[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Sep 23 23:16:56 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8bd11420 by Moritz Muehlenhoff at 2026-09-24T00:16:36+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -635,7 +635,7 @@ CVE-2026-81338 (The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.
 CVE-2026-80342 (The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0 ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-79767 (Gardener implements the automated management and operation of Kubernet ...)
-	TODO: check
+	NOT-FOR-US: Gardener
 CVE-2026-77987 (A server-side request forgery (SSRF) vulnerability was identified in t ...)
 	NOT-FOR-US: Github Enterprise Server
 CVE-2026-77912 (A stored cross-site scripting (XSS) vulnerability was identified in Gi ...)
@@ -645,15 +645,15 @@ CVE-2026-77766 (The Directorist: AI-Powered Business Directory, Listings & Class
 CVE-2026-77765 (The Better Payment  WordPress plugin before 2.3.4 does not validate th ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-77426 (Unleash is an open-source feature management platform. Prior to 8.0.3, ...)
-	TODO: check
+	NOT-FOR-US: Unleash
 CVE-2026-77425 (Unleash is an open-source feature management platform. Prior to 8.0.3, ...)
-	TODO: check
+	NOT-FOR-US: Unleash
 CVE-2026-77322 (SIPGO is a library for writing SIP services in the GO language. Prior  ...)
-	TODO: check
+	NOT-FOR-US: sipgo
 CVE-2026-76910 (Unleash is an open-source feature management platform. Prior to 8.0.3, ...)
-	TODO: check
+	NOT-FOR-US: Unleash
 CVE-2026-76909 (Unleash is an open-source feature management platform. Prior to 8.0.3, ...)
-	TODO: check
+	NOT-FOR-US: Unleash
 CVE-2026-76717 (A vulnerability exists in the Analytics and Location Engine (ALE) API  ...)
 	NOT-FOR-US: HPE
 CVE-2026-76716 (Multiple vulnerabilities exist in the Analytics and Location Engine (A ...)
@@ -683,23 +683,23 @@ CVE-2026-75101 (An authorization bypass vulnerability was identified in GitHub E
 CVE-2026-6831 (The Advanced Contact form 7 DB plugin for WordPress is vulnerable to m ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-67615 (openEQUELLA before 2026.1.0 contains an authenticated remote code exec ...)
-	TODO: check
+	NOT-FOR-US: openEQUELLA
 CVE-2026-65829 (MPXJ is an open source library to read and write project plans from a  ...)
-	TODO: check
+	NOT-FOR-US: MPXJ
 CVE-2026-63628 (mppx is a TypeScript interface for machine payments protocol. Prior to ...)
-	TODO: check
+	NOT-FOR-US: mppx
 CVE-2026-63627 (mppx is a TypeScript interface for machine payments protocol. Prior to ...)
-	TODO: check
+	NOT-FOR-US: mppx
 CVE-2026-63104 (Kaneo versions 2.3.12 before 2.12.2 contain a missing authorization vu ...)
-	TODO: check
+	NOT-FOR-US: Kaneo
 CVE-2026-62985 (request-filtering-agent is an http(s).Agent implementation that blocks ...)
-	TODO: check
+	NOT-FOR-US: Node request-filtering-agent
 CVE-2026-62364 (wlc is a Weblate command-line client using Weblate's REST API. Prior t ...)
 	TODO: check
 CVE-2026-61685 (ReactPress is a publishing system for React developers. Prior to versi ...)
-	TODO: check
+	NOT-FOR-US: ReactPress
 CVE-2026-61570 (MPXJ is an open source library to read and write project plans from a  ...)
-	TODO: check
+	NOT-FOR-US: MPXJ
 CVE-2026-5924 (The Getwid \u2013 Gutenberg Blocks plugin for WordPress is vulnerable  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-59991 (psd-tools is a Python package for working with Adobe Photoshop PSD fil ...)
@@ -707,11 +707,11 @@ CVE-2026-59991 (psd-tools is a Python package for working with Adobe Photoshop P
 	NOTE: https://github.com/psd-tools/psd-tools/security/advisories/GHSA-8q6g-vjhf-jp8m
 	NOTE: Fixed by: https://github.com/psd-tools/psd-tools/commit/a3d9a53ad51e667b5772a4f636ca6f2e16f4b271 (v1.17.4)
 CVE-2026-58268 (SIPGO is a library for writing SIP services in the GO language. Prior  ...)
