[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Sep 24 22:52:35 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
937d2065 by Moritz Muehlenhoff at 2026-09-24T23:52:17+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -41,13 +41,13 @@ CVE-2026-97185 (A flaw was found in GIMP. When processing a specially crafted GI
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/3016
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/3b5e12f8eb2734f954559fbdaf27d03765cea2e5
 CVE-2026-97182 (A security vulnerability has been detected in halo-dev Halo up to 2.25 ...)
-	TODO: check
+	NOT-FOR-US: Halo
 CVE-2026-97181 (GPM LIGHT developed by ezGlobal has a Sensitive Data Exposure vulnerab ...)
 	TODO: check
 CVE-2026-97179 (A security vulnerability has been detected in O2OA up to 9.5.3/10.0.2. ...)
 	TODO: check
 CVE-2026-97062 (Aureus ERP through 1.6.0 stores uploaded SVG files on its public disk  ...)
-	TODO: check
+	NOT-FOR-US: Aureus ERP
 CVE-2026-97061 (Black Candy through 3.2.1 fails to scope playlist search queries to th ...)
 	TODO: check
 CVE-2026-97059 (DCMTK through 3.7.0 contains a heap over-read vulnerability in Concate ...)
@@ -73,7 +73,7 @@ CVE-2026-96745 (Deserialization of untrusted data in the command monitoring supp
 CVE-2026-96744 (Improper neutralization of special elements in data query logic in the ...)
 	TODO: check
 CVE-2026-96515 (This vulnerability exists in the Netlink ICT HG323RW router due to ins ...)
-	TODO: check
+	NOT-FOR-US: Netlink
 CVE-2026-95985 (The file write tool in Amazon Kiro IDE versions before 1.0.242 might a ...)
 	NOT-FOR-US: Amazon
 CVE-2026-95521 (A command injection flaw was found in rpm. Installing or rebuilding a  ...)
@@ -81,15 +81,15 @@ CVE-2026-95521 (A command injection flaw was found in rpm. Installing or rebuild
 CVE-2026-95519 (A flaw was found in rpm. An attacker can supply a crafted manifest fil ...)
 	TODO: check
 CVE-2026-94613 (authentik is an open-source identity provider. Prior to 2026.2.7, 2026 ...)
-	TODO: check
+	NOT-FOR-US: authentik
 CVE-2026-94612 (authentik is an open-source identity provider. Prior to 2026.2.7, 2026 ...)
-	TODO: check
+	NOT-FOR-US: authentik
 CVE-2026-94611 (authentik is an open-source identity provider. Prior to 2026.2.7, 2026 ...)
-	TODO: check
+	NOT-FOR-US: authentik
 CVE-2026-94609 (authentik is an open-source identity provider. Prior to 2026.2.7, 2026 ...)
-	TODO: check
+	NOT-FOR-US: authentik
 CVE-2026-94606 (authentik is an open-source identity provider. Prior to 2026.2.7, 2026 ...)
-	TODO: check
+	NOT-FOR-US: authentik
 CVE-2026-94604
 	REJECTED
 CVE-2026-94416 (An authorization bypass was found in the Ansible Automation Platform ( ...)
@@ -113,13 +113,13 @@ CVE-2026-93405 (Mailspring is a fast, cross-platform, open-source email client.
 CVE-2026-92905 (ZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071  ...)
 	NOT-FOR-US: Zoho
 CVE-2026-92680 (Araxis Merge for Windows version 2011.4074 through 2026.0 stores user- ...)
-	TODO: check
+	NOT-FOR-US: Araxis Merge
 CVE-2026-91187 (Improper Verification of Cryptographic Signature vulnerability in dash ...)
 	TODO: check
 CVE-2026-91161 (OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior ...)
-	TODO: check
+	NOT-FOR-US: OpenWA
 CVE-2026-91160 (OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior ...)
-	TODO: check
+	NOT-FOR-US: OpenWA
 CVE-2026-91134 (Discourse is an open-source discussion platform. Prior to 2026.1.8, 20 ...)
 	NOT-FOR-US: Discourse
 CVE-2026-91133 (Discourse is an open-source discussion platform. Prior to 2026.1.8, 20 ...)
@@ -139,15 +139,15 @@ CVE-2026-91119 (Discourse is an open-source discussion platform. Prior to 2026.1
 CVE-2026-90959 (A path traversal vulnerability was found in pulpcore. The content uplo ...)
 	TODO: check
 CVE-2026-90481 (In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition ...)
-	TODO: check
+	NOT-FOR-US: PortSwigger Burp Suite
 CVE-2026-89325 (An uncontrolled search path element in InsightVM assessment content in ...)
 	TODO: check
 CVE-2026-88916 (Incorrect Authorization vulnerability in T\xdcB\u0130TAK ULAKB\u0130M  ...)
