[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Sep 26 09:05:29 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
5c7e300b by Salvatore Bonaccorso at 2026-09-26T10:05:01+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -15,7 +15,7 @@ CVE-2026-96876 (Improper neutralization of input during web page generation ('cr
CVE-2026-96875 (Improper neutralization of input during web page generation ('cross-si ...)
TODO: check
CVE-2026-96795 (Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.exp ...)
- TODO: check
+ NOT-FOR-US: Horilla
CVE-2026-96533 (The Testimonials Widget WordPress plugin through 4.0.4 does not valida ...)
NOT-FOR-US: WordPress plugin
CVE-2026-96532 (The Testimonials Widget WordPress plugin through 4.0.4 does not perfor ...)
@@ -33,9 +33,9 @@ CVE-2026-92411 (The WP Delicious WordPress plugin before 1.10.8 does not valida
CVE-2026-89237 (The Bluff Post WordPress plugin through 1.1.1 does not sanitise and es ...)
NOT-FOR-US: WordPress plugin
CVE-2026-88003 (InvoicePlane is a self-hosted open source application for managing inv ...)
- TODO: check
+ NOT-FOR-US: InvoicePlane
CVE-2026-86066 (Horilla is an HR and CRM software. Prior to 2.0.0, approve_validate_at ...)
- TODO: check
+ NOT-FOR-US: Horilla
CVE-2026-85081 (The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPre ...)
NOT-FOR-US: WordPress plugin
CVE-2026-84097 (The wp-review-slider-pro WordPress plugin before 12.7.12 does not sani ...)
@@ -49,11 +49,11 @@ CVE-2026-7800
CVE-2026-7799
REJECTED
CVE-2026-71483 (Horilla is an HR and CRM software. Prior to 1.6.0, the search paramete ...)
- TODO: check
+ NOT-FOR-US: Horilla
CVE-2026-63432 (Horilla is an HR and CRM software. From 1.0.0 until 1.6.0 and 2.0.0, t ...)
- TODO: check
+ NOT-FOR-US: Horilla
CVE-2026-63431 (Horilla is an HR and CRM software. In 1.5.0-85 and earlier, payroll/vi ...)
- TODO: check
+ NOT-FOR-US: Horilla
CVE-2026-5267 (Ciena Navigator Network Control Suite (NCS) contains an information ex ...)
TODO: check
CVE-2026-57864
@@ -61,7 +61,7 @@ CVE-2026-57864
CVE-2026-57861
REJECTED
CVE-2026-57449 (Actual is a local-first personal finance tool. Prior to 26.7.0, Actual ...)
- TODO: check
+ NOT-FOR-US: Actual
CVE-2026-57443 (SCBE-AETHERMOORE is a geometric AI governance and evaluation framework ...)
TODO: check
CVE-2026-53990
@@ -463,7 +463,7 @@ CVE-2026-95699 (Prior to 9/18/2026, the iSteamX mobile application's AWS policy
CVE-2026-94573 (The Repeater Fields for Elementor Forms plugin for WordPress is vulner ...)
NOT-FOR-US: WordPress plugin
CVE-2026-94445 (A malicious txtar could escape the intended execution context and forc ...)
- TODO: check
+ NOT-FOR-US: golang.org/x/playground
CVE-2026-94376 (The Better Messages \u2013 Chat Rooms, Group Chat, Private Messages & ...)
NOT-FOR-US: WordPress plugin
CVE-2026-93901 (The Optima Express IDX plugin for WordPress is vulnerable to Privilege ...)
@@ -512,7 +512,7 @@ CVE-2026-93306 (IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 throu
CVE-2026-93303 (The HT Contact Form \u2013 Drag & Drop Form Builder for WordPress plug ...)
NOT-FOR-US: WordPress plugin
CVE-2026-93291 (Omni C20 lacks proper certificate validation which could allow an atta ...)
- TODO: check
+ NOT-FOR-US: Omni C20
CVE-2026-93290 (Omni C20 uses hard-coded credentials that could allow an attacker to m ...)
NOT-FOR-US: Omni C20
CVE-2026-93289 (The affected products are vulnerable to command injection attack that ...)
@@ -573,7 +573,7 @@ CVE-2026-87721 (Uncontrolled Resource Consumption (CWE-400 / CWE-407) in the ANT
CVE-2026-87720 (Incorrect Authorization (CWE-863) in project name normalization (Proje ...)
TODO: check
CVE-2026-87118 (The Botslab G980H dash camera firmware contains an out of bounds write ...)
- TODO: check
+ NOT-FOR-US: Botslab G980H dash camera firmware
CVE-2026-86837 (The Bookly WordPress plugin before 28.3 does not properly verify a cus ...)
NOT-FOR-US: WordPress plugin
CVE-2026-85750 (Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote ...)