-	TODO: check
+	NOT-FOR-US: sipgo
 CVE-2026-57576 (plone.app.dexterity is a content-type system for the Plone content man ...)
-	TODO: check
+	NOT-FOR-US: plone.app.dexterity
 CVE-2026-47116 (LTSecurity LTK3500SF contains a hard-coded credentials vulnerability w ...)
-	TODO: check
+	NOT-FOR-US: LTSecurity LTK3500SF
 CVE-2026-28325 (SolarWinds Observability Self-Hosted was found to be affected by an un ...)
 	NOT-FOR-US: SolarWinds
 CVE-2026-28324 (SolarWinds Observability Self-Hosted was found to be affected by an un ...)
@@ -719,7 +719,7 @@ CVE-2026-28324 (SolarWinds Observability Self-Hosted was found to be affected by
 CVE-2026-19438 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
 	NOT-FOR-US: ABB group
 CVE-2026-19202 (A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-pyth ...)
-	TODO: check
+	NOT-FOR-US: mcp-toolbox-sdk-python
 CVE-2026-18365 (The zportals WordPress plugin before 6.4.2 does not perform any capabi ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-18364 (The zportals WordPress plugin before 6.4.2 does not perform any capabi ...)
@@ -1392,7 +1392,7 @@ CVE-2026-7866 (Stack-based Buffer Overflow vulnerability in RTI Connext Professi
 CVE-2026-7622 (The ThumbPress plugin for WordPress is vulnerable to unauthorized acce ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-79913 (Cloudreve is a self-hosted file management and sharing system. Prior t ...)
-	TODO: check
+	NOT-FOR-US: Cloudreve
 CVE-2026-79906 (Substance3D - Modeler is affected by an out-of-bounds write vulnerabil ...)
 	NOT-FOR-US: Adobe
 CVE-2026-79315 (A reflected cross-site scripting vulnerability exists in x-ui 0.3.2. T ...)
@@ -1619,7 +1619,7 @@ CVE-2026-65112 (NVIDIA Infrastructure Controller for Linux contains a vulnerabil
 CVE-2026-65111 (NVIDIA NeMo Speech for all platforms contains a vulnerability where ma ...)
 	NOT-FOR-US: NVIDIA
 CVE-2026-63386 (js-toml is a TOML parser for JavaScript. Prior to 1.1.3, load() does n ...)
-	TODO: check
+	NOT-FOR-US: Node js-toml
 CVE-2026-63279 (LibreOffice can import PICT images, which may be embedded in documents ...)
 	- libreoffice 4:26.2.5.2-1
 	NOTE: https://www.libreoffice.org/security/#cve-2026-63279
@@ -1660,7 +1660,7 @@ CVE-2026-43641 (Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contain
 CVE-2026-37604 (pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 resolves ...)
 	NOT-FOR-US: pH7Software pH7Builder
 CVE-2026-37603 (Improper Restriction of Excessive Authentication Attempts in the admin ...)
-	TODO: check
+	NOT-FOR-US: pH7Software pH7Builder
 CVE-2026-34689 (Adobe Connect is affected by an Improper Limitation of a Pathname to a ...)
 	NOT-FOR-US: Adobe
 CVE-2026-25265 (Privilege escalation due to weak configuration while temporary file ha ...)
@@ -1680,7 +1680,7 @@ CVE-2026-24239 (NVIDIA NeMo Speech for all platforms contains a vulnerability wh
 CVE-2026-1645 (The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scr ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-19915 (A potential security vulnerability has been identified in the HP Suppo ...)
-	TODO: check
+	NOT-FOR-US: HP
 CVE-2026-19480 (CAI Content Credentials is affected by an Improper Input Validation vu ...)
 	NOT-FOR-US: Adobe
 CVE-2026-18626 (Out-of-bounds Read vulnerability in RTI Connext Professional (Core Lib ...)
@@ -1710,7 +1710,7 @@ CVE-2026-13087 (A heap out-of-bounds write vulnerability was found in the Linux
 CVE-2026-12995 (The Custom Field Template plugin for WordPress is vulnerable to Insecu ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-12718 (Improper neutralization of special elements used in an SQL command ('S ...)
