[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Sep 21 19:58:10 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7f0ecc1b by Moritz Muehlenhoff at 2026-09-21T20:57:53+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -11163,9 +11163,9 @@ CVE-2026-53714 (Envoy Gateway is an open source project for managing Envoy Proxy
 CVE-2026-53713 (Envoy Gateway is an open source project for managing Envoy Proxy as a  ...)
 	- envoyproxy <itp> (bug #987544)
 CVE-2026-50006 (Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5 ...)
-	TODO: check
+	NOT-FOR-US: Anyquery
 CVE-2026-47253 (Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5 ...)
-	TODO: check
+	NOT-FOR-US: Anyquery
 CVE-2026-43815 (A buffer overflow was addressed with improved bounds checking. This is ...)
 	NOT-FOR-US: Apple
 CVE-2026-43808 (A use-after-free issue was addressed with improved memory management.  ...)
@@ -11912,7 +11912,7 @@ CVE-2026-54087 (EasyAdmin is a fast and modern admin generator for Symfony appli
 CVE-2026-53752 (docx4j is an open source Java library for creating, editing, and savin ...)
 	TODO: check
 CVE-2026-53708 (ContextForge is an AI gateway, registry, and proxy that provides centr ...)
-	TODO: check
+	NOT-FOR-US: ContextForge
 CVE-2026-53659 (http4k is a functional toolkit for Kotlin HTTP applications. Prior to  ...)
 	NOT-FOR-US: http4k
 CVE-2026-53496 (ExifReader is a JavaScript Exif information parser. Prior to 4.40.1, E ...)
@@ -11924,21 +11924,21 @@ CVE-2026-53495 (containerd is an open-source container runtime. Prior to 1.7.35,
 	NOTE: https://github.com/containerd/containerd/commit/22ccf4314d1fe0834f8e28f10d37d5305ef9880c (v2.2.8)
 	NOTE: https://github.com/containerd/containerd/commit/5a2a3a759b0d2ad8c821b33c3afc20890daf6d81 (v1.7.35)
 CVE-2026-50276 (dd-trace-rb is Datadog's client library for Ruby. Prior to 2.32.0, W3C ...)
-	TODO: check
+	NOT-FOR-US: dd-trace-rb
 CVE-2026-50270 (dd-trace-java is a Datadog APM client for Java. Prior to 1.62.0, W3C b ...)
-	TODO: check
+	NOT-FOR-US: dd-trace-rb
 CVE-2026-50157 (Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management ...)
-	TODO: check
+	NOT-FOR-US: Auth0 Symfony
 CVE-2026-4103 (Insufficient HTML sanitization in the Publisher Portal and Developer P ...)
 	NOT-FOR-US: WSO2
 CVE-2026-49400 (October System provides the system module for October Content Manageme ...)
-	TODO: check
+	NOT-FOR-US: October System
 CVE-2026-49250 (Conform, a type-safe form validation library, allows the parsing of ne ...)
-	TODO: check
+	NOT-FOR-US: Node Conform
 CVE-2026-47256 (OpenTelemetry, also known as OTel, is a vendor-neutral open source Obs ...)
 	NOT-FOR-US: opentelemetry-collector-contrib (OpenTelemetry Collector)
 CVE-2026-46696 (October System provides the system module for October Content Manageme ...)
-	TODO: check
+	NOT-FOR-US: October System
 CVE-2026-44162 (fluent-plugin-s3 is an Amazon S3 input and output plugin for Fluentd.  ...)
 	NOT-FOR-US: fluent-plugin-s3
 CVE-2026-34151 (XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0 ...)
@@ -12309,7 +12309,7 @@ CVE-2025-64031 (libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer ove
 	NOTE: Introduced with: https://github.com/libarchive/libarchive/commit/84ac71335fd7bc151be763dd525353c182b280b5 (v3.8.0)
 	NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/53e85224536a73600f6920f692c9d38e16753bd9 (v3.8.2)
 CVE-2025-63842 (A Cross-Site Scripting (XSS) vulnerability in the web backend for the  ...)
-	TODO: check
+	NOT-FOR-US: Repetico
 CVE-2025-26790 (Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a  ...)
 	NOT-FOR-US: Withsecure
 CVE-2024-53922 (An issue was discovered in the buffer queue driver in Samsung Automoti ...)
@@ -53252,8 +53252,7 @@ CVE-2026-72558 (An SQL injection vulnerability in CiviCRM through 6.18.alpha1 al
 CVE-2026-72557 (An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows  ...)
 	NOT-FOR-US: Cockpit CMS
 CVE-2026-72556 (A remote code execution vulnerability in ZoneMinder 1.39.17 allows any ...)
-	- zoneminder <undetermined>
-	TODO: check, another CVE assigned by "Turan Security" CNA without providing details
+	NOTE: Bogus report without any details provided
 CVE-2026-72555 (A broken access control vulnerability in Peppermint Lab Peppermint thr ...)
 	NOT-FOR-US: Peppermint Lab Peppermint
 CVE-2026-72554 (A broken access control vulnerability in Ladybird Web Solution Faveo H ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7f0ecc1b298d0cade1aa4cee46dd0efebe7bb474

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7f0ecc1b298d0cade1aa4cee46dd0efebe7bb474
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260921/1c717c8c/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list