[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 25 07:59:04 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e5121407 by Salvatore Bonaccorso at 2026-09-25T08:58:52+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -194,15 +194,15 @@ CVE-2026-93541 (An out-of-bounds read in libXi's XQueryDeviceState() in libXi be
 	- libxi <unfixed>
 	NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
 CVE-2026-93425 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
-	TODO: check
+	NOT-FOR-US: Dokploy
 CVE-2026-93405 (Mailspring is a fast, cross-platform, open-source email client. Prior  ...)
-	TODO: check
+	NOT-FOR-US: Mailspring
 CVE-2026-92905 (ZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071  ...)
 	NOT-FOR-US: Zoho
 CVE-2026-92680 (Araxis Merge for Windows version 2011.4074 through 2026.0 stores user- ...)
 	NOT-FOR-US: Araxis Merge
 CVE-2026-91187 (Improper Verification of Cryptographic Signature vulnerability in dash ...)
-	TODO: check
+	NOT-FOR-US: dashbit nimble_zta
 CVE-2026-91161 (OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior ...)
 	NOT-FOR-US: OpenWA
 CVE-2026-91160 (OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior ...)
@@ -224,11 +224,11 @@ CVE-2026-91120 (Discourse is an open-source discussion platform. Prior to 2026.1
 CVE-2026-91119 (Discourse is an open-source discussion platform. Prior to 2026.1.8, 20 ...)
 	NOT-FOR-US: Discourse
 CVE-2026-90959 (A path traversal vulnerability was found in pulpcore. The content uplo ...)
-	TODO: check
+	NOT-FOR-US: pulpcore
 CVE-2026-90481 (In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition ...)
 	NOT-FOR-US: PortSwigger Burp Suite
 CVE-2026-89325 (An uncontrolled search path element in InsightVM assessment content in ...)
-	TODO: check
+	NOT-FOR-US: Rapid7 Insight Agent
 CVE-2026-88916 (Incorrect Authorization vulnerability in T\xdcB\u0130TAK ULAKB\u0130M  ...)
 	NOT-FOR-US: ULAKBIM UlakPDF
 CVE-2026-88907 (Incorrect Authorization vulnerability in T\xdcB\u0130TAK ULAKB\u0130M  ...)
@@ -1667,13 +1667,13 @@ CVE-2026-93526 (Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5
 CVE-2026-93513 (Contributor Insecure Direct Object References (IDOR) in SiteSkite <= 2 ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-93421 (Mesop is a Python-based UI framework that allows users to build web ap ...)
-	TODO: check
+	NOT-FOR-US: Mesop
 CVE-2026-93368 (The Rename wp-login.php to anything you want plugin for WordPress is v ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-93352 (Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for C ...)
 	NOT-FOR-US: Laravel-Mediable
 CVE-2026-93349 (Frictionless through 5.20.0rc1 contains an OS command injection vulner ...)
-	TODO: check
+	NOT-FOR-US: Frictionless
 CVE-2026-92874 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-92730 (LimeSurvey Community Edition 7.0.14 contains a reflected cross-site sc ...)
@@ -1682,7 +1682,7 @@ CVE-2026-92700 (Caddy is an extensible server platform that uses TLS by default.
 	- caddy <undetermined>
 	TODO: check references, refers to GHSA-j8px-rmrx-76h9 which is for CVE-2026-77281
 CVE-2026-92692 (Sulu is an open-source PHP content management system based on the Symf ...)
-	TODO: check
+	NOT-FOR-US: Sulu
 CVE-2026-92628 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-92530 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
@@ -1692,14 +1692,14 @@ CVE-2026-92529 (GitLab has remediated an issue in GitLab EE affecting all versio
 CVE-2026-92470 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-92419 (WEBCON BPS is vulnerable to Insecure Direct Object Reference (IDOR) in ...)
-	TODO: check
+	NOT-FOR-US: WEBCON BPS
 CVE-2026-92378 (A session management vulnerability exists in the Legacy UI Reduced Fun ...)
 	NOT-FOR-US: Canon
 CVE-2026-92284 (Caddy is an extensible server platform that uses TLS by default. In ve ...)
 	- caddy <undetermined>
 	TODO: check references, refers to GHSA-j8px-rmrx-76h9 which is for CVE-2026-77281
 CVE-2026-92164 (Streamlink is a CLI utility which pipes video streams from various ser ...)
-	TODO: check
+	NOT-FOR-US: Streamlink
 CVE-2026-92001 (Improper restriction of recursive entity references in DTDs ('XML enti ...)
 	TODO: check
 CVE-2026-91999 (Improper neutralization of input during web page generation ('cross-si ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e5121407a17bb92e7696a18342f7f94508229ca4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e5121407a17bb92e7696a18342f7f94508229ca4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260925/a620b9a4/attachment.htm>


More information about the debian-security-tracker-commits mailing list