[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Sep 24 20:16:19 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
73e34305 by security tracker role at 2026-09-24T19:16:12+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -63,7 +63,7 @@ CVE-2026-96744 (Improper neutralization of special elements in data query logic
CVE-2026-96515 (This vulnerability exists in the Netlink ICT HG323RW router due to ins ...)
TODO: check
CVE-2026-95985 (The file write tool in Amazon Kiro IDE versions before 1.0.242 might a ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-95521 (A command injection flaw was found in rpm. Installing or rebuilding a ...)
TODO: check
CVE-2026-95519 (A flaw was found in rpm. An attacker can supply a crafted manifest fil ...)
@@ -99,7 +99,7 @@ CVE-2026-93425 (Dokploy is a free, self-hostable Platform as a Service (PaaS). P
CVE-2026-93405 (Mailspring is a fast, cross-platform, open-source email client. Prior ...)
TODO: check
CVE-2026-92905 (ZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071 ...)
- TODO: check
+ NOT-FOR-US: Zoho
CVE-2026-92680 (Araxis Merge for Windows version 2011.4074 through 2026.0 stores user- ...)
TODO: check
CVE-2026-91187 (Improper Verification of Cryptographic Signature vulnerability in dash ...)
@@ -109,21 +109,21 @@ CVE-2026-91161 (OpenWA is a free, open source, self-hosted WhatsApp API gateway.
CVE-2026-91160 (OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior ...)
TODO: check
CVE-2026-91134 (Discourse is an open-source discussion platform. Prior to 2026.1.8, 20 ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-91133 (Discourse is an open-source discussion platform. Prior to 2026.1.8, 20 ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-91132 (Discourse is an open-source discussion platform. Prior to 2026.1.8, 20 ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-91123 (Discourse is an open-source discussion platform. Prior to 2026.1.8, 20 ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-91122 (Discourse is an open-source discussion platform. Prior to 2026.1.8, 20 ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-91121 (Discourse is an open-source discussion platform. Prior to 2026.1.8, 20 ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-91120 (Discourse is an open-source discussion platform. Prior to 2026.1.8, 20 ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-91119 (Discourse is an open-source discussion platform. Prior to 2026.1.8, 20 ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-90959 (A path traversal vulnerability was found in pulpcore. The content uplo ...)
TODO: check
CVE-2026-90481 (In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition ...)
@@ -147,9 +147,9 @@ CVE-2026-88382 (hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled me
CVE-2026-88378 (QuickJS commit 04be24600 contains a heap out-of-bounds write condition ...)
TODO: check
CVE-2026-88377 (Bento4 1.6.0.0 contains an integer underflow vulnerability in the avcC ...)
- TODO: check
+ NOT-FOR-US: Bento4
CVE-2026-88376 (Bento4 1.6.0.0 contains an integer underflow vulnerability in AP4_Avcc ...)
- TODO: check
+ NOT-FOR-US: Bento4
CVE-2026-88373 (libde265 commit 4d45a6b contains a NULL pointer dereference vulnerabil ...)
TODO: check
CVE-2026-88372 (libsndfile 1.2.2 contains an integer overflow vulnerability in mat4_re ...)
@@ -185,49 +185,49 @@ CVE-2026-88355 (An incorrect buffer size calculation vulnerability exists in tin
CVE-2026-88351 (An integer overflow vulnerability exists in the MPack Node API in MPac ...)
TODO: check
CVE-2026-86860 (ServiceNow has remediated a missing authorization vulnerability that w ...)
- TODO: check
+ NOT-FOR-US: ServiceNow
CVE-2026-86859 (ServiceNow has remediated an authorization bypass security issue that ...)
- TODO: check
+ NOT-FOR-US: ServiceNow
CVE-2026-86858 (ServiceNow has remediated an improper access control security issue th ...)
- TODO: check
+ NOT-FOR-US: ServiceNow
CVE-2026-86857 (ServiceNow has remediated an authorization bypass security issue that ...)
- TODO: check
+ NOT-FOR-US: ServiceNow
CVE-2026-85738 (TREK is a collaborative travel planner. Prior to 3.4.0, the checkSsrf ...)
TODO: check
CVE-2026-85682 (The YOP Poll plugin for WordPress is vulnerable to Origin Validation E ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-85057 (ZITADEL is an open source identity management platform. From 3.0.0 unt ...)
TODO: check
CVE-2026-85056 (ZITADEL is an open source identity management platform. From 4.0.0 unt ...)
TODO: check
CVE-2026-84302 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
- TODO: check
+ NOT-FOR-US: Discourse
CVE-2026-82371 (Plaintext exposure of sensitive authentication data in Brocade SANnav ...)
- TODO: check
+ NOT-FOR-US: Brocade
CVE-2026-82157 (Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, cont ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-82094 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-82093 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81552 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81549 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81548 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81547 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81545 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81539 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81508 (ESF-IDF is the Espressif Internet of Things (IOT) Development Framewor ...)