-	TODO: check
+	NOT-FOR-US: KarelIPS
 CVE-2026-11389 (Out-of-bounds Read, Function Call With Incorrect Number of Arguments,  ...)
 	NOT-FOR-US: RTI Connext
 CVE-2026-11388 (Double Free vulnerability in RTI Connext Professional (Core Libraries) ...)
@@ -1904,7 +1904,7 @@ CVE-2026-93340 (Gladys Assistant before 5.1.0 contains a password reset link poi
 CVE-2026-93339 (Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a  ...)
 	NOT-FOR-US: Metaphor Creations Ditty (ditty-news-ticker)
 CVE-2026-92612 (In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exp ...)
-	TODO: check
+	NOT-FOR-US: Eclipse iceoryx2
 CVE-2026-92438 (The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-92400 (The Payment Gateway for PayPal on WooCommerce WordPress plugin before  ...)
@@ -2041,43 +2041,43 @@ CVE-2026-79079 (An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to
 	NOTE: https://gist.github.com/lggcs/c1f98ce55ced44472651b9590d9f199a
 	NOTE: Fixed by: https://github.com/crosswire/xiphos/commit/f96ad3273277e7fb24908b40f3aa1e9efeeb4e85 (4.4.0)
 CVE-2026-78847 (An issue in gray-matter All versions (verified on 4.0.3) allows the Ja ...)
-	TODO: check
+	NOT-FOR-US: Node gray-matter
 CVE-2026-78806 (An issue in Matter Standard Specification-Implementation gap v1.5.1 Ma ...)
-	TODO: check
+	NOT-FOR-US: Matter Project Chip
 CVE-2026-77582 (Tinyauth is an authentication and authorization server. Prior to 5.1.0 ...)
-	TODO: check
+	NOT-FOR-US: Tinyauth
 CVE-2026-77561 (Tinyauth is an authentication and authorization server. Prior to 5.1.0 ...)
-	TODO: check
+	NOT-FOR-US: Tinyauth
 CVE-2026-77560 (Tinyauth is an authentication and authorization server. Prior to 5.1.2 ...)
-	TODO: check
+	NOT-FOR-US: Tinyauth
 CVE-2026-77525 (MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and ...)
-	TODO: check
+	NOT-FOR-US: MaxKB
 CVE-2026-77523 (MaxKB is an open-source AI assistant for enterprise. In version 2.10.3 ...)
-	TODO: check
+	NOT-FOR-US: MaxKB
 CVE-2026-77522 (MaxKB is an open-source AI assistant for enterprise. In version 2.10.3 ...)
-	TODO: check
+	NOT-FOR-US: MaxKB
 CVE-2026-77521 (MaxKB is an open-source AI assistant for enterprise. Prior to version  ...)
-	TODO: check
+	NOT-FOR-US: MaxKB
 CVE-2026-77520 (MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and ...)
-	TODO: check
+	NOT-FOR-US: MaxKB
 CVE-2026-77519 (MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and ...)
-	TODO: check
+	NOT-FOR-US: MaxKB
 CVE-2026-77518 (MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and ...)
-	TODO: check
+	NOT-FOR-US: MaxKB
 CVE-2026-77517 (MaxKB is an open-source AI assistant for enterprise. From version 2.0. ...)
-	TODO: check
+	NOT-FOR-US: MaxKB
 CVE-2026-77516 (MaxKB is an open-source AI assistant for enterprise. From version 2.0. ...)
-	TODO: check
+	NOT-FOR-US: MaxKB
 CVE-2026-77166 (The emoji field in the page emoji update endpoint does not properly va ...)
-	TODO: check
+	NOT-FOR-US: Nextcloud Collectives
 CVE-2026-77165 (File owners were unable to unlock TYPE_TOKEN locks placed by other use ...)
-	TODO: check
+	- nextcloud-server <itp> (bug #941708)
 CVE-2026-77021 (Improper handling of highly compressed data (data amplification) in Ch ...)
 	NOT-FOR-US: Checkmk
 CVE-2026-76974 (SAP Fiori Launchpad does not sufficiently validate certain user-contro ...)