-	TODO: check
+	NOT-FOR-US: ULAKBIM UlakPDF
 CVE-2026-88907 (Incorrect Authorization vulnerability in T\xdcB\u0130TAK ULAKB\u0130M  ...)
-	TODO: check
+	NOT-FOR-US: ULAKBIM UlakPDF
 CVE-2026-88390 (An out-of-bounds write vulnerability in jslGetTokenValueAsString() in  ...)
-	TODO: check
+	NOT-FOR-US: Espruino
 CVE-2026-88385 (Mini-XML 4.0.5 contains a memory leak vulnerability in mxml_load_data( ...)
 	TODO: check
 CVE-2026-88384 (OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ attribut ...)
@@ -173,17 +173,17 @@ CVE-2026-88370 (libconfini 1.16.4 contains a heap out-of-bounds write condition
 CVE-2026-88369 (zserge jsmn commit 25647e6 is vulnerable to Buffer Overflow in example ...)
 	TODO: check
 CVE-2026-88368 (NanoSVG commit 239e102ec contains an incorrect numeric conversion vuln ...)
-	TODO: check
+	NOT-FOR-US: NanoSVG
 CVE-2026-88367 (NanoSVG 239e102ec contains an incorrect numeric conversion vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: NanoSVG
 CVE-2026-88366 (NanoSVG commit 239e102ec contains an incorrect numeric conversion vuln ...)
-	TODO: check
+	NOT-FOR-US: NanoSVG
 CVE-2026-88365 (minimp3 commit ea99364f contains an integer overflow vulnerability in  ...)
 	TODO: check
 CVE-2026-88362 (MuJS e892c9fdb contains an incorrect numeric conversion vulnerability  ...)
 	TODO: check
 CVE-2026-88361 (SumatraPDF 3.6.1 contains an integer overflow vulnerability in EngineM ...)
-	TODO: check
+	NOT-FOR-US: SumatraPDF
 CVE-2026-88360 (libvips 8.19.0 contains a memory access vulnerability when processing  ...)
 	TODO: check
 CVE-2026-88359 (libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_it ...)
@@ -205,13 +205,13 @@ CVE-2026-86858 (ServiceNow has remediated an improper access control security is
 CVE-2026-86857 (ServiceNow has remediated an authorization bypass security issue that  ...)
 	NOT-FOR-US: ServiceNow
 CVE-2026-85738 (TREK is a collaborative travel planner. Prior to 3.4.0, the checkSsrf  ...)
-	TODO: check
+	NOT-FOR-US: TREK
 CVE-2026-85682 (The YOP Poll plugin for WordPress is vulnerable to Origin Validation E ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-85057 (ZITADEL is an open source identity management platform. From 3.0.0 unt ...)
-	TODO: check
+	NOT-FOR-US: ZITADEL
 CVE-2026-85056 (ZITADEL is an open source identity management platform. From 4.0.0 unt ...)
-	TODO: check
+	NOT-FOR-US: ZITADEL
 CVE-2026-84302 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
 	NOT-FOR-US: Discourse
 CVE-2026-82371 (Plaintext exposure of sensitive authentication data in Brocade SANnav  ...)
@@ -243,21 +243,21 @@ CVE-2026-81455 (Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10
 CVE-2026-7169 (a vulnerability involving an unchecked search path element in Evope Co ...)
 	TODO: check
 CVE-2026-79766 (Termix is a web-based server management platform with SSH terminal, tu ...)
-	TODO: check
+	NOT-FOR-US: Termix
 CVE-2026-79764 (Termix is a web-based server management platform with SSH terminal, tu ...)
-	TODO: check
+	NOT-FOR-US: Termix
 CVE-2026-79763 (Termix is a web-based server management platform with SSH terminal, tu ...)
-	TODO: check
+	NOT-FOR-US: Termix
 CVE-2026-79762 (Termix is a web-based server management platform with SSH terminal, tu ...)
-	TODO: check
+	NOT-FOR-US: Termix
 CVE-2026-79761 (Termix is a web-based server management platform with SSH terminal, tu ...)
-	TODO: check
+	NOT-FOR-US: Termix
 CVE-2026-79760 (Termix is a web-based server management platform with SSH terminal, tu ...)
-	TODO: check
+	NOT-FOR-US: Termix
 CVE-2026-79759 (Termix is a web-based server management platform with SSH terminal, tu ...)
-	TODO: check
+	NOT-FOR-US: Termix
 CVE-2026-79758 (Termix is a web-based server management platform with SSH terminal, tu ...)
-	TODO: check
+	NOT-FOR-US: Termix
 CVE-2026-79680 (Authentication bypass vulnerability in the password authentication mec ...)
 	TODO: check
 CVE-2026-78313 (Improper Access Control in DIAEnergie.  This issue affects DIAEnergie: ...)