TODO: check
CVE-2026-81473 (Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain a ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-81455 (Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, cont ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-7169 (a vulnerability involving an unchecked search path element in Evope Co ...)
TODO: check
CVE-2026-79766 (Termix is a web-based server management platform with SSH terminal, tu ...)
@@ -249,23 +249,23 @@ CVE-2026-79758 (Termix is a web-based server management platform with SSH termin
CVE-2026-79680 (Authentication bypass vulnerability in the password authentication mec ...)
TODO: check
CVE-2026-78313 (Improper Access Control in DIAEnergie. This issue affects DIAEnergie: ...)
- TODO: check
+ NOT-FOR-US: Delta Electronics
CVE-2026-78312 (Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1 ...)
- TODO: check
+ NOT-FOR-US: Delta Electronics
CVE-2026-78311 (SQL Injection vulnerability in DIAEnergie. This issue affects DIAEner ...)
- TODO: check
+ NOT-FOR-US: Delta Electronics
CVE-2026-78310 (Authorization Bypass Through User-Controlled Key in DIAEnergie. This ...)
- TODO: check
+ NOT-FOR-US: Delta Electronics
CVE-2026-78309 (SQL Injection vulnerability in DIAEnergie. This issue affects DIAEner ...)
- TODO: check
+ NOT-FOR-US: Delta Electronics
CVE-2026-78308 (Improper Authentication vulnerability in DIAEnergie allows Authenticat ...)
- TODO: check
+ NOT-FOR-US: Delta Electronics
CVE-2026-77825 (IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to pat ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-77798 (Velociraptor contains a deadlock condition that may be triggered by au ...)
- TODO: check
+ NOT-FOR-US: Rapid7
CVE-2026-77797 (Velociraptor's prefetch library contains an out of bound vulnerability ...)
- TODO: check
+ NOT-FOR-US: Rapid7
CVE-2026-77707 (Improper certificate validation vulnerability in HAVELSAN Inc. Liman R ...)
TODO: check
CVE-2026-77703 (Key exchange without entity authentication vulnerability in HAVELSAN I ...)
@@ -281,7 +281,7 @@ CVE-2026-77294 (TREK is a collaborative travel planner. Prior to 3.3.0, TREK all
CVE-2026-77293 (TREK is a collaborative travel planner. Prior to 3.3.0, the DELETE /ap ...)
TODO: check
CVE-2026-77193 (The eesy_ID2WP \u2013 Publish InDesign HTML5 plugin for WordPress is v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-76907 (LaSuite Doc is a collaborative note taking, wiki and documentation pla ...)
TODO: check
CVE-2026-75907 (The door access control on a Norwegian Cruise Line asset grants entry ...)
@@ -289,15 +289,15 @@ CVE-2026-75907 (The door access control on a Norwegian Cruise Line asset grants
CVE-2026-73064 (In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker wh ...)
TODO: check
CVE-2026-71540 (Wazuh is an open-source security platform providing unified XDR and SI ...)
- TODO: check
+ NOT-FOR-US: Wazuh
CVE-2026-6544 (IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directorie ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-67233 (RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.1 ...)
TODO: check
CVE-2026-65827 (Docmost is open-source collaborative wiki and documentation software. ...)
TODO: check
CVE-2026-65422 (A flaw in the authorization mechanism for Media Gateway API in Genetec ...)
- TODO: check
+ NOT-FOR-US: Genetec
CVE-2026-63645 (OpenObserve is a cloud-native observability platform. Prior to 0.90.3, ...)
TODO: check
CVE-2026-63630 (BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 ...)
@@ -321,7 +321,7 @@ CVE-2026-61816 (zbateson/mail-mime-parser is a mail mime parser alternative to P
CVE-2026-61815 (zbateson/mail-mime-parser is a mail mime parser alternative to PHP's i ...)
TODO: check
CVE-2026-61811 (Wazuh is an open-source security platform providing unified XDR and SI ...)
- TODO: check
+ NOT-FOR-US: Wazuh
CVE-2026-61788 (DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle ...)
TODO: check
CVE-2026-61784 (xhtml-purifier is a Node.js library to take in raw/unknown/untrusted H ...)
@@ -337,17 +337,17 @@ CVE-2026-61732 (Decepticon is an autonomous hacking agent for red teams. Version
CVE-2026-61604 (The ixo Blockchain is a Layer 1 blockchain that runs on both Testnet a ...)
TODO: check
CVE-2026-58008 (Stack-based buffer overflow vulnerability in Altera Trusted Firmware o ...)
- TODO: check
+ NOT-FOR-US: Altera
CVE-2026-58007 (Untrusted pointer dereference vulnerability in Altera Trusted Firmware ...)
