[Git][security-tracker-team/security-tracker][master] Add new misp issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Sep 22 20:31:20 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
2099f06a by Salvatore Bonaccorso at 2026-09-22T21:30:23+02:00
Add new misp issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -7,49 +7,49 @@ CVE-2026-95862 (A malicious actor with access to the network could exploit an Ou
 CVE-2026-95861 (A malicious actor with access to the network could exploit an Uncontro ...)
 	NOT-FOR-US: Ubiquity
 CVE-2026-95806 (MISP ships with PHP's phar stream wrapper registered in both its web e ...)
-	TODO: check
+	- misp <itp> (bug #1144317)
 CVE-2026-95805 (A typo in the MISP ACLComponent access control configuration caused th ...)
-	TODO: check
+	- misp <itp> (bug #1144317)
 CVE-2026-95754 (In MISP's UsersController login() method, the pre-authentication datab ...)
-	TODO: check
+	- misp <itp> (bug #1144317)
 CVE-2026-95703 (In MISP, the OrganisationsController::__uploadLogo method processed a  ...)
-	TODO: check
+	- misp <itp> (bug #1144317)
 CVE-2026-95701 (In MISP, the __statisticsOrgs method in UsersController.php used the o ...)
-	TODO: check
+	- misp <itp> (bug #1144317)
 CVE-2026-95698 (The findOrgImage method in MISP's OrgImgHelper constructs a filesystem ...)
-	TODO: check
+	- misp <itp> (bug #1144317)
 CVE-2026-95697 (MISP contains an authorization flaw in the Organisation model's captur ...)
-	TODO: check
+	- misp <itp> (bug #1144317)
 CVE-2026-95693 (In MISP, the EventReport::uploadPicture method in processed a caller-s ...)
-	TODO: check
+	- misp <itp> (bug #1144317)
 CVE-2026-95685 (MISP contains an access control flaw in the EventReports functionality ...)
-	TODO: check
+	- misp <itp> (bug #1144317)
 CVE-2026-95683 (In MISP, the Overmind event view enriches an event with its most recen ...)
-	TODO: check
+	- misp <itp> (bug #1144317)
 CVE-2026-95682 (MISP contains a stored cross-site scripting (XSS) vulnerability in the ...)
-	TODO: check
+	- misp <itp> (bug #1144317)
 CVE-2026-95679 (MISP's RequestHandlerComponent automatically decodes XML request bodie ...)
-	TODO: check
+	- misp <itp> (bug #1144317)
 CVE-2026-95675 (D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthen ...)
 	NOT-FOR-US: D-Link
 CVE-2026-95674 (In MISP, the queryEnrichment method in EventsController.php accepted a ...)
-	TODO: check
+	- misp <itp> (bug #1144317)
 CVE-2026-95671 (In MISP, the CollectionsController add() method enforced the sharing-g ...)
-	TODO: check
+	- misp <itp> (bug #1144317)
 CVE-2026-95667 (The MISP installer scripts (for Debian 12, Debian 13, Ubuntu 24.04, an ...)
-	TODO: check
+	- misp <itp> (bug #1144317)
 CVE-2026-95666 (Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7 ...)
 	TODO: check
 CVE-2026-95665 (MISP contains a reflected cross-site scripting (XSS) vulnerability in  ...)
-	TODO: check
+	- misp <itp> (bug #1144317)
 CVE-2026-95661 (MISP contains a reflected cross-site scripting (XSS) vulnerability in  ...)
-	TODO: check
+	- misp <itp> (bug #1144317)
 CVE-2026-95660 (A security flaw has been discovered in Moonshot AI Kimi Code up to 0.3 ...)
 	TODO: check
 CVE-2026-95659 (MISP contains a reflected cross-site scripting (XSS) vulnerability in  ...)
-	TODO: check
+	- misp <itp> (bug #1144317)
 CVE-2026-95658 (MISP's WorkflowsController exposed the moduleStatelessExecution action ...)
-	TODO: check
+	- misp <itp> (bug #1144317)
 CVE-2026-95657 (A vulnerability was determined in dgtlmoon Changedetection.io up to 0. ...)
 	TODO: check
 CVE-2026-95656 (A vulnerability was found in dgtlmoon changedetection.io up to 50389b0 ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2099f06a8472d44b2f630fed49ed28b138bb64d9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2099f06a8472d44b2f630fed49ed28b138bb64d9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260922/9766dfd2/attachment.htm>


More information about the debian-security-tracker-commits mailing list