 	NOT-FOR-US: SAP
 CVE-2026-76898 (draw.io is a configurable diagramming and whiteboarding application. P ...)
-	TODO: check
+	NOT-FOR-US: draw.io
 CVE-2026-75158 (Apache Airflow's `/assets/events` API returned asset events for every  ...)
 	- airflow <itp> (bug #819700)
 CVE-2026-71543 (OpenBao is an open source identity-based secrets management system. Pr ...)
@@ -2085,189 +2085,189 @@ CVE-2026-71543 (OpenBao is an open source identity-based secrets management syst
 CVE-2026-69190 (Graylog is a free and open log management platform. From 6.3.0 until 6 ...)
 	- graylog2 <itp> (bug #652273)
 CVE-2026-68919 (GoCD is a continuous deliver server. From 13.3.0 until 26.1.0, GoCD do ...)
-	TODO: check
+	NOT-FOR-US: GoCD
 CVE-2026-67827 (Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9 ...)
-	TODO: check
+	NOT-FOR-US: ZLMediaKit
 CVE-2026-66280
 	REJECTED
 CVE-2026-65980 (Chartbrew is an open-source web application that can connect directly  ...)
-	TODO: check
+	NOT-FOR-US: Chartbrew
 CVE-2026-65654 (github.com/temporalio/ringpop-go enforces configured LabelOptions limi ...)
-	TODO: check
+	NOT-FOR-US: github.com/temporalio/ringpop-go
 CVE-2026-65653 (github.com/temporalio/tchannel-go did not reject TChannel call fragmen ...)
-	TODO: check
+	NOT-FOR-US: github.com/temporalio/tchannel-go
 CVE-2026-65652 (github.com/temporalio/tchannel-go did not validate the one-byte checks ...)
-	TODO: check
+	NOT-FOR-US: github.com/temporalio/tchannel-go
 CVE-2026-65651 (temporalio/sqlparser accepts SQL containing deeply nested unary expres ...)
-	TODO: check
+	NOT-FOR-US: temporalio/sqlparser
 CVE-2026-63416 (draw.io is a configurable diagramming and whiteboarding application. P ...)
-	TODO: check
+	NOT-FOR-US: draw.io
 CVE-2026-63373 (draw.io is a configurable diagramming and whiteboarding application. P ...)
-	TODO: check
+	NOT-FOR-US: draw.io
 CVE-2026-63342 (Hatchet is a platform for orchestrating background tasks, AI agents, a ...)
-	TODO: check
+	NOT-FOR-US: Hatchet
 CVE-2026-63334 (draw.io is a configurable diagramming and whiteboarding application. P ...)
-	TODO: check
+	NOT-FOR-US: draw.io
 CVE-2026-63330 (Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux ...)
-	TODO: check
+	NOT-FOR-US: Warpgate
 CVE-2026-63329 (Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux ...)
-	TODO: check
+	NOT-FOR-US: Warpgate
 CVE-2026-63116 (deepstream is a server that allows clients and backend services to syn ...)
-	TODO: check
+	NOT-FOR-US: deepstream
 CVE-2026-62987 (Fabio is an HTTP(S) and TCP router for deploying applications managed  ...)
-	TODO: check
+	NOT-FOR-US: Fabio
 CVE-2026-62866 (Dasel is a command-line tool and library for querying, modifying, and  ...)
 	TODO: check
 CVE-2026-62371 (KubeEdge is an open source system for extending native containerized a ...)
-	TODO: check
+	NOT-FOR-US: KubeEdge
 CVE-2026-62370 (KubeEdge is an open source system for extending native containerized a ...)
-	TODO: check
+	NOT-FOR-US: KubeEdge
 CVE-2026-62369 (KubeEdge is an open source system for extending native containerized a ...)
-	TODO: check
+	NOT-FOR-US: KubeEdge
 CVE-2026-62247 (Supabase Realtime provides Broadcast, Presence, and Postgres Changes v ...)
-	TODO: check
+	NOT-FOR-US: KubeEdge
 CVE-2026-62182 (KubeEdge is an open source system for extending native containerized a ...)
-	TODO: check
+	NOT-FOR-US: Supabase
 CVE-2026-61852 (Chartbrew is an open-source web application that can connect directly  ...)
