[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 26 20:59:16 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ca447bb5 by Salvatore Bonaccorso at 2026-09-26T21:58:59+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -58,15 +58,15 @@ CVE-2026-100709 (Froxlor through 2.3.10 stores only a numeric user ID in remembe
 CVE-2026-100708 (Froxlor before 2.3.13 returns the ssl_key_file column \u2014 which sto ...)
 	- froxlor <itp> (bug #581792)
 CVE-2026-100707 (Kyverno before 1.19.1 contains a namespace isolation bypass in the api ...)
-	TODO: check
+	NOT-FOR-US: Kyverno
 CVE-2026-100706 (kyverno before 1.19.1 fails to properly validate URL-encoded path segm ...)
-	TODO: check
+	NOT-FOR-US: Kyverno
 CVE-2026-100705 (Kyverno before 1.19.1 is vulnerable to server-side request forgery. Th ...)
-	TODO: check
+	NOT-FOR-US: Kyverno
 CVE-2026-100704 (Kyverno is a policy engine for Kubernetes. In versions 1.14.0 through  ...)
-	TODO: check
+	NOT-FOR-US: Kyverno
 CVE-2026-100703 (Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib CEL libr ...)
-	TODO: check
+	NOT-FOR-US: Kyverno
 CVE-2026-100702 (Nodemailer before 10.0.2 fails to properly flatten deeply nested array ...)
 	TODO: check
 CVE-2026-100701 (Nodemailer versions 5.0.0 through 10.0.1 use a process-global DNS cach ...)
@@ -96,49 +96,49 @@ CVE-2026-100690 (Hugo versions from v0.161.0 through v0.165.0 run Node.js tools
 CVE-2026-100689 (GitPython before 3.1.62 does not validate the `path` field read from a ...)
 	TODO: check
 CVE-2026-100688 (Budibase server before 3.45.0 contains a cross-tenant information disc ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-100687 (Budibase Server before 3.45.0 fails to redact plaintext datasource cre ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-100686 (Budibase versions before 3.45.0 fail to validate per-app authorization ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-100685 (Budibase before 3.45.0 fails to properly scope the GET /api/chat-links ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-100684 (Budibase versions 3.41.0 before 3.45.0 contain an authentication bypas ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-100683 (Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL colum ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-100682 (Budibase Server before 3.45.0 contains an arbitrary file write vulnera ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-100681 (Budibase before 3.45.0 contains an unauthenticated server-side request ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-100680 (Budibase versions before 3.45.0 fail to disable external JSON referenc ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-100679 (stoatchat before 0.15.5 fails to validate that MFA tickets belong to t ...)
-	TODO: check
+	NOT-FOR-US: stoatchat
 CVE-2026-100678 (stoatchat before 0.15.5 fails to enforce account-level attempt limits  ...)
-	TODO: check
+	NOT-FOR-US: stoatchat
 CVE-2026-100677 (stoatchat before 0.15.5 contains an account enumeration vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: stoatchat
 CVE-2026-100676 (January, the media proxy/embed service of stoatchat (stoatchat/stoatch ...)
-	TODO: check
+	NOT-FOR-US: stoatchat
 CVE-2026-100675 (stoatchat versions before 0.15.5 contain a denial of service vulnerabi ...)
-	TODO: check
+	NOT-FOR-US: stoatchat
 CVE-2026-100674 (stoatchat before 0.15.5 fails to revalidate usernames after Unicode sa ...)
-	TODO: check
+	NOT-FOR-US: stoatchat
 CVE-2026-100673 (The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) version ...)
-	TODO: check
+	NOT-FOR-US: Grav Data Manager plugin
 CVE-2026-100672 (The Comments plugin (getgrav/grav-plugin-comments) for Grav CMS throug ...)
-	TODO: check
+	NOT-FOR-US: Grav CMS plugin
 CVE-2026-100671 (Grav is a flat-file CMS. In versions 2.0.19 through 2.0.24 \u2014 and  ...)
-	TODO: check
+	NOT-FOR-US: Grav CMS
 CVE-2026-100670 (Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnera ...)
-	TODO: check
+	NOT-FOR-US: Grav CMS
 CVE-2026-100669 (Grav before 2.0.25 ships web server configuration samples whose access ...)
-	TODO: check
+	NOT-FOR-US: Grav CMS
 CVE-2026-100668 (Grav 2.0.0 through 2.0.24 contain a Twig content sandbox escape. The ` ...)
-	TODO: check
+	NOT-FOR-US: Grav CMS
 CVE-2026-100667 (grav-plugin-login (the Grav CMS Login plugin) versions >= 3.8.7 and <  ...)
-	TODO: check
+	NOT-FOR-US: Grav CMS plugin
 CVE-2026-100666 (Netty's HttpServerCodec (io.netty:netty-codec-http) in versions 4.2.0. ...)
 	TODO: check
 CVE-2026-100665 (Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomp ...)
@@ -351,7 +351,7 @@ CVE-2026-63432 (Horilla is an HR and CRM software. From 1.0.0 until 1.6.0 and 2.
 CVE-2026-63431 (Horilla is an HR and CRM software. In 1.5.0-85 and earlier, payroll/vi ...)
 	NOT-FOR-US: Horilla
 CVE-2026-5267 (Ciena Navigator Network Control Suite (NCS) contains an information ex ...)
-	TODO: check
+	NOT-FOR-US: Ciena Navigator Network Control Suite (NCS)
 CVE-2026-57864
 	REJECTED
 CVE-2026-57861
@@ -359,7 +359,7 @@ CVE-2026-57861
 CVE-2026-57449 (Actual is a local-first personal finance tool. Prior to 26.7.0, Actual ...)
 	NOT-FOR-US: Actual
 CVE-2026-57443 (SCBE-AETHERMOORE is a geometric AI governance and evaluation framework ...)
-	TODO: check
+	NOT-FOR-US: SCBE-AETHERMOORE
 CVE-2026-53990
 	REJECTED
 CVE-2026-53973
@@ -399,7 +399,7 @@ CVE-2026-15273 (The Automatic.css plugin for WordPress is vulnerable to Stored C
 CVE-2026-11871 (The Team Members  WordPress plugin through 9.2 does not perform any au ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-10758 (Esri LERC is an open-source image or raster format which supports rapi ...)
-	TODO: check
+	NOT-FOR-US: Esri LERC
 CVE-2026-100599 (OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configur ...)
 	NOT-FOR-US: OpenClaw
 CVE-2026-100598 (OpenClaw (npm package openclaw) before 2026.7.1 incorrectly binds Sign ...)
@@ -880,7 +880,7 @@ CVE-2026-85750 (Piwigo before v16.4.0 is vulnerable to arbitrary file read and r
 CVE-2026-85542 (IBM Guardium Data Protection 12.2 is affected by a command injection v ...)
 	NOT-FOR-US: IBM
 CVE-2026-85496 (The Botslab G980H dash camera firmware generates session identifiers u ...)
-	TODO: check
+	NOT-FOR-US: Botslab G980H dash camera firmware
 CVE-2026-85417 (Incomplete property masking in the SANnav logging subsystem permits SN ...)
 	NOT-FOR-US: Brocade
 CVE-2026-