[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Sep 24 10:44:00 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
7044cdae by Salvatore Bonaccorso at 2026-09-24T11:43:50+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -121,7 +121,7 @@ CVE-2026-96673 (Photoview through 2.4.0 contains an SQL injection vulnerability
CVE-2026-96672 (Frappe ERPNext versions before 16.34.1 fail to validate that Financial ...)
NOT-FOR-US: Frappe ERPNext
CVE-2026-96656 (Plex Media Server before 1.43.3.10861 allows an admin user to write ar ...)
- TODO: check
+ NOT-FOR-US: Plex Media Server
CVE-2026-96655 (Plex Media Server before 1.43.3.10861 allows an authenticated user to ...)
NOT-FOR-US: Plex Media Server
CVE-2026-96654 (Plex Media Server before 1.43.3.10861 does not correctly neutralize UR ...)
@@ -137,37 +137,37 @@ CVE-2026-96611 (FFmpeg before 9.0 has a signed integer overflow in libavformat/m
NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/31a192f5dd75be9f7520db29ce44fa8f36ae8ba3 (n8.1.2)
NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/15396fa8d550cd19e8619cca919ea09ecbe84ef6 (n7.1.5)
CVE-2026-96609 (Robur Albatross 1.0.0 through 2.x before 2.7.2 does not limit use of t ...)
- TODO: check
+ NOT-FOR-US: Robur Albatross
CVE-2026-96606 (A security flaw has been discovered in LB-Link BL-CPE600EU 5.8.13. Thi ...)
- TODO: check
+ NOT-FOR-US: LB-Link BL-CPE600EU
CVE-2026-96604 (A vulnerability was identified in SoftNews Media Group DataLife Engine ...)
- TODO: check
+ NOT-FOR-US: SoftNews Media Group DataLife Engine
CVE-2026-96603 (A vulnerability has been found in Abdurrab5 online-makeup-store. Affec ...)
- TODO: check
+ NOT-FOR-US: Abdurrab5 online-makeup-store
CVE-2026-96602 (A flaw has been found in Abdurrab5 online-makeup-store. This impacts a ...)
- TODO: check
+ NOT-FOR-US: Abdurrab5 online-makeup-store
CVE-2026-96601 (A vulnerability was detected in Abdurrab5 online-makeup-store. This af ...)
- TODO: check
+ NOT-FOR-US: Abdurrab5 online-makeup-store
CVE-2026-96600 (Isotope eCommerce through 2.9.10 contains a blind SQL injection vulner ...)
- TODO: check
+ NOT-FOR-US: Isotope eCommerce
CVE-2026-96599 (Isotope eCommerce through 2.9.10 derives order identifiers from uniqid ...)
- TODO: check
+ NOT-FOR-US: Isotope eCommerce
CVE-2026-96560 (LightLLM through 1.2.0 contains a remote code execution vulnerability ...)
- TODO: check
+ NOT-FOR-US: LightLLM
CVE-2026-96559
REJECTED
CVE-2026-96556 (A flaw has been found in Neethuharii CafeManagement. Affected by this ...)
- TODO: check
+ NOT-FOR-US: Neethuharii CafeManagement
CVE-2026-96552 (A vulnerability was identified in sfturing hosp_order up to 627f426331 ...)
- TODO: check
+ NOT-FOR-US: sfturing hosp_order
CVE-2026-96551 (A vulnerability was determined in sfturing hosp_order up to 627f426331 ...)
- TODO: check
+ NOT-FOR-US: sfturing hosp_order
CVE-2026-96550 (A vulnerability was found in sfturing hosp_order up to 627f426331da808 ...)
- TODO: check
+ NOT-FOR-US: sfturing hosp_order
CVE-2026-96549 (A vulnerability has been found in sfturing hosp_order up to 627f426331 ...)
- TODO: check
+ NOT-FOR-US: sfturing hosp_order
CVE-2026-96548 (A flaw has been found in sfturing hosp_order up to 627f426331da8086ce8 ...)
