[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Sep 24 10:44:00 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7044cdae by Salvatore Bonaccorso at 2026-09-24T11:43:50+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -121,7 +121,7 @@ CVE-2026-96673 (Photoview through 2.4.0 contains an SQL injection vulnerability
 CVE-2026-96672 (Frappe ERPNext versions before 16.34.1 fail to validate that Financial ...)
 	NOT-FOR-US: Frappe ERPNext
 CVE-2026-96656 (Plex Media Server before 1.43.3.10861 allows an admin user to write ar ...)
-	TODO: check
+	NOT-FOR-US: Plex Media Server
 CVE-2026-96655 (Plex Media Server before 1.43.3.10861 allows an authenticated user to  ...)
 	NOT-FOR-US: Plex Media Server
 CVE-2026-96654 (Plex Media Server before 1.43.3.10861 does not correctly neutralize UR ...)
@@ -137,37 +137,37 @@ CVE-2026-96611 (FFmpeg before 9.0 has a signed integer overflow in libavformat/m
 	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/31a192f5dd75be9f7520db29ce44fa8f36ae8ba3 (n8.1.2)
 	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/15396fa8d550cd19e8619cca919ea09ecbe84ef6 (n7.1.5)
 CVE-2026-96609 (Robur Albatross 1.0.0 through 2.x before 2.7.2 does not limit use of t ...)
-	TODO: check
+	NOT-FOR-US: Robur Albatross
 CVE-2026-96606 (A security flaw has been discovered in LB-Link BL-CPE600EU 5.8.13. Thi ...)
-	TODO: check
+	NOT-FOR-US: LB-Link BL-CPE600EU
 CVE-2026-96604 (A vulnerability was identified in SoftNews Media Group DataLife Engine ...)
-	TODO: check
+	NOT-FOR-US: SoftNews Media Group DataLife Engine
 CVE-2026-96603 (A vulnerability has been found in Abdurrab5 online-makeup-store. Affec ...)
-	TODO: check
+	NOT-FOR-US: Abdurrab5 online-makeup-store
 CVE-2026-96602 (A flaw has been found in Abdurrab5 online-makeup-store. This impacts a ...)
-	TODO: check
+	NOT-FOR-US: Abdurrab5 online-makeup-store
 CVE-2026-96601 (A vulnerability was detected in Abdurrab5 online-makeup-store. This af ...)
-	TODO: check
+	NOT-FOR-US: Abdurrab5 online-makeup-store
 CVE-2026-96600 (Isotope eCommerce through 2.9.10 contains a blind SQL injection vulner ...)
-	TODO: check
+	NOT-FOR-US: Isotope eCommerce
 CVE-2026-96599 (Isotope eCommerce through 2.9.10 derives order identifiers from uniqid ...)
-	TODO: check
+	NOT-FOR-US: Isotope eCommerce
 CVE-2026-96560 (LightLLM through 1.2.0 contains a remote code execution vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: LightLLM
 CVE-2026-96559
 	REJECTED
 CVE-2026-96556 (A flaw has been found in Neethuharii CafeManagement. Affected by this  ...)
-	TODO: check
+	NOT-FOR-US: Neethuharii CafeManagement
 CVE-2026-96552 (A vulnerability was identified in sfturing hosp_order up to 627f426331 ...)
-	TODO: check
+	NOT-FOR-US: sfturing hosp_order
 CVE-2026-96551 (A vulnerability was determined in sfturing hosp_order up to 627f426331 ...)
-	TODO: check
+	NOT-FOR-US: sfturing hosp_order
 CVE-2026-96550 (A vulnerability was found in sfturing hosp_order up to 627f426331da808 ...)
-	TODO: check
+	NOT-FOR-US: sfturing hosp_order
 CVE-2026-96549 (A vulnerability has been found in sfturing hosp_order up to 627f426331 ...)
-	TODO: check
+	NOT-FOR-US: sfturing hosp_order
 CVE-2026-96548 (A flaw has been found in sfturing hosp_order up to 627f426331da8086ce8 ...)
