[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Sep 24 13:41:27 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
8e0891d7 by Moritz Muehlenhoff at 2026-09-24T14:40:31+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -204,9 +204,9 @@ CVE-2026-96455 (The Reachy Mini daemon exposes an HTTP API for managing the robo
CVE-2026-96454 (Pake turns a website into a desktop application built on Tauri. Every ...)
NOT-FOR-US: Pake
CVE-2026-96446 (A flaw was found in the Pushed Authorization Request PAR implementatio ...)
- TODO: check
+ - keycloak <itp> (bug #1088287)
CVE-2026-96445 (A flaw was found in the Conditional OTP authenticator of Keycloak, an ...)
- TODO: check
+ - keycloak <itp> (bug #1088287)
CVE-2026-96443 (Insufficient validation of the JDBC driver URL in Apache Doris allows ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-95848 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when a co ...)
@@ -680,7 +680,7 @@ CVE-2026-76979 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 1
CVE-2026-76978 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.70 ...)
NOT-FOR-US: Zoho
CVE-2026-76648 (CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes = (I ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-76089 (Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3 ...)
NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-76087 (Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3 ...)
@@ -692,7 +692,7 @@ CVE-2026-75887 (A flaw was found in the OpenShift console. An unauthenticated at
CVE-2026-75886 (A flaw was found in openshift/console. An unauthenticated remote attac ...)
NOT-FOR-US: OpenShift
CVE-2026-75884 (A flaw was found in AWX. The container group pod_spec_override field u ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-75825 (ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the A ...)
NOT-FOR-US: Zoho
CVE-2026-74991 (The WPForms WordPress plugin before 2.0.2 does not verify that a Stri ...)
@@ -3131,7 +3131,7 @@ CVE-2026-61687 (Hatchet is a platform for orchestrating background tasks, AI age
CVE-2026-61681 (Hatchet is a platform for orchestrating background tasks, AI agents, a ...)
NOT-FOR-US: Hatchet
CVE-2026-61674 (Fluent Bit is a fast and lightweight logs, metrics, and traces process ...)
- TODO: check
+ NOT-FOR-US: Fluent Bit
CVE-2026-61652 (Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to ...)
NOT-FOR-US: Zapros
CVE-2026-61647 (NotebookLM MCP is an MCP server and HTTP service for interacting with ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8e0891d7c95bc3ea2440ea324ce968c09c71deb9
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8e0891d7c95bc3ea2440ea324ce968c09c71deb9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/d54705ed/attachment.htm>
More information about the debian-security-tracker-commits
mailing list