[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Sep 24 22:52:35 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
937d2065 by Moritz Muehlenhoff at 2026-09-24T23:52:17+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -41,13 +41,13 @@ CVE-2026-97185 (A flaw was found in GIMP. When processing a specially crafted GI
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/3016
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/3b5e12f8eb2734f954559fbdaf27d03765cea2e5
CVE-2026-97182 (A security vulnerability has been detected in halo-dev Halo up to 2.25 ...)
- TODO: check
+ NOT-FOR-US: Halo
CVE-2026-97181 (GPM LIGHT developed by ezGlobal has a Sensitive Data Exposure vulnerab ...)
TODO: check
CVE-2026-97179 (A security vulnerability has been detected in O2OA up to 9.5.3/10.0.2. ...)
TODO: check
CVE-2026-97062 (Aureus ERP through 1.6.0 stores uploaded SVG files on its public disk ...)
- TODO: check
+ NOT-FOR-US: Aureus ERP
CVE-2026-97061 (Black Candy through 3.2.1 fails to scope playlist search queries to th ...)
TODO: check
CVE-2026-97059 (DCMTK through 3.7.0 contains a heap over-read vulnerability in Concate ...)
@@ -73,7 +73,7 @@ CVE-2026-96745 (Deserialization of untrusted data in the command monitoring supp
CVE-2026-96744 (Improper neutralization of special elements in data query logic in the ...)
TODO: check
CVE-2026-96515 (This vulnerability exists in the Netlink ICT HG323RW router due to ins ...)
- TODO: check
+ NOT-FOR-US: Netlink
CVE-2026-95985 (The file write tool in Amazon Kiro IDE versions before 1.0.242 might a ...)
NOT-FOR-US: Amazon
CVE-2026-95521 (A command injection flaw was found in rpm. Installing or rebuilding a ...)
@@ -81,15 +81,15 @@ CVE-2026-95521 (A command injection flaw was found in rpm. Installing or rebuild
CVE-2026-95519 (A flaw was found in rpm. An attacker can supply a crafted manifest fil ...)
TODO: check
CVE-2026-94613 (authentik is an open-source identity provider. Prior to 2026.2.7, 2026 ...)
- TODO: check
+ NOT-FOR-US: authentik
CVE-2026-94612 (authentik is an open-source identity provider. Prior to 2026.2.7, 2026 ...)
- TODO: check
+ NOT-FOR-US: authentik
CVE-2026-94611 (authentik is an open-source identity provider. Prior to 2026.2.7, 2026 ...)
- TODO: check
+ NOT-FOR-US: authentik
CVE-2026-94609 (authentik is an open-source identity provider. Prior to 2026.2.7, 2026 ...)
- TODO: check
+ NOT-FOR-US: authentik
CVE-2026-94606 (authentik is an open-source identity provider. Prior to 2026.2.7, 2026 ...)
- TODO: check
+ NOT-FOR-US: authentik
CVE-2026-94604
REJECTED
CVE-2026-94416 (An authorization bypass was found in the Ansible Automation Platform ( ...)
@@ -113,13 +113,13 @@ CVE-2026-93405 (Mailspring is a fast, cross-platform, open-source email client.
CVE-2026-92905 (ZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071 ...)
NOT-FOR-US: Zoho
CVE-2026-92680 (Araxis Merge for Windows version 2011.4074 through 2026.0 stores user- ...)
- TODO: check
+ NOT-FOR-US: Araxis Merge
CVE-2026-91187 (Improper Verification of Cryptographic Signature vulnerability in dash ...)
TODO: check
CVE-2026-91161 (OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior ...)
- TODO: check
+ NOT-FOR-US: OpenWA
CVE-2026-91160 (OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior ...)
- TODO: check
+ NOT-FOR-US: OpenWA
CVE-2026-91134 (Discourse is an open-source discussion platform. Prior to 2026.1.8, 20 ...)
NOT-FOR-US: Discourse
CVE-2026-91133 (Discourse is an open-source discussion platform. Prior to 2026.1.8, 20 ...)
@@ -139,15 +139,15 @@ CVE-2026-91119 (Discourse is an open-source discussion platform. Prior to 2026.1
CVE-2026-90959 (A path traversal vulnerability was found in pulpcore. The content uplo ...)
TODO: check
CVE-2026-90481 (In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition ...)
- TODO: check
+ NOT-FOR-US: PortSwigger Burp Suite
CVE-2026-89325 (An uncontrolled search path element in InsightVM assessment content in ...)
TODO: check
CVE-2026-88916 (Incorrect Authorization vulnerability in T\xdcB\u0130TAK ULAKB\u0130M ...)
- TODO: check
+ NOT-FOR-US: ULAKBIM UlakPDF
CVE-2026-88907 (Incorrect Authorization vulnerability in T\xdcB\u0130TAK ULAKB\u0130M ...)