@@ -585,19 +585,19 @@ CVE-2026-85496 (The Botslab G980H dash camera firmware generates session identif
CVE-2026-85417 (Incomplete property masking in the SANnav logging subsystem permits SN ...)
NOT-FOR-US: Brocade
CVE-2026-85293 (InvoicePlane is a self-hosted open source application for managing inv ...)
- TODO: check
+ NOT-FOR-US: Botslab G980H dash camera firmware
CVE-2026-85292 (InvoicePlane is a self-hosted open source application for managing inv ...)
- TODO: check
+ NOT-FOR-US: InvoicePlane
CVE-2026-85291 (InvoicePlane is a self-hosted open source application for managing inv ...)
- TODO: check
+ NOT-FOR-US: InvoicePlane
CVE-2026-85290 (InvoicePlane is a self-hosted open source application for managing inv ...)
- TODO: check
+ NOT-FOR-US: InvoicePlane
CVE-2026-85289 (InvoicePlane is a self-hosted open source application for managing inv ...)
- TODO: check
+ NOT-FOR-US: InvoicePlane
CVE-2026-85274 (InvoicePlane is a self-hosted open source application for managing inv ...)
- TODO: check
+ NOT-FOR-US: InvoicePlane
CVE-2026-85082 (Root Browser Classic 3.3.0 passes the path of a selected SQLite databa ...)
- TODO: check
+ NOT-FOR-US: Root Browser Classic
CVE-2026-85029 (IBM Guardium Data Protection 12.2 could allow a remote attacker to obt ...)
NOT-FOR-US: IBM
CVE-2026-84893 (IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in th ...)
@@ -623,11 +623,11 @@ CVE-2026-84460 (Zammad is a web based open source helpdesk/customer support syst
CVE-2026-84458 (Zammad is a web based open source helpdesk/customer support system. Pr ...)
- zammad <itp> (bug #841355)
CVE-2026-84403 (The Botslab G980H dash camera firmware does not require authenticated ...)
- TODO: check
+ NOT-FOR-US: Botslab G980H dash camera firmware
CVE-2026-84399 (The Botslab G980H dash camera firmware contains an authorization vulne ...)
- TODO: check
+ NOT-FOR-US: Botslab G980H dash camera firmware
CVE-2026-84283 (Secure Folder 1.2 stores files selected for its password-protected vau ...)
- TODO: check
+ NOT-FOR-US: Secure Folder
CVE-2026-84281 (The Fancy Product Designer plugin for WordPress is vulnerable to Store ...)
NOT-FOR-US: WordPress plugin
CVE-2026-84280 (The Fancy Product Designer plugin for WordPress is vulnerable to Store ...)
@@ -637,19 +637,19 @@ CVE-2026-84279 (The Fancy Product Designer plugin for WordPress is vulnerable to
CVE-2026-83591 (The AMP for WP \u2013 Accelerated Mobile Pages plugin for WordPress is ...)
NOT-FOR-US: WordPress plugin
CVE-2026-82716 (The Botslab G980H dash camera firmware includes sensitive configuratio ...)
- TODO: check
+ NOT-FOR-US: Botslab G980H dash camera firmware
CVE-2026-82708 (The Botslab G980H dash camera firmware contains a path traversal vulne ...)
- TODO: check
+ NOT-FOR-US: Botslab G980H dash camera firmware
CVE-2026-82585 (The Botslab G980H dash camera firmware transmits sensitive information ...)
- TODO: check
+ NOT-FOR-US: Botslab G980H dash camera firmware
CVE-2026-82566 (The Botslab G980H dash camera firmware contains a session management v ...)
- TODO: check
+ NOT-FOR-US: Botslab G980H dash camera firmware
CVE-2026-82372 (Improper handling of sensitive data during IPsec policy creation and m ...)
NOT-FOR-US: Brocade
CVE-2026-82164 (Dell Trusted Device Client, versions prior to 8.1.359.0, contain an In ...)
NOT-FOR-US: Dell / EMC
CVE-2026-81630 (The Botslab G980H dash camera firmware does not adequately verify the ...)
- TODO: check
+ NOT-FOR-US: Botslab G980H dash camera firmware
CVE-2026-80514 (The wpForo Forum WordPress plugin from 3.0.0 before 3.1.6 does not ver ...)
NOT-FOR-US: WordPress plugin
CVE-2026-80432 (Missing Authorization in the drop handling path of the drag and drop p ...)
@@ -659,11 +659,11 @@ CVE-2026-80431 (Out-of-bounds Write in the natural width branch of the text sizi
CVE-2026-80430 (Improper Link Resolution Before File Access in the drag source staging ...)
TODO: check
CVE-2026-79959 (The Botslab G980H dash camera firmware contains a hard-coded root acco ...)
