[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Sep 22 07:30:34 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8d4b559e by Salvatore Bonaccorso at 2026-09-22T08:28:32+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -9948,7 +9948,7 @@ CVE-2026-19641 (On affected platforms running Arista EOS with password authentic
 CVE-2026-19515 (The WSO2 Integrator MI VS Code extension fails to properly sanitize or ...)
 	NOT-FOR-US: WSO2
 CVE-2026-19504 (Fabric.js loadFromJSON Server-Side Request Forgery Vulnerability. This ...)
-	TODO: check
+	NOT-FOR-US: Fabric.js
 CVE-2026-19407 (Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK  ...)
 	NOT-FOR-US: Google Cloud Gemini Enterprise Agent Platform SDK
 CVE-2026-18115 (Concrete CMS 9.2.0 to 9.5.2 did not enforce per-field edit_user_proper ...)
@@ -11951,7 +11951,7 @@ CVE-2026-54541 (Nimiq is a Rust implementation of the Nimiq Proof-of-Stake proto
 CVE-2026-54529 (SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to ...)
 	NOT-FOR-US: SQLAdmin
 CVE-2026-54452 (safeurl is a server-side request forgery protection library. Prior to  ...)
-	TODO: check
+	NOT-FOR-US: Doyensec safeurl
 CVE-2026-54182 (backpack/crud provides Create, Read, Update & Delete (CRUD) functions  ...)
 	NOT-FOR-US: backpack/crud
 CVE-2026-54181 (backpack/crud provides Create, Read, Update & Delete (CRUD) functions  ...)
@@ -11975,13 +11975,13 @@ CVE-2026-54150 (next-video is a library for adding video to Next.js applications
 CVE-2026-54087 (EasyAdmin is a fast and modern admin generator for Symfony application ...)
 	NOT-FOR-US: EasyAdminEasyAdmin
 CVE-2026-53752 (docx4j is an open source Java library for creating, editing, and savin ...)
-	TODO: check
+	NOT-FOR-US: docx4j
 CVE-2026-53708 (ContextForge is an AI gateway, registry, and proxy that provides centr ...)
 	NOT-FOR-US: ContextForge
 CVE-2026-53659 (http4k is a functional toolkit for Kotlin HTTP applications. Prior to  ...)
 	NOT-FOR-US: http4k
 CVE-2026-53496 (ExifReader is a JavaScript Exif information parser. Prior to 4.40.1, E ...)
-	TODO: check
+	NOT-FOR-US: ExifReader
 CVE-2026-53495 (containerd is an open-source container runtime. Prior to 1.7.35, 2.0.1 ...)
 	- containerd <unfixed> (bug #1148180)
 	NOTE: https://github.com/containerd/containerd/security/advisories/GHSA-7jxh-36q5-gcqv
@@ -629708,7 +629708,7 @@ CVE-2021-3032 (An information exposure through log file vulnerability exists in
 CVE-2021-3031 (Padding bytes in Ethernet packets on PA-200, PA-220, PA-500, PA-800, P ...)
 	NOT-FOR-US: Palo Alto Networks
 CVE-2021-3030 (Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scri ...)
-	TODO: check
+	NOT-FOR-US: Cute Editor for ASP.NET
 CVE-2021-23234
 	RESERVED
 CVE-2021-23135 (Exposure of System Data to an Unauthorized Control Sphere vulnerabilit ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8d4b559e1d4795a54dc7d65b11ddc86ab2486303

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8d4b559e1d4795a54dc7d65b11ddc86ab2486303
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260922/9f1dbab0/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list