[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Sep 24 08:57:27 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f939d584 by Moritz Muehlenhoff at 2026-09-24T09:57:09+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -403,7 +403,7 @@ CVE-2026-91789 (Foxit PDF Editor/Reader\u2019s U3D/GIF texture decoding path con
 CVE-2026-91788 (When implementing the JavaScript interface, Foxit PDF Editor/Reader di ...)
 	NOT-FOR-US: Foxit
 CVE-2026-91775 (LimeSurvey fails to safely encode attacker-controlled content from a c ...)
-	TODO: check
+	- limesurvey <itp> (bug #472802)
 CVE-2026-90950 (The Paid Membership Subscriptions WordPress plugin before 3.1.0 does n ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-90905 (Joomla Extension - joomshaper.com - Missing CSRF and Access Control on ...)
@@ -429,7 +429,7 @@ CVE-2026-89004 (The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 do
 CVE-2026-89002 (The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-88974 (WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-88847 (The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.50 d ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-88846 (The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.50 d ...)
@@ -513,39 +513,39 @@ CVE-2026-84789 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 1
 CVE-2026-84787 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.71 ...)
 	NOT-FOR-US: Zoho
 CVE-2026-84724 (An argument-injection flaw was found in the Ansible Automation Platfor ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2026-84721 (A server-side request forgery flaw was found in the Ansible Automation ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2026-84720 (A flaw was found in the Ansible Automation Platform automation-control ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2026-84719 (A flaw was found in the Ansible Automation Platform automation-control ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2026-84718 (A flaw was found in the Ansible Automation Platform automation-control ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2026-84717 (A flaw was found in the Ansible Automation Platform automation-control ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2026-84716 (A flaw was found in the automation-controller instance                 ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2026-84714 (A flaw was found in the automation-controller input-validation         ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2026-84713 (A flaw was found in the automation-controller notification             ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2026-84712 (A flaw was found in the automation-controller API. The                 ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2026-84706 (A flaw was found in Ansible Automation Platform's automation-controlle ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2026-84691 (A flaw was found in Red Hat Ansible Automation Platform's automation-  ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2026-84683 (A flaw was found in Red Hat Ansible Automation Platform's automation-  ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2026-84502 (A flaw was found in Red Hat Ansible Automation Platform's automation-  ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2026-84499 (A flaw was found in Red Hat Ansible Automation Platform's automation-  ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2026-84486 (A flaw was found in Red Hat Ansible Automation Platform's automation-  ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2026-84474 (A flaw was found in Red Hat Ansible Automation Platform's automation-  ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2026-84151 (The Post Grid  WordPress plugin before 7.9.5 does not limit an expansi ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-84091 (The SUMIT Payment Gateway for WooCommerce WordPress plugin before 4.0. ...)
@@ -601,15 +601,15 @@ CVE-2026-79616 (Out-of-bounds read while parsing untrusted SVG path strings in Q
 CVE-2026-79310 (webpy web.py 0.76 is vulnerable to server-side template injection (SST ...)
 	TODO: check
 CVE-2026-79306 (CyberPanel v1.9.1 contains a path traversal vulnerability in the compr ...)
-	TODO: check
+	NOT-FOR-US: CyberPanel
 CVE-2026-79304 (CyberPanel 1.9.1 contains a path traversal vulnerability in the readFi ...)
-	TODO: check
+	NOT-FOR-US: CyberPanel
 CVE-2026-78253 (Uncontrolled recursion in QXmlStreamReader::readElementText() in Qt Gr ...)
 	TODO: check
 CVE-2026-77602 (OpenC3 COSMOS provides the functionality needed to send commands to an ...)
-	TODO: check
+	NOT-FOR-US: OpenC3 COSMOS
 CVE-2026-77601 (OpenC3 COSMOS provides the functionality needed to send commands to an ...)
-	TODO: check
+	NOT-FOR-US: OpenC3 COSMOS
 CVE-2026-77423 (JLine is a Java library for handling console input. From 3.0.0 until 3 ...)
 	TODO: check
 CVE-2026-77422 (JLine is a Java library for handling console input. From 3.0.0 until 3 ...)
@@ -619,9 +619,9 @@ CVE-2026-77421 (JLine is a Java library for handling console input. From 3.0.0 u
 CVE-2026-77420 (JLine is a Java library for handling console input. From 3.0.0 until 3 ...)
 	TODO: check
 CVE-2026-77394 (OpenC3 COSMOS provides the functionality needed to send commands to an ...)
-	TODO: check
+	NOT-FOR-US: OpenC3 COSMOS
 CVE-2026-77285 (OpenBao is an open source identity-based secrets management system. Pr ...)
-	TODO: check
+	- openbao <itp> (bug #1069794)
 CVE-2026-77112 (Server-Side request forgery (SSRF) vulnerability in Global IT Informat ...)
 	TODO: check
 CVE-2026-76980 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.70 ...)
@@ -639,9 +639,9 @@ CVE-2026-76087 (Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23
 CVE-2026-76086 (Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3 ...)
 	NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-75887 (A flaw was found in the OpenShift console. An unauthenticated attacker ...)
-	TODO: check
+	NOT-FOR-US: OpenShift
 CVE-2026-75886 (A flaw was found in openshift/console. An unauthenticated remote attac ...)
-	TODO: check
+	NOT-FOR-US: OpenShift
 CVE-2026-75884 (A flaw was found in AWX. The container group pod_spec_override field u ...)
 	TODO: check
 CVE-2026-75825 (ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the A ...)
@@ -759,17 +759,17 @@ CVE-2026-66068 (RabbitMQ is a messaging and streaming broker. Prior to versions
 CVE-2026-66067 (RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7  ...)
 	TODO: check
 CVE-2026-63132 (OpenBao is an open source identity-based secrets management system. Pr ...)
-	TODO: check
+	- openbao <itp> (bug #1069794)
 CVE-2026-63131 (OpenBao is an open source identity-based secrets management system. Pr ...)
-	TODO: check
+	- openbao <itp> (bug #1069794)
 CVE-2026-63002 (REDAXO is a PHP-based content management system. Prior to 5.21.2, reda ...)
-	TODO: check
+	NOT-FOR-US: REDAXO
 CVE-2026-63001 (REDAXO is a PHP-based content management system. Prior to 5.21.2, the  ...)
-	TODO: check
+	NOT-FOR-US: REDAXO
 CVE-2026-63000 (REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_ ...)
-	TODO: check
+	NOT-FOR-US: REDAXO
 CVE-2026-62998 (REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_ ...)
-	TODO: check
+	NOT-FOR-US: REDAXO
 CVE-2026-61834 (scim-patch is a library for applying SCIM patch operations. Prior to 0 ...)
 	TODO: check
 CVE-2026-61814 (Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's AsyncParser ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f939d584d563f09eab270c0d2aba59f51869262c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f939d584d563f09eab270c0d2aba59f51869262c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/37d42092/attachment.htm>


More information about the debian-security-tracker-commits mailing list