- TODO: check
+ NOT-FOR-US: Botslab G980H dash camera firmware
CVE-2026-79153 (Seclore FileSecure Desktop Client before 3.25.1.0 contains improper ac ...)
- TODO: check
+ NOT-FOR-US: Seclore FileSecure Desktop Client
CVE-2026-78902 (Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE ...)
- TODO: check
+ NOT-FOR-US: Netgate pfSense
CVE-2026-78397 (The Link Library WordPress plugin before 7.9.6 does not validate the d ...)
NOT-FOR-US: WordPress plugin
CVE-2026-78394 (The Link Library WordPress plugin before 7.9.6 does not sanitize a use ...)
@@ -671,25 +671,25 @@ CVE-2026-78394 (The Link Library WordPress plugin before 7.9.6 does not sanitize
CVE-2026-78393 (The Link Library WordPress plugin before 7.9.6 does not properly escap ...)
NOT-FOR-US: WordPress plugin
CVE-2026-77967 (The Botslab G980H dash camera firmware accepts a reusable authenticati ...)
- TODO: check
+ NOT-FOR-US: Botslab G980H dash camera firmware
CVE-2026-75558 (The Botslab G980H dash camera firmware uses a hard-coded cryptographic ...)
- TODO: check
+ NOT-FOR-US: Botslab G980H dash camera firmware
CVE-2026-75553 (Smartphone application Tohoku Electric Power "Yorisou e Net" uses a ha ...)
- TODO: check
+ NOT-FOR-US: Smartphone application Tohoku Electric Power "Yorisou e Net"
CVE-2026-6088 (Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and ...)
- TODO: check
+ NOT-FOR-US: StockAgile
CVE-2026-6087 (Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and ...)
- TODO: check
+ NOT-FOR-US: StockAgile
CVE-2026-6086 (Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and ...)
- TODO: check
+ NOT-FOR-US: StockAgile
CVE-2026-6085 (Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and ...)
- TODO: check
+ NOT-FOR-US: StockAgile
CVE-2026-6084 (Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and ...)
- TODO: check
+ NOT-FOR-US: StockAgile
CVE-2026-6083 (Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and ...)
- TODO: check
+ NOT-FOR-US: StockAgile
CVE-2026-6082 (Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and ...)
- TODO: check
+ NOT-FOR-US: StockAgile
CVE-2026-67421 (RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.1 ...)
- rabbitmq-server <unfixed>
NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-6256-27fm-4rgr
@@ -2776,7 +2776,7 @@ CVE-2026-6544 (IBM Concert 1.0.0 through 3.0.0 allows recursive copying of direc
CVE-2026-67233 (RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.1 ...)
TODO: check
CVE-2026-65827 (Docmost is open-source collaborative wiki and documentation software. ...)
- TODO: check
+ NOT-FOR-US: Docmost
CVE-2026-65422 (A flaw in the authorization mechanism for Media Gateway API in Genetec ...)
NOT-FOR-US: Genetec
CVE-2026-63645 (OpenObserve is a cloud-native observability platform. Prior to 0.90.3, ...)
@@ -2788,35 +2788,35 @@ CVE-2026-63498 (Snipe-IT is an IT asset/license management system. Prior to 8.7.
CVE-2026-63493 (Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a p ...)
- snipe-it <itp> (bug #1005172)
CVE-2026-63203 (Logto is the modern, open-source auth infrastructure for SaaS and AI a ...)
- TODO: check
+ NOT-FOR-US: Logto
CVE-2026-62368 (Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a u ...)
- snipe-it <itp> (bug #1005172)
CVE-2026-62286 (Dozzle is a realtime log viewer for docker containers. Prior to 10.6.7 ...)
- TODO: check
+ NOT-FOR-US: Dozzle
CVE-2026-61825 (code16 Sharp is a Laravel-based framework for building content-managem ...)
- TODO: check
+ NOT-FOR-US: code16 Sharp
CVE-2026-61823 (code16 Sharp is a Laravel-based framework for building content-managem ...)
- TODO: check
+ NOT-FOR-US: code16 Sharp
CVE-2026-61816 (zbateson/mail-mime-parser is a mail mime parser alternative to PHP's i ...)
- TODO: check
+ NOT-FOR-US: zbateson/mail-mime-parser
CVE-2026-61815 (zbateson/mail-mime-parser is a mail mime parser alternative to PHP's i ...)
- TODO: check
+ NOT-FOR-US: zbateson/mail-mime-parser
CVE-2026-61811 (Wazuh is an open-source security platform providing unified XDR and SI ...)
NOT-FOR-US: Wazuh
CVE-2026-61788 (DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle ...)
- TODO: check
+ NOT-FOR-US: DBHub
CVE-2026-61784 (xhtml-purifier is a Node.js library to take in raw/unknown/untrusted H ...)
