin through 1.0 does not escape user input ...)
NOT-FOR-US: WordPress plugin
CVE-2026-XXXX [SQUID-2026:8]
@@ -6968,7 +6968,7 @@ CVE-2026-81176 (Svelte devalue is a JavaScript library that serializes values in
CVE-2026-7514 (GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-79994 (The guest-to-host Unix-domain socket relay in Docker Sandboxes validat ...)
- TODO: check
+ NOT-FOR-US: Docker Sandboxes
CVE-2026-79993 (The `deleteContainer` opcode (0x14/20) is processed without verifying ...)
- zookeeper 3.9.6-1 (bug #1148409)
NOTE: https://lists.apache.org/thread/9cw3rmrzhqpct26v8j18fy41bghlq8y5
@@ -7105,11 +7105,11 @@ CVE-2026-76825 (RestrictedPython is a tool that helps define a subset of the Pyt
NOTE: https://github.com/zopefoundation/RestrictedPython/security/advisories/GHSA-hp3v-5vw7-fx9w
NOTE: Fixed by: https://github.com/zopefoundation/RestrictedPython/commit/3b47440070b91f8807c2b2998aca99e94783639a (8.4)
CVE-2026-76821 (OpenCTI is an open source platform for managing cyber threat intellige ...)
- TODO: check
+ NOT-FOR-US: OpenCTI
CVE-2026-76820 (OpenCTI is an open source platform for managing cyber threat intellige ...)
- TODO: check
+ NOT-FOR-US: OpenCTI
CVE-2026-76796 (The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect De ...)
- TODO: check
+ NOT-FOR-US: Newell Brands DYMO Connect Desktop local web service
CVE-2026-76707 (A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could al ...)
NOT-FOR-US: HPE
CVE-2026-76706 (A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-W ...)
@@ -7277,7 +7277,7 @@ CVE-2026-73940 (Vulnerability in the Oracle Access Manager product of Oracle Fus
CVE-2026-73926 (Vulnerability in the Oracle Access Manager product of Oracle Fusion Mi ...)
NOT-FOR-US: Oracle
CVE-2026-73807 (The mySCADA myPRO Manager command API does not properly enforce authen ...)
- TODO: check
+ NOT-FOR-US: mySCADA myPRO Manager
CVE-2026-73469 (When specific platforms are using Arista EOS with a loose Unicast Reve ...)
NOT-FOR-US: Arista Networks
CVE-2026-73468 (A specially crafted packet can cause the premature expiry of multicast ...)
@@ -7654,9 +7654,9 @@ CVE-2026-10149
CVE-2026-10145
REJECTED
CVE-2026-10144 (Rsbuild before 2.0.9 contains a command injection vulnerability that a ...)
- TODO: check
+ NOT-FOR-US: Rsbuild
CVE-2025-59953 (LMDeploy is a toolkit for compressing, deploying, and serving large la ...)
- TODO: check
+ NOT-FOR-US: LMDeploy
CVE-2025-43936 (Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an I ...)
NOT-FOR-US: Dell / EMC
CVE-2025-36591 (Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versio ...)
@@ -11019,9 +11019,9 @@ CVE-2026-54559 (PocketSphinx is a small speech recognizer. Prior to 5.1.1, the t
CVE-2026-54447 (garminconnect is a Python 3 API wrapper for Garmin Connect that retrie ...)
TODO: check
CVE-2026-54334 (UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structur ...)
- TODO: check
+ NOT-FOR-US: uefi-firmware-parser
CVE-2026-54333 (UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structur ...)
- TODO: check
+ NOT-FOR-US: uefi-firmware-parser
CVE-2026-54247 (Skipper is an HTTP router and reverse proxy for service composition. P ...)
TODO: check
CVE-2026-54246 (Skipper is an HTTP router and reverse proxy for service composition. P ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/72cf04ea99b18d07a3e94f9f607d6969c70adcc0
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/72cf04ea99b18d07a3e94f9f607d6969c70adcc0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260920/b5a10ff1/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list