-	TODO: check
+	NOT-FOR-US: sfturing hosp_order
 CVE-2026-96546 (A one-byte out-of-bounds heap read flaw was found in GIMP's uncompress ...)
 	- gimp <unfixed>
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16802
@@ -186,19 +186,19 @@ CVE-2026-96541 (A denial-of-service flaw was found in gnome-remote-desktop. An u
 	NOTE: Introduced with: https://gitlab.gnome.org/GNOME/gnome-remote-desktop/-/commit/959cd39ae528a6751d94b0dcff173a470a5bc7ef (50.beta)
 	NOTE: Issue exists because of an incomplete fix of CVE-2025-5024.
 CVE-2026-96514 (A weakness has been identified in Neethuharii CafeManagement. Impacted ...)
-	TODO: check
+	NOT-FOR-US: Neethuharii CafeManagement
 CVE-2026-96513 (A security flaw has been discovered in Neethuharii CafeManagement. Thi ...)
-	TODO: check
+	NOT-FOR-US: Neethuharii CafeManagement
 CVE-2026-96512 (A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER ...)
 	- sudo <unfixed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2539327
 	NOTE: Fixed by: https://github.com/sudo-project/sudo/commit/1820a349687522f51023d1ae5925125f59679a8c
 CVE-2026-96456 (The Reachy Mini Bluetooth service asks a connecting device for a PIN b ...)
-	TODO: check
+	NOT-FOR-US: Reachy Mini Bluetooth service
 CVE-2026-96455 (The Reachy Mini daemon exposes an HTTP API for managing the robot. Its ...)
-	TODO: check
+	NOT-FOR-US: Reachy Mini daemon
 CVE-2026-96454 (Pake turns a website into a desktop application built on Tauri. Every  ...)
-	TODO: check
+	NOT-FOR-US: Pake
 CVE-2026-96446 (A flaw was found in the Pushed Authorization Request PAR implementatio ...)
 	TODO: check
 CVE-2026-96445 (A flaw was found in the Conditional OTP authenticator of Keycloak, an  ...)
@@ -208,27 +208,27 @@ CVE-2026-96443 (Insufficient validation of the JDBC driver URL in Apache Doris a
 CVE-2026-96442 (A code execution flaw was found in Emacs, affecting versions prior to  ...)
 	TODO: check
 CVE-2026-95848 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when a co ...)
-	TODO: check
+	NOT-FOR-US: Moquette
 CVE-2026-95847 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, H2Persist ...)
-	TODO: check
+	NOT-FOR-US: Moquette
 CVE-2026-95846 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffic ...)
-	TODO: check
+	NOT-FOR-US: Moquette
 CVE-2026-95845 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, the broke ...)
-	TODO: check
+	NOT-FOR-US: Moquette
 CVE-2026-95844 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, Moquette  ...)
-	TODO: check
+	NOT-FOR-US: Moquette
 CVE-2026-95843 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffic ...)
-	TODO: check
+	NOT-FOR-US: Moquette
 CVE-2026-95842 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, SessionEv ...)
-	TODO: check
+	NOT-FOR-US: Moquette
 CVE-2026-95676 (A missing/improper authentication vulnerability in the WatchGuard Auth ...)
 	NOT-FOR-US: WatchGuard
 CVE-2026-95627 (When a Tauri application uses the dialog plugin's file or folder picke ...)
-	TODO: check
+	NOT-FOR-US: Tauri
 CVE-2026-95626 (Tauri's Content Security Policy hardening, which injects a random nonc ...)
-	TODO: check
+	NOT-FOR-US: Tauri
 CVE-2026-95625 (The Tauri updater plugin verifies update binaries using minisign signa ...)
-	TODO: check
+	NOT-FOR-US: Tauri
 CVE-2026-95604 (Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versio ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-95603 (Shop manager PHP Object Injection in Reycob Product Import Export <= 2 ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7044cdaef16475fdf2a4920edbd6998c29cbaae0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7044cdaef16475fdf2a4920edbd6998c29cbaae0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/c94381b4/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list