- TODO: check
+ NOT-FOR-US: ULAKBIM UlakPDF
CVE-2026-88390 (An out-of-bounds write vulnerability in jslGetTokenValueAsString() in ...)
- TODO: check
+ NOT-FOR-US: Espruino
CVE-2026-88385 (Mini-XML 4.0.5 contains a memory leak vulnerability in mxml_load_data( ...)
TODO: check
CVE-2026-88384 (OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ attribut ...)
@@ -173,17 +173,17 @@ CVE-2026-88370 (libconfini 1.16.4 contains a heap out-of-bounds write condition
CVE-2026-88369 (zserge jsmn commit 25647e6 is vulnerable to Buffer Overflow in example ...)
TODO: check
CVE-2026-88368 (NanoSVG commit 239e102ec contains an incorrect numeric conversion vuln ...)
- TODO: check
+ NOT-FOR-US: NanoSVG
CVE-2026-88367 (NanoSVG 239e102ec contains an incorrect numeric conversion vulnerabili ...)
- TODO: check
+ NOT-FOR-US: NanoSVG
CVE-2026-88366 (NanoSVG commit 239e102ec contains an incorrect numeric conversion vuln ...)
- TODO: check
+ NOT-FOR-US: NanoSVG
CVE-2026-88365 (minimp3 commit ea99364f contains an integer overflow vulnerability in ...)
TODO: check
CVE-2026-88362 (MuJS e892c9fdb contains an incorrect numeric conversion vulnerability ...)
TODO: check
CVE-2026-88361 (SumatraPDF 3.6.1 contains an integer overflow vulnerability in EngineM ...)
- TODO: check
+ NOT-FOR-US: SumatraPDF
CVE-2026-88360 (libvips 8.19.0 contains a memory access vulnerability when processing ...)
TODO: check
CVE-2026-88359 (libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_it ...)
@@ -205,13 +205,13 @@ CVE-2026-86858 (ServiceNow has remediated an improper access control security is
CVE-2026-86857 (ServiceNow has remediated an authorization bypass security issue that ...)
NOT-FOR-US: ServiceNow
CVE-2026-85738 (TREK is a collaborative travel planner. Prior to 3.4.0, the checkSsrf ...)
- TODO: check
+ NOT-FOR-US: TREK
CVE-2026-85682 (The YOP Poll plugin for WordPress is vulnerable to Origin Validation E ...)
NOT-FOR-US: WordPress plugin
CVE-2026-85057 (ZITADEL is an open source identity management platform. From 3.0.0 unt ...)
- TODO: check
+ NOT-FOR-US: ZITADEL
CVE-2026-85056 (ZITADEL is an open source identity management platform. From 4.0.0 unt ...)
- TODO: check
+ NOT-FOR-US: ZITADEL
CVE-2026-84302 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
NOT-FOR-US: Discourse
CVE-2026-82371 (Plaintext exposure of sensitive authentication data in Brocade SANnav ...)
@@ -243,21 +243,21 @@ CVE-2026-81455 (Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10
CVE-2026-7169 (a vulnerability involving an unchecked search path element in Evope Co ...)
TODO: check
CVE-2026-79766 (Termix is a web-based server management platform with SSH terminal, tu ...)
- TODO: check
+ NOT-FOR-US: Termix
CVE-2026-79764 (Termix is a web-based server management platform with SSH terminal, tu ...)
- TODO: check
+ NOT-FOR-US: Termix
CVE-2026-79763 (Termix is a web-based server management platform with SSH terminal, tu ...)
- TODO: check
+ NOT-FOR-US: Termix
CVE-2026-79762 (Termix is a web-based server management platform with SSH terminal, tu ...)
- TODO: check
+ NOT-FOR-US: Termix
CVE-2026-79761 (Termix is a web-based server management platform with SSH terminal, tu ...)
- TODO: check
+ NOT-FOR-US: Termix
CVE-2026-79760 (Termix is a web-based server management platform with SSH terminal, tu ...)
- TODO: check
+ NOT-FOR-US: Termix
CVE-2026-79759 (Termix is a web-based server management platform with SSH terminal, tu ...)
- TODO: check
+ NOT-FOR-US: Termix
CVE-2026-79758 (Termix is a web-based server management platform with SSH terminal, tu ...)
- TODO: check
+ NOT-FOR-US: Termix
CVE-2026-79680 (Authentication bypass vulnerability in the password authentication mec ...)
TODO: check
CVE-2026-78313 (Improper Access Control in DIAEnergie. This issue affects DIAEnergie: ...)
@@ -387,39 +387,39 @@ CVE-2026-56736 (phpMyFAQ is an open source FAQ web application. A stored cross-s
CVE-2026-54461 (Habitica is a habit tracker application that treats goals like a role- ...)
