[Git][security-tracker-team/security-tracker][master] Process CVE-2026-96750 as NFU

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 25 07:15:03 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c0e342dc by Salvatore Bonaccorso at 2026-09-25T08:14:35+02:00
Process CVE-2026-96750 as NFU

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -103,7 +103,7 @@ CVE-2026-97057 (redis-parser through 3.0.0 fails to validate the multi-bulk leng
 CVE-2026-96873 (Improper neutralization of input during web page generation ('cross-si ...)
 	TODO: check
 CVE-2026-96750 (MongoDB Compass can interpolate a database name without escaping into  ...)
-	TODO: check
+	NOT-FOR-US: NOT-FOR-US: mongodb-js (not same as node-mongodb)
 CVE-2026-96749 (An integer overflow in the BSON document encoding component of the Mon ...)
 	TODO: check
 CVE-2026-96748 (PyMongo's connection string parsing decodes percent-encoded characters ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c0e342dc829ea3567458ea04f83143d0fd6d3022

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c0e342dc829ea3567458ea04f83143d0fd6d3022
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260925/355dd26a/attachment.htm>


More information about the debian-security-tracker-commits mailing list