[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Sep 21 19:18:47 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
efa46235 by Salvatore Bonaccorso at 2026-09-21T20:18:12+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -11116,27 +11116,27 @@ CVE-2026-55244 (ASTEVAL is an evaluator of Python expressions and statements. Pr
NOTE: Fixed by: https://github.com/lmfit/asteval/commit/9c625b3674f8d05f206708bb85afca17a87694a4 (1.0.9)
NOTE: Fixed by: https://github.com/lmfit/asteval/commit/c49c99a67acb63eb7410231932250bd820380e45 (1.0.9)
CVE-2026-55209 (resdata is software for reading and writing result files from the Ecli ...)
- TODO: check
+ NOT-FOR-US: resdata
CVE-2026-55093 (Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX infer ...)
- TODO: check
+ NOT-FOR-US: Tract
CVE-2026-54632 (SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET. Prior t ...)
- TODO: check
+ NOT-FOR-US: SIPSorcery
CVE-2026-54629 (Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5 ...)
- TODO: check
+ NOT-FOR-US: Anyquery
CVE-2026-54628 (Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5 ...)
- TODO: check
+ NOT-FOR-US: Anyquery
CVE-2026-54559 (PocketSphinx is a small speech recognizer. Prior to 5.1.1, the trie la ...)
- TODO: check
+ NOT-FOR-US: PocketSphinx
CVE-2026-54447 (garminconnect is a Python 3 API wrapper for Garmin Connect that retrie ...)
- TODO: check
+ NOT-FOR-US: garminconnect
CVE-2026-54334 (UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structur ...)
NOT-FOR-US: uefi-firmware-parser
CVE-2026-54333 (UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structur ...)
NOT-FOR-US: uefi-firmware-parser
CVE-2026-54247 (Skipper is an HTTP router and reverse proxy for service composition. P ...)
- TODO: check
+ NOT-FOR-US: Zalando Skipper
CVE-2026-54246 (Skipper is an HTTP router and reverse proxy for service composition. P ...)
- TODO: check
+ NOT-FOR-US: Zalando Skipper
CVE-2026-53719 (Envoy Gateway is an open source project for managing Envoy Proxy as a ...)
- envoyproxy <itp> (bug #987544)
CVE-2026-53718 (Envoy Gateway is an open source project for managing Envoy Proxy as a ...)
@@ -11854,9 +11854,9 @@ CVE-2026-55236 (langgraph-api implements the LangGraph API for rapid development
CVE-2026-55235 (langgraph-api implements the LangGraph API for rapid development and t ...)
NOT-FOR-US: langgraph-api
CVE-2026-55102 (hashi-vault-js is a Node.js module for interacting with the HashiCorp ...)
- TODO: check
+ NOT-FOR-US: hashi-vault-js Node.js module
CVE-2026-55091 (flat-to-nested converts a hierarchy from a flat representation to a ne ...)
- TODO: check
+ NOT-FOR-US: flat-to-nested
CVE-2026-55073 (WeasyPrint helps web developers to create PDF documents. Prior to 70.0 ...)
- weasyprint <unfixed> (bug #1148178)
[trixie] - weasyprint <no-dsa> (Minor issue)
@@ -11865,15 +11865,15 @@ CVE-2026-55073 (WeasyPrint helps web developers to create PDF documents. Prior t
CVE-2026-55072 (Pimcore is an Open Source Data & Experience Management Platform. Prior ...)
NOT-FOR-US: Pimcore
CVE-2026-54723 (devpi is a Python package index staging server and packaging, testing, ...)
- TODO: check
+ NOT-FOR-US: devpi
CVE-2026-54567 (Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6 ...)
- TODO: check
+ NOT-FOR-US: Flask-Reuploaded
CVE-2026-54542 (Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol ba ...)
- TODO: check
+ NOT-FOR-US: Nimiq
CVE-2026-54541 (Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol ba ...)
- TODO: check
+ NOT-FOR-US: Nimiq
CVE-2026-54529 (SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to ...)
- TODO: check
+ NOT-FOR-US: SQLAdmin
CVE-2026-54452 (safeurl is a server-side request forgery protection library. Prior to ...)
TODO: check
CVE-2026-54182 (backpack/crud provides Create, Read, Update & Delete (CRUD) functions ...)
@@ -11891,13 +11891,13 @@ CVE-2026-54176 (backpack/crud provides Create, Read, Update & Delete (CRUD) func
CVE-2026-54175 (backpack/crud provides Create, Read, Update & Delete (CRUD) functions ...)
NOT-FOR-US: backpack/crud
CVE-2026-54156 (node-opcua is an OPC UA implementation for TypeScript and Node.js. Pri ...)
- TODO: check
+ NOT-FOR-US: node-opcua/node-opcua
CVE-2026-54155 (node-opcua is an OPC UA implementation for TypeScript and Node.js. Pri ...)
- TODO: check
+ NOT-FOR-US: node-opcua/node-opcua
CVE-2026-54150 (next-video is a library for adding video to Next.js applications. Prio ...)
NOT-FOR-US: Next.js
CVE-2026-54087 (EasyAdmin is a fast and modern admin generator for Symfony application ...)
- TODO: check
+ NOT-FOR-US: EasyAdminEasyAdmin
CVE-2026-53752 (docx4j is an open source Java library for creating, editing, and savin ...)
TODO: check
CVE-2026-53708 (ContextForge is an AI gateway, registry, and proxy that provides centr ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/efa462356a94707b8f6b87efdadecd1cf777d5ff
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/efa462356a94707b8f6b87efdadecd1cf777d5ff
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260921/636acd8e/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list