-	TODO: check
+	NOT-FOR-US: Chartbrew
 CVE-2026-61851 (Chartbrew is an open-source web application that can connect directly  ...)
-	TODO: check
+	NOT-FOR-US: Chartbrew
 CVE-2026-61749 (InvenTree is an Open Source Inventory Management System. Prior to 1.4. ...)
-	TODO: check
+	NOT-FOR-US: InvenTree
 CVE-2026-61748 (InvenTree is an Open Source Inventory Management System. Prior to 1.4. ...)
-	TODO: check
+	NOT-FOR-US: InvenTree
 CVE-2026-61747 (InvenTree is an Open Source Inventory Management System. Prior to 1.4. ...)
-	TODO: check
+	NOT-FOR-US: InvenTree
 CVE-2026-61746 (InvenTree is an Open Source Inventory Management System. Prior to 1.4. ...)
-	TODO: check
+	NOT-FOR-US: InvenTree
 CVE-2026-61745 (InvenTree is an Open Source Inventory Management System. Prior to 1.4. ...)
-	TODO: check
+	NOT-FOR-US: InvenTree
 CVE-2026-61744 (InvenTree is an Open Source Inventory Management System. Prior to 1.4. ...)
-	TODO: check
+	NOT-FOR-US: InvenTree
 CVE-2026-61743 (Chartbrew is an open-source web application that can connect directly  ...)
-	TODO: check
+	NOT-FOR-US: Chartbrew
 CVE-2026-61687 (Hatchet is a platform for orchestrating background tasks, AI agents, a ...)
-	TODO: check
+	NOT-FOR-US: Hatchet
 CVE-2026-61681 (Hatchet is a platform for orchestrating background tasks, AI agents, a ...)
-	TODO: check
+	NOT-FOR-US: Hatchet
 CVE-2026-61674 (Fluent Bit is a fast and lightweight logs, metrics, and traces process ...)
 	TODO: check
 CVE-2026-61652 (Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to ...)
-	TODO: check
+	NOT-FOR-US: Zapros
 CVE-2026-61647 (NotebookLM MCP is an MCP server and HTTP service for interacting with  ...)
-	TODO: check
+	NOT-FOR-US: NotebookLM MCP
 CVE-2026-61630 (nginx ignition is a user interface for the nginx web server. In versio ...)
-	TODO: check
+	NOT-FOR-US: nginx ignition
 CVE-2026-61629 (nginx ignition is a user interface for the nginx web server. In versio ...)
-	TODO: check
+	NOT-FOR-US: nginx ignition
 CVE-2026-61628 (nginx ignition is a user interface for the nginx web server. Prior to  ...)
-	TODO: check
+	NOT-FOR-US: nginx ignition
 CVE-2026-61612 (CKAN MCP Server is a tool for querying CKAN open data portals. Prior t ...)
-	TODO: check
+	NOT-FOR-US: CKAN MCP Server
 CVE-2026-61541 (Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to ...)
-	TODO: check
+	NOT-FOR-US: Zapros
 CVE-2026-59830 (Discourse is an open-source discussion platform. Prior to 2026.7.0, th ...)
 	NOT-FOR-US: Discourse
 CVE-2026-59816 (Joplin is an open source note-taking and to-do application that organi ...)
-	TODO: check
+	- joplin <itp> (bug #931306)
 CVE-2026-59815 (Joplin is an open source note-taking and to-do application that organi ...)
-	TODO: check
+	- joplin <itp> (bug #931306)
 CVE-2026-59814 (Joplin is an open source note-taking and to-do application that organi ...)
-	TODO: check
+	- joplin <itp> (bug #931306)
 CVE-2026-59168 (Dasel is a command-line tool and library for querying, modifying, and  ...)
 	TODO: check
 CVE-2026-58504 (draw.io is a configurable diagramming and whiteboarding application. P ...)
-	TODO: check
+	NOT-FOR-US: draw.io
 CVE-2026-58491 (Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux ...)
-	TODO: check
+	NOT-FOR-US: Warpgate
 CVE-2026-58272 (Sync-in Server is an open-source platform for file storage, sharing, c ...)
-	TODO: check
+	NOT-FOR-US: Sync-in Server
 CVE-2026-58271 (Sync-in Server is an open-source platform for file storage, sharing, c ...)