- TODO: check
+ NOT-FOR-US: Altera
CVE-2026-58006 (Untrusted pointer dereference vulnerability in Altera Trusted Firmware ...)
- TODO: check
+ NOT-FOR-US: Altera
CVE-2026-58005 (Out-of-bounds read vulnerability in Altera Trusted Firmware on HPS all ...)
- TODO: check
+ NOT-FOR-US: Altera
CVE-2026-58004 (Out-of-bounds read vulnerability in Altera Trusted Firmware on HPS all ...)
- TODO: check
+ NOT-FOR-US: Altera
CVE-2026-57590 (A missing authorization vulnerability exists in the Task Group APIs of ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-57440 (The EmbedVideo Extension is a MediaWiki extension which adds a parser ...)
TODO: check
CVE-2026-57179 (Python Social Auth is a social authentication/registration mechanism. ...)
@@ -361,7 +361,7 @@ CVE-2026-57176 (Python Social Auth is a social authentication/registration mecha
CVE-2026-57175 (Python Social Auth is a social authentication/registration mechanism. ...)
TODO: check
CVE-2026-56792 (Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain a ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-56744 (`@bsv/wallet-toolbox` provides BRC-100 wallet signing and storage comp ...)
TODO: check
CVE-2026-56739 (Logto is the modern, open-source auth infrastructure for SaaS and AI a ...)
@@ -389,7 +389,7 @@ CVE-2026-51995 (An issue in geelen mcp-remote 0.1.32 through 0.1.38 allows a rem
CVE-2026-51994 (mcp-remote versions 0.1.32 through 0.1.38 are vulnerable to Server-Sid ...)
TODO: check
CVE-2026-4806 (The Custom Thank You Page for WooCommerce plugin for WordPress is vuln ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-4638 (PRTG Network Monitor before version 26.2.120.1449 ships a demo EXE/Scr ...)
TODO: check
CVE-2026-4637 (Paessler PRTG Network Monitor before version 26.2.120.1449 is affected ...)
@@ -403,53 +403,53 @@ CVE-2026-48070 (Docmost is open-source collaborative wiki and documentation soft
CVE-2026-47132 (phpMyFAQ is an open source FAQ web application. Prior to version 4.2.0 ...)
TODO: check
CVE-2026-3253 (The MailerLite \u2013 Signup forms (official) plugin for WordPress is ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-26054 (SumatraPDF is a multi-format reader for Windows. Prior to 3.6, the Mob ...)
TODO: check
CVE-2026-19532 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
TODO: check
CVE-2026-19492 (IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19072 (Velociraptor stores the compiled VQL in the hunt object internally to ...)
- TODO: check
+ NOT-FOR-US: Rapid7
CVE-2026-18870 (IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18857 (IBM OPENBMC FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18335 (The Kirki \u2013 Freeform Page Builder, Website Builder & Customizer p ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18104 (IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17511 (IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17504 (IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17503 (IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17413 (IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16302 (The Spectra Legacy \u2013 Gutenberg Blocks plugin for WordPress is vul ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15731 (The WP Multilang \u2013 Translation and Multilingual Plugin plugin for ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13467 (Out-of-bounds write vulnerability in Altera Trusted Firmware on HPS al ...)
- TODO: check
+ NOT-FOR-US: Altera
CVE-2026-13466 (Incorrect calculation of buffer size vulnerability in Altera Trusted F ...)
- TODO: check
+ NOT-FOR-US: Altera
CVE-2026-13465 (Stack-based buffer overflow vulnerability in Altera Trusted Firmware o ...)
- TODO: check
+ NOT-FOR-US: Altera
CVE-2026-13249 (An unauthenticated Remote Code Execution via Arbitrary File Upload vul ...)
- TODO: check
+ NOT-FOR-US: Honeywell
CVE-2026-13248 (An Authenticated Remote Code Execution via Arbitrary File Write in the ...)
- TODO: check
+ NOT-FOR-US: Honeywell
CVE-2026-13016 (ServiceNow has remediated a SQL injection vulnerability that was ident ...)
- TODO: check
+ NOT-FOR-US: ServiceNow
CVE-2026-12559 (A Stored Cross-Site Scripting (XSS) vulnerability has been identified ...)
- TODO: check
+ NOT-FOR-US: OpenText
CVE-2026-12227 (The Visual Composer Website Builder plugin for WordPress is vulnerable ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2025-32000 (HCL Sametime is vulnerable to insufficient input sanitization. The app ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-97404 (In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Si ...)
- zaqar <unfixed> (bug #1148897)
NOTE: https://security.openstack.org/ossa/OSSA-2026-042.html
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/73e34305b3c11c5429bc3fa61997adee1b5c3800
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/73e34305b3c11c5429bc3fa61997adee1b5c3800
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/7dd22f4c/attachment.htm>
More information about the debian-security-tracker-commits
mailing list