[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Sep 21 19:18:47 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
efa46235 by Salvatore Bonaccorso at 2026-09-21T20:18:12+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -11116,27 +11116,27 @@ CVE-2026-55244 (ASTEVAL is an evaluator of Python expressions and statements. Pr
 	NOTE: Fixed by: https://github.com/lmfit/asteval/commit/9c625b3674f8d05f206708bb85afca17a87694a4 (1.0.9)
 	NOTE: Fixed by: https://github.com/lmfit/asteval/commit/c49c99a67acb63eb7410231932250bd820380e45 (1.0.9)
 CVE-2026-55209 (resdata is software for reading and writing result files from the Ecli ...)
-	TODO: check
+	NOT-FOR-US: resdata
 CVE-2026-55093 (Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX infer ...)
-	TODO: check
+	NOT-FOR-US: Tract
 CVE-2026-54632 (SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET. Prior t ...)
-	TODO: check
+	NOT-FOR-US: SIPSorcery
 CVE-2026-54629 (Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5 ...)
-	TODO: check
+	NOT-FOR-US: Anyquery
 CVE-2026-54628 (Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5 ...)
-	TODO: check
+	NOT-FOR-US: Anyquery
 CVE-2026-54559 (PocketSphinx is a small speech recognizer. Prior to 5.1.1, the trie la ...)
-	TODO: check
+	NOT-FOR-US: PocketSphinx
 CVE-2026-54447 (garminconnect is a Python 3 API wrapper for Garmin Connect that retrie ...)
-	TODO: check
+	NOT-FOR-US: garminconnect
 CVE-2026-54334 (UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structur ...)
 	NOT-FOR-US: uefi-firmware-parser
 CVE-2026-54333 (UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structur ...)
 	NOT-FOR-US: uefi-firmware-parser
 CVE-2026-54247 (Skipper is an HTTP router and reverse proxy for service composition. P ...)
-	TODO: check
+	NOT-FOR-US: Zalando Skipper
 CVE-2026-54246 (Skipper is an HTTP router and reverse proxy for service composition. P ...)
-	TODO: check
+	NOT-FOR-US: Zalando Skipper
 CVE-2026-53719 (Envoy Gateway is an open source project for managing Envoy Proxy as a  ...)
 	- envoyproxy <itp> (bug #987544)
 CVE-2026-53718 (Envoy Gateway is an open source project for managing Envoy Proxy as a  ...)
@@ -11854,9 +11854,9 @@ CVE-2026-55236 (langgraph-api implements the LangGraph API for rapid development
 CVE-2026-55235 (langgraph-api implements the LangGraph API for rapid development and t ...)
 	NOT-FOR-US: langgraph-api
 CVE-2026-55102 (hashi-vault-js is a Node.js module for interacting with the HashiCorp  ...)
-	TODO: check
+	NOT-FOR-US: hashi-vault-js Node.js module
 CVE-2026-55091 (flat-to-nested converts a hierarchy from a flat representation to a ne ...)
-	TODO: check
+	NOT-FOR-US: flat-to-nested
 CVE-2026-55073 (WeasyPrint helps web developers to create PDF documents. Prior to 70.0 ...)
 	- weasyprint <unfixed> (bug #1148178)
 	[trixie] - weasyprint <no-dsa> (Minor issue)
@@ -11865,15 +11865,15 @@ CVE-2026-55073 (WeasyPrint helps web developers to create PDF documents. Prior t
 CVE-2026-55072 (Pimcore is an Open Source Data & Experience Management Platform. Prior ...)
 	NOT-FOR-US: Pimcore
 CVE-2026-54723 (devpi is a Python package index staging server and packaging, testing, ...)
-	TODO: check
+	NOT-FOR-US: devpi
 CVE-2026-54567 (Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6 ...)
-	TODO: check
+	NOT-FOR-US: Flask-Reuploaded
 CVE-2026-54542 (Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol ba ...)
-	TODO: check
+	NOT-FOR-US: Nimiq
 CVE-2026-54541 (Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol ba ...)
-	TODO: check
+	NOT-FOR-US: Nimiq
 CVE-2026-54529 (SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to ...)
-	TODO: check
+	NOT-FOR-US: SQLAdmin
 CVE-2026-54452 (safeurl is a server-side request forgery protection library. Prior to  ...)
 	TODO: check
 CVE-2026-54182 (backpack/crud provides Create, Read, Update & Delete (CRUD) functions  ...)
@@ -11891,13 +11891,13 @@ CVE-2026-54176 (backpack/crud provides Create, Read, Update & Delete (CRUD) func
 CVE-2026-54175 (backpack/crud provides Create, Read, Update & Delete (CRUD) functions  ...)
 	NOT-FOR-US: backpack/crud
 CVE-2026-54156 (node-opcua is an OPC UA implementation for TypeScript and Node.js. Pri ...)
-	TODO: check
+	NOT-FOR-US: node-opcua/node-opcua
 CVE-2026-54155 (node-opcua is an OPC UA implementation for TypeScript and Node.js. Pri ...)
-	TODO: check
+	NOT-FOR-US: node-opcua/node-opcua
 CVE-2026-54150 (next-video is a library for adding video to Next.js applications. Prio ...)
 	NOT-FOR-US: Next.js
 CVE-2026-54087 (EasyAdmin is a fast and modern admin generator for Symfony application ...)
-	TODO: check
+	NOT-FOR-US: EasyAdminEasyAdmin
 CVE-2026-53752 (docx4j is an open source Java library for creating, editing, and savin ...)
 	TODO: check
 CVE-2026-53708 (ContextForge is an AI gateway, registry, and proxy that provides centr ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/efa462356a94707b8f6b87efdadecd1cf777d5ff

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/efa462356a94707b8f6b87efdadecd1cf777d5ff
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260921/636acd8e/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list