-	TODO: check
+	NOT-FOR-US: Sync-in Server
 CVE-2026-58270 (Sync-in Server is an open-source platform for file storage, sharing, c ...)
-	TODO: check
+	NOT-FOR-US: Sync-in Server
 CVE-2026-58269 (Sync-in Server is an open-source platform for file storage, sharing, c ...)
-	TODO: check
+	NOT-FOR-US: Sync-in Server
 CVE-2026-55897 (luci-app-advanced-reboot is a LuCI (web interface) application for Ope ...)
-	TODO: check
+	NOT-FOR-US: luci-app-advanced-reboot
 CVE-2026-55870 (GoCD is a continuous deliver server. Prior to 26.1.0, GoCD can return  ...)
-	TODO: check
+	NOT-FOR-US: GoCD
 CVE-2026-55625 (GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the int ...)
-	TODO: check
+	NOT-FOR-US: GoCD
 CVE-2026-55567 (BleachBit cleans files to free disk space and to maintain privacy. Pri ...)
-	TODO: check
+	NOT-FOR-US: BleachBit
 CVE-2026-55563 (Feast is the open source feature store for AI and machine learning. Pr ...)
-	TODO: check
+	NOT-FOR-US: Feast
 CVE-2026-55473 (HomeBox is a home inventory and organization system. Prior to 0.26.0,  ...)
-	TODO: check
+	NOT-FOR-US: HomeBox
 CVE-2026-55210 (Joplin is an open source note-taking and to-do application that organi ...)
-	TODO: check
+	- joplin <itp> (bug #931306)
 CVE-2026-55179 (Joplin is an open source note-taking and to-do application that organi ...)
-	TODO: check
+	- joplin <itp> (bug #931306)
 CVE-2026-55159 (luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-block ...)
-	TODO: check
+	NOT-FOR-US: luci-app-adblock-fast
 CVE-2026-55105 (Joplin is an open source note-taking and to-do application that organi ...)
-	TODO: check
+	- joplin <itp> (bug #931306)
 CVE-2026-55074 (Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin ...)
-	TODO: check
+	NOT-FOR-US: Ansible FreeBSD Jail Connection Plugin
 CVE-2026-55071 (MCP-for-Stata is a MCP server for integrating Stata into agent loops w ...)
-	TODO: check
+	NOT-FOR-US: MCP-for-Stata
 CVE-2026-55060 (GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go ...)
-	TODO: check
+	NOT-FOR-US: GoCD
 CVE-2026-54915 (Tautulli is a Python based monitoring and tracking tool for Plex Media ...)
-	TODO: check
+	NOT-FOR-US: Tautulli
 CVE-2026-54584 (mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPD ...)
-	TODO: check
+	NOT-FOR-US: mport MidnightBSD Package Manager
 CVE-2026-53940 (Conda is a system-level binary package and environment manager that ru ...)
-	TODO: check
+	NOT-FOR-US: Conda
 CVE-2026-52835 (Tautulli is a Python based monitoring and tracking tool for Plex Media ...)
-	TODO: check
+	NOT-FOR-US: Tautulli
 CVE-2026-52743 (GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoC ...)
-	TODO: check
+	NOT-FOR-US: GoCD
 CVE-2026-52742 (GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy  ...)
-	TODO: check
+	NOT-FOR-US: GoCD
 CVE-2026-52741 (GoCD is a continuous deliver server. From 18.3.0 until 26.1.0, GoCD ca ...)
-	TODO: check
+	NOT-FOR-US: GoCD
 CVE-2026-52740 (GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, the Get ...)
-	TODO: check
+	NOT-FOR-US: GoCD
 CVE-2026-49995 (Tautulli is a Python based monitoring and tracking tool for Plex Media ...)
-	TODO: check
+	NOT-FOR-US: Tautulli
 CVE-2026-49811 (Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an In ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-49810 (Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 cont ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-49453 (Joplin is an open source note-taking and to-do application that organi ...)
-	TODO: check
+	- joplin <itp> (bug #931306)
 CVE-2026-49450 (Joplin is an open source note-taking and to-do application that organi ...)