- TODO: check
+ NOT-FOR-US: sfturing hosp_order
CVE-2026-96546 (A one-byte out-of-bounds heap read flaw was found in GIMP's uncompress ...)
- gimp <unfixed>
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16802
@@ -186,19 +186,19 @@ CVE-2026-96541 (A denial-of-service flaw was found in gnome-remote-desktop. An u
NOTE: Introduced with: https://gitlab.gnome.org/GNOME/gnome-remote-desktop/-/commit/959cd39ae528a6751d94b0dcff173a470a5bc7ef (50.beta)
NOTE: Issue exists because of an incomplete fix of CVE-2025-5024.
CVE-2026-96514 (A weakness has been identified in Neethuharii CafeManagement. Impacted ...)
- TODO: check
+ NOT-FOR-US: Neethuharii CafeManagement
CVE-2026-96513 (A security flaw has been discovered in Neethuharii CafeManagement. Thi ...)
- TODO: check
+ NOT-FOR-US: Neethuharii CafeManagement
CVE-2026-96512 (A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER ...)
- sudo <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2539327
NOTE: Fixed by: https://github.com/sudo-project/sudo/commit/1820a349687522f51023d1ae5925125f59679a8c
CVE-2026-96456 (The Reachy Mini Bluetooth service asks a connecting device for a PIN b ...)
- TODO: check
+ NOT-FOR-US: Reachy Mini Bluetooth service
CVE-2026-96455 (The Reachy Mini daemon exposes an HTTP API for managing the robot. Its ...)
- TODO: check
+ NOT-FOR-US: Reachy Mini daemon
CVE-2026-96454 (Pake turns a website into a desktop application built on Tauri. Every ...)
- TODO: check
+ NOT-FOR-US: Pake
CVE-2026-96446 (A flaw was found in the Pushed Authorization Request PAR implementatio ...)
TODO: check
CVE-2026-96445 (A flaw was found in the Conditional OTP authenticator of Keycloak, an ...)
@@ -208,27 +208,27 @@ CVE-2026-96443 (Insufficient validation of the JDBC driver URL in Apache Doris a
CVE-2026-96442 (A code execution flaw was found in Emacs, affecting versions prior to ...)
TODO: check
CVE-2026-95848 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when a co ...)
- TODO: check
+ NOT-FOR-US: Moquette
CVE-2026-95847 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, H2Persist ...)
- TODO: check
+ NOT-FOR-US: Moquette
CVE-2026-95846 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffic ...)
- TODO: check
+ NOT-FOR-US: Moquette
CVE-2026-95845 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, the broke ...)
- TODO: check
+ NOT-FOR-US: Moquette
CVE-2026-95844 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, Moquette ...)
- TODO: check
+ NOT-FOR-US: Moquette
CVE-2026-95843 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffic ...)
- TODO: check
+ NOT-FOR-US: Moquette
CVE-2026-95842 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, SessionEv ...)
- TODO: check
+ NOT-FOR-US: Moquette
CVE-2026-95676 (A missing/improper authentication vulnerability in the WatchGuard Auth ...)
NOT-FOR-US: WatchGuard
CVE-2026-95627 (When a Tauri application uses the dialog plugin's file or folder picke ...)
- TODO: check
+ NOT-FOR-US: Tauri
CVE-2026-95626 (Tauri's Content Security Policy hardening, which injects a random nonc ...)
- TODO: check
+ NOT-FOR-US: Tauri
CVE-2026-95625 (The Tauri updater plugin verifies update binaries using minisign signa ...)
- TODO: check
+ NOT-FOR-US: Tauri
CVE-2026-95604 (Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versio ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-95603 (Shop manager PHP Object Injection in Reycob Product Import Export <= 2 ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7044cdaef16475fdf2a4920edbd6998c29cbaae0
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7044cdaef16475fdf2a4920edbd6998c29cbaae0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/c94381b4/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list