TODO: check
CVE-2026-52853 (Docmost is open-source collaborative wiki and documentation software. ...)
- TODO: check
+ NOT-FOR-US: Docmost
CVE-2026-52850 (Docmost is open-source collaborative wiki and documentation software. ...)
- TODO: check
+ NOT-FOR-US: Docmost
CVE-2026-52001 (An issue in geelen mcp-remote 0.1.18 through 0.1.38 allows a remote at ...)
- TODO: check
+ NOT-FOR-US: mcp-remote
CVE-2026-51997 (An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote at ...)
- TODO: check
+ NOT-FOR-US: mcp-remote
CVE-2026-51996 (An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote at ...)
- TODO: check
+ NOT-FOR-US: mcp-remote
CVE-2026-51995 (An issue in geelen mcp-remote 0.1.32 through 0.1.38 allows a remote at ...)
- TODO: check
+ NOT-FOR-US: mcp-remote
CVE-2026-51994 (mcp-remote versions 0.1.32 through 0.1.38 are vulnerable to Server-Sid ...)
- TODO: check
+ NOT-FOR-US: mcp-remote
CVE-2026-4806 (The Custom Thank You Page for WooCommerce plugin for WordPress is vuln ...)
NOT-FOR-US: WordPress plugin
CVE-2026-4638 (PRTG Network Monitor before version 26.2.120.1449 ships a demo EXE/Scr ...)
- TODO: check
+ NOT-FOR-US: Paessler PRTG Network Monitor
CVE-2026-4637 (Paessler PRTG Network Monitor before version 26.2.120.1449 is affected ...)
- TODO: check
+ NOT-FOR-US: Paessler PRTG Network Monitor
CVE-2026-48073 (Docmost is open-source collaborative wiki and documentation software. ...)
- TODO: check
+ NOT-FOR-US: Docmost
CVE-2026-48072 (Docmost is open-source collaborative wiki and documentation software. ...)
- TODO: check
+ NOT-FOR-US: Docmost
CVE-2026-48070 (Docmost is open-source collaborative wiki and documentation software. ...)
- TODO: check
+ NOT-FOR-US: Docmost
CVE-2026-47132 (phpMyFAQ is an open source FAQ web application. Prior to version 4.2.0 ...)
- TODO: check
+ NOT-FOR-US: phpMyFAQ
CVE-2026-3253 (The MailerLite \u2013 Signup forms (official) plugin for WordPress is ...)
NOT-FOR-US: WordPress plugin
CVE-2026-26054 (SumatraPDF is a multi-format reader for Windows. Prior to 3.6, the Mob ...)
- TODO: check
+ NOT-FOR-US: SumatraPDF
CVE-2026-19532 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
- TODO: check
+ NOT-FOR-US: Liman MYS
CVE-2026-19492 (IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through ...)
NOT-FOR-US: IBM
CVE-2026-19072 (Velociraptor stores the compiled VQL in the hunt object internally to ...)
@@ -1556,7 +1556,7 @@ CVE-2026-93773 (Contributor SQL Injection in Mollie Forms <= 2.11.0 versions.)
CVE-2026-93772 (Subscriber Cross Site Scripting (XSS) in wpForo Forum <= 3.1.5 version ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-93769 (HumHub 1.18.5 is affected by a stored cross-site scripting (XSS) vulne ...)
- TODO: check
+ NOT-FOR-US: HumHub
CVE-2026-93662 (The Events Manager WordPress plugin before 7.4.5 does not force the s ...)
NOT-FOR-US: WordPress plugin
CVE-2026-93661 (The Events Manager WordPress plugin before 7.4.5 does not stop a tick ...)
@@ -1584,13 +1584,13 @@ CVE-2026-93421 (Mesop is a Python-based UI framework that allows users to build
CVE-2026-93368 (The Rename wp-login.php to anything you want plugin for WordPress is v ...)
NOT-FOR-US: WordPress plugin
CVE-2026-93352 (Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for C ...)
- TODO: check
+ NOT-FOR-US: Laravel-Mediable
CVE-2026-93349 (Frictionless through 5.20.0rc1 contains an OS command injection vulner ...)
TODO: check
CVE-2026-92874 (GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-92730 (LimeSurvey Community Edition 7.0.14 contains a reflected cross-site sc ...)
- TODO: check
+ - limesurvey <itp> (bug #472802)
CVE-2026-92700 (Caddy is an extensible server platform that uses TLS by default. In ve ...)
- caddy <undetermined>
TODO: check references, refers to GHSA-j8px-rmrx-76h9 which is for CVE-2026-77281
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/937d20651f13167b63774ff639f1da65bfb3b6b7
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/937d20651f13167b63774ff639f1da65bfb3b6b7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/3cf0650a/attachment.htm>
More information about the debian-security-tracker-commits
mailing list