@@ -387,39 +387,39 @@ CVE-2026-56736 (phpMyFAQ is an open source FAQ web application. A stored cross-s
 CVE-2026-54461 (Habitica is a habit tracker application that treats goals like a role- ...)
 	TODO: check
 CVE-2026-52853 (Docmost is open-source collaborative wiki and documentation software.  ...)
-	TODO: check
+	NOT-FOR-US: Docmost
 CVE-2026-52850 (Docmost is open-source collaborative wiki and documentation software.  ...)
-	TODO: check
+	NOT-FOR-US: Docmost
 CVE-2026-52001 (An issue in geelen mcp-remote 0.1.18 through 0.1.38 allows a remote at ...)
-	TODO: check
+	NOT-FOR-US: mcp-remote
 CVE-2026-51997 (An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote at ...)
-	TODO: check
+	NOT-FOR-US: mcp-remote
 CVE-2026-51996 (An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote at ...)
-	TODO: check
+	NOT-FOR-US: mcp-remote
 CVE-2026-51995 (An issue in geelen mcp-remote 0.1.32 through 0.1.38 allows a remote at ...)
-	TODO: check
+	NOT-FOR-US: mcp-remote
 CVE-2026-51994 (mcp-remote versions 0.1.32 through 0.1.38 are vulnerable to Server-Sid ...)
-	TODO: check
+	NOT-FOR-US: mcp-remote
 CVE-2026-4806 (The Custom Thank You Page for WooCommerce plugin for WordPress is vuln ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-4638 (PRTG Network Monitor before version 26.2.120.1449 ships a demo EXE/Scr ...)
-	TODO: check
+	NOT-FOR-US: Paessler PRTG Network Monitor
 CVE-2026-4637 (Paessler PRTG Network Monitor before version 26.2.120.1449 is affected ...)
-	TODO: check
+	NOT-FOR-US: Paessler PRTG Network Monitor
 CVE-2026-48073 (Docmost is open-source collaborative wiki and documentation software.  ...)
-	TODO: check
+	NOT-FOR-US: Docmost
 CVE-2026-48072 (Docmost is open-source collaborative wiki and documentation software.  ...)
-	TODO: check
+	NOT-FOR-US: Docmost
 CVE-2026-48070 (Docmost is open-source collaborative wiki and documentation software.  ...)
-	TODO: check
+	NOT-FOR-US: Docmost
 CVE-2026-47132 (phpMyFAQ is an open source FAQ web application. Prior to version 4.2.0 ...)
-	TODO: check
+	NOT-FOR-US: phpMyFAQ
 CVE-2026-3253 (The MailerLite \u2013 Signup forms (official) plugin for WordPress is  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-26054 (SumatraPDF is a multi-format reader for Windows. Prior to 3.6, the Mob ...)
-	TODO: check
+	NOT-FOR-US: SumatraPDF
 CVE-2026-19532 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
-	TODO: check
+	NOT-FOR-US: Liman MYS
 CVE-2026-19492 (IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through  ...)
 	NOT-FOR-US: IBM
 CVE-2026-19072 (Velociraptor stores the compiled VQL in the hunt object internally to  ...)
@@ -1556,7 +1556,7 @@ CVE-2026-93773 (Contributor SQL Injection in Mollie Forms <= 2.11.0 versions.)
 CVE-2026-93772 (Subscriber Cross Site Scripting (XSS) in wpForo Forum <= 3.1.5 version ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-93769 (HumHub 1.18.5 is affected by a stored cross-site scripting (XSS) vulne ...)
-	TODO: check
+	NOT-FOR-US: HumHub
 CVE-2026-93662 (The Events Manager  WordPress plugin before 7.4.5 does not force the s ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-93661 (The Events Manager  WordPress plugin before 7.4.5 does not stop a tick ...)
@@ -1584,13 +1584,13 @@ CVE-2026-93421 (Mesop is a Python-based UI framework that allows users to build
 CVE-2026-93368 (The Rename wp-login.php to anything you want plugin for WordPress is v ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-93352 (Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for C ...)
-	TODO: check
+	NOT-FOR-US: Laravel-Mediable
 CVE-2026-93349 (Frictionless through 5.20.0rc1 contains an OS command injection vulner ...)
 	TODO: check
 CVE-2026-92874 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-92730 (LimeSurvey Community Edition 7.0.14 contains a reflected cross-site sc ...)
-	TODO: check
+	- limesurvey <itp> (bug #472802)
 CVE-2026-92700 (Caddy is an extensible server platform that uses TLS by default. In ve ...)
 	- caddy <undetermined>
 	TODO: check references, refers to GHSA-j8px-rmrx-76h9 which is for CVE-2026-77281



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/937d20651f13167b63774ff639f1da65bfb3b6b7

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/937d20651f13167b63774ff639f1da65bfb3b6b7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/3cf0650a/attachment.htm>


More information about the debian-security-tracker-commits mailing list