-	TODO: check
+	- joplin <itp> (bug #931306)
 CVE-2026-49449 (Joplin is an open source note-taking and to-do application that organi ...)
-	TODO: check
+	- joplin <itp> (bug #931306)
 CVE-2026-48976 (HomeBox is a home inventory and organization system. Prior to 0.26.0,  ...)
-	TODO: check
+	NOT-FOR-US: HomeBox
 CVE-2026-48975 (HomeBox is a home inventory and organization system. Prior to 0.26.0,  ...)
-	TODO: check
+	NOT-FOR-US: HomeBox
 CVE-2026-48974 (HomeBox is a home inventory and organization system. Prior to 0.26.0,  ...)
-	TODO: check
+	NOT-FOR-US: HomeBox
 CVE-2026-48826 (HomeBox is a home inventory and organization system. Prior to 0.26.0,  ...)
-	TODO: check
+	NOT-FOR-US: HomeBox
 CVE-2026-46650 (Joplin is an open source note-taking and to-do application that organi ...)
-	TODO: check
+	- joplin <itp> (bug #931306)
 CVE-2026-46649 (Joplin is an open source note-taking and to-do application that organi ...)
-	TODO: check
+	- joplin <itp> (bug #931306)
 CVE-2026-45381 (Tautulli is a Python based monitoring and tracking tool for Plex Media ...)
-	TODO: check
+	NOT-FOR-US: Tautulli
 CVE-2026-36472 (CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper ...)
-	TODO: check
+	NOT-FOR-US: CuteNews
 CVE-2026-36471 (Deserialization of Untrusted Data of the __post_data parameter in cn_p ...)
-	TODO: check
+	NOT-FOR-US: CuteNews
 CVE-2026-36470 (CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index. ...)
-	TODO: check
+	NOT-FOR-US: CuteNews
 CVE-2026-36469 (CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) i ...)
-	TODO: check
+	NOT-FOR-US: CuteNews
 CVE-2026-36468 (Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows rem ...)
-	TODO: check
+	NOT-FOR-US: CuteNews
 CVE-2026-36467 (Unrestricted Upload of File with Dangerous Type in core/modules/media. ...)
-	TODO: check
+	NOT-FOR-US: CuteNews
 CVE-2026-19658 (The Give Tributes plugin for WordPress is vulnerable to PHP Object Inj ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-17054 (The Espressif ESP-hosted Wi-Fi driver (drivers/wifi/esp_hosted/) parse ...)
@@ -2281,7 +2281,7 @@ CVE-2026-17050 (The experimental USB host stack allocates a per-device configura
 CVE-2026-16652 (Temporal Server did not bound the work performed while searching for a ...)
 	TODO: check
 CVE-2026-16651 (temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNex ...)
-	TODO: check
+	NOT-FOR-US: temporalio/sqlparser
 CVE-2026-15890 (The default AEAD nonce provider for the PSA Internal Trusted Storage t ...)
 	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-13355 (The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escal ...)
@@ -2289,13 +2289,13 @@ CVE-2026-13355 (The Meta Box AIO plugin for WordPress is vulnerable to Privilege
 CVE-2026-12470 (The CMP \u2013 Coming Soon & Maintenance Plugin by NiteoThemes plugin  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2025-71421 (UVdesk core-framework before 1.1.7 contains an improper privilege mana ...)
-	TODO: check
+	NOT-FOR-US: UVdesk core-framework
 CVE-2025-71420 (UVdesk core-framework before 1.1.7 contains an authorization bypass vu ...)
-	TODO: check
+	NOT-FOR-US: UVdesk core-framework
 CVE-2025-71419 (UVdesk core-framework before 1.1.7 contains a stored cross-site script ...)
-	TODO: check
+	NOT-FOR-US: UVdesk core-framework
 CVE-2025-12999 (UrlUtil.getBaseUrl builds the absolute URLs in a response \u2014 downl ...)
-	TODO: check
+	NOT-FOR-US: Open VSX
 CVE-2026-80110 (A flaw was found in pki-core. The v2 REST ACL filter selects a tie-bre ...)
 	- dogtag-pki <removed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2523749



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8bd11420b2b7994c17de29a684134f183e884710

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8bd11420b2b7994c17de29a684134f183e884710
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260923/a636619f/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list