- TODO: check
+ NOT-FOR-US: xhtml-purifier Node.js module
CVE-2026-61782 (Rsdoctor is a build analyzer tailored for projects built with Rspack. ...)
- TODO: check
+ NOT-FOR-US: Rsdoctor
CVE-2026-61742 (DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle ...)
- TODO: check
+ NOT-FOR-US: DBHub
CVE-2026-61741 (http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances ...)
- TODO: check
+ NOT-FOR-US: http4s-scala-xml
CVE-2026-61732 (Decepticon is an autonomous hacking agent for red teams. Versions prio ...)
- TODO: check
+ NOT-FOR-US: Decepticon
CVE-2026-61604 (The ixo Blockchain is a Layer 1 blockchain that runs on both Testnet a ...)
- TODO: check
+ NOT-FOR-US: ixo Blockchain
CVE-2026-58008 (Stack-based buffer overflow vulnerability in Altera Trusted Firmware o ...)
NOT-FOR-US: Altera
CVE-2026-58007 (Untrusted pointer dereference vulnerability in Altera Trusted Firmware ...)
@@ -2830,7 +2830,7 @@ CVE-2026-58004 (Out-of-bounds read vulnerability in Altera Trusted Firmware on H
CVE-2026-57590 (A missing authorization vulnerability exists in the Task Group APIs of ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-57440 (The EmbedVideo Extension is a MediaWiki extension which adds a parser ...)
- TODO: check
+ NOT-FOR-US: SCBE-AETHERMOORE
CVE-2026-57179 (Python Social Auth is a social authentication/registration mechanism. ...)
TODO: check
CVE-2026-57178 (Python Social Auth is a social authentication/registration mechanism. ...)
@@ -4629,25 +4629,32 @@ CVE-2026-63000 (REDAXO is a PHP-based content management system. Prior to 5.21.2
CVE-2026-62998 (REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_ ...)
NOT-FOR-US: REDAXO
CVE-2026-61834 (scim-patch is a library for applying SCIM patch operations. Prior to 0 ...)
- TODO: check
+ NOT-FOR-US: scim-patch
CVE-2026-61814 (Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's AsyncParser ...)
- TODO: check
+ - jawn <unfixed>
+ NOTE: https://github.com/typelevel/jawn/security/advisories/GHSA-w4cm-gvhj-cgw6
+ NOTE: Fixed by: https://github.com/typelevel/jawn/commit/cddcd5e3387c356b05953f7b2af103d309687e4b (v1.7.0)
CVE-2026-61695 (Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, an ...)
- TODO: check
+ NOT-FOR-US: Wire
CVE-2026-61413 (Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5. ...)
NOT-FOR-US: Dell / EMC
CVE-2026-5696 (Reflected Cross-Site Scripting (XSS) in Microweber. The vulnerability ...)
- TODO: check
+ NOT-FOR-US: Microweber. CMS
CVE-2026-5695 (Arbitrary file upload vulnerability due to a lack of proper validation ...)
- TODO: check
+ NOT-FOR-US: Microweber. CMS
CVE-2026-59990 (Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse methods ...)
- TODO: check
+ - jawn <unfixed>
+ NOTE: https://github.com/typelevel/jawn/security/advisories/GHSA-cc4v-rvgp-2pf3
+ NOTE: Fixed by: https://github.com/typelevel/jawn/commit/191cb3a44e77f1afab439ee636bf66bdf3c54a04 (v1.7.0)
+ NOTE: Fixed by: https://github.com/typelevel/jawn/commit/6219666641f9408498f85868f835e17bd8a72fed (v1.7.0)
+ NOTE: Fxied by: https://github.com/typelevel/jawn/commit/93ac93e9c992c11b4c03d5455d8551f9fb24da1b (v1.7.0)
+ NOTE: Fixed by: https://github.com/typelevel/jawn/commit/f6ace7e0db715de1a8c4618bed9378333a5c2214 (v1.7.0)
CVE-2026-59980 (hpack is an HTTP/2 Header Encoding for Python. Prior to version 4.2.0, ...)
- python-hpack <unfixed> (bug #1148944)
NOTE: https://github.com/python-hyper/hpack/security/advisories/GHSA-8v8h-hg4w-mvq2
NOTE: https://github.com/python-hyper/hpack/commit/8cfb02c547740e16dbfe7aba77bad84b297cec2c (v4.2.0)
CVE-2026-59167 (SunEditor is a lightweight and powerful WYSIWYG editor in vanilla Java ...)
- TODO: check
+ NOT-FOR-US: SunEditor
CVE-2026-57854
REJECTED
CVE-2026-57168
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5c7e300b150a3b2c04c69500aaed91a59209565f
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5c7e300b150a3b2c04c69500aaed91a59209565f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260926/b904d9cd/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list