[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 25 12:44:40 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
13a12164 by Salvatore Bonaccorso at 2026-09-25T13:44:20+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -319,7 +319,7 @@ CVE-2026-88357 (nDPI 5.1.0 contains a memory access issue in the DNS dissector a
 	NOTE: https://github.com/ntop/nDPI/issues/3213
 	NOTE: https://github.com/ntop/nDPI/pull/3231
 CVE-2026-88355 (An incorrect buffer size calculation vulnerability exists in tinyexpr  ...)
-	TODO: check
+	NOT-FOR-US: tinyexpr
 CVE-2026-88351 (An integer overflow vulnerability exists in the MPack Node API in MPac ...)
 	TODO: check
 CVE-2026-86860 (ServiceNow has remediated a missing authorization vulnerability that w ...)
@@ -361,7 +361,7 @@ CVE-2026-81545 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote
 CVE-2026-81539 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
 	NOT-FOR-US: IBM
 CVE-2026-81508 (ESF-IDF is the Espressif Internet of Things (IOT) Development Framewor ...)
-	TODO: check
+	NOT-FOR-US: ESF-IDF
 CVE-2026-81473 (Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain a ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-81455 (Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, cont ...)
@@ -405,25 +405,25 @@ CVE-2026-77798 (Velociraptor contains a deadlock condition that may be triggered
 CVE-2026-77797 (Velociraptor's prefetch library contains an out of bound vulnerability ...)
 	NOT-FOR-US: Rapid7
 CVE-2026-77707 (Improper certificate validation vulnerability in HAVELSAN Inc. Liman R ...)
-	TODO: check
+	NOT-FOR-US: Liman Render Engine
 CVE-2026-77703 (Key exchange without entity authentication vulnerability in HAVELSAN I ...)
-	TODO: check
+	NOT-FOR-US: Liman Render Engine
 CVE-2026-77581 (BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6  ...)
-	TODO: check
+	NOT-FOR-US: BentoPDF
 CVE-2026-77321 (TREK is a collaborative travel planner. Prior to 3.3.0, the get_trip_s ...)
-	TODO: check
+	NOT-FOR-US: TREK
 CVE-2026-77320 (TREK is a collaborative travel planner. Prior to 3.3.0, getSharedTripD ...)
-	TODO: check
+	NOT-FOR-US: TREK
 CVE-2026-77294 (TREK is a collaborative travel planner. Prior to 3.3.0, TREK allows an ...)
-	TODO: check
+	NOT-FOR-US: TREK
 CVE-2026-77293 (TREK is a collaborative travel planner. Prior to 3.3.0, the DELETE /ap ...)
-	TODO: check
+	NOT-FOR-US: TREK
 CVE-2026-77193 (The eesy_ID2WP \u2013 Publish InDesign HTML5 plugin for WordPress is v ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-76907 (LaSuite Doc is a collaborative note taking, wiki and documentation pla ...)
-	TODO: check
+	NOT-FOR-US: LaSuite Doc
 CVE-2026-75907 (The door access control on a Norwegian Cruise Line asset grants entry  ...)
-	TODO: check
+	NOT-FOR-US: door access control on a Norwegian Cruise Line
 CVE-2026-73064 (In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker wh ...)
 	TODO: check
 CVE-2026-71540 (Wazuh is an open-source security platform providing unified XDR and SI ...)
@@ -1929,7 +1929,7 @@ CVE-2026-86065 (Klever-Go is the Go implementation of the Klever blockchain prot
 CVE-2026-86064 (Klever-Go is the Go implementation of the Klever blockchain protocol.  ...)
 	NOT-FOR-US: Klever-Go
 CVE-2026-85724 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when patt ...)
-	TODO: check
+	NOT-FOR-US: Moquette
 CVE-2026-85475 (A flaw was found in the Ansible Automation Platform automation control ...)
 	NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2026-84791 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.71 ...)
@@ -2011,7 +2011,7 @@ CVE-2026-81208 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authe
 CVE-2026-80513 (The wpForo Forum WordPress plugin before 3.1.6 does not restrict which ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-80444 (URL redirection to untrusted site ('open redirect') vulnerability in A ...)
-	TODO: check
+	NOT-FOR-US: AVESIS
 CVE-2026-80425 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
 	NOT-FOR-US: IBM
 CVE-2026-80423 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
@@ -2069,7 +2069,7 @@ CVE-2026-77394 (OpenC3 COSMOS provides the functionality needed to send commands
 CVE-2026-77285 (OpenBao is an open source identity-based secrets management system. Pr ...)
 	- openbao <itp> (bug #1069794)
 CVE-2026-77112 (Server-Side request forgery (SSRF) vulnerability in Global IT Informat ...)
-	TODO: check
+	NOT-FOR-US: Weoll
 CVE-2026-76980 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.70 ...)
 	NOT-FOR-US: Zoho
 CVE-2026-76979 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.70 ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/13a12164ee284a121426cdf56c759e5884e567e2

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/13a12164ee284a121426cdf56c759e5884e567e2
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260925/08441eb4/attachment.htm>


More information about the debian-security-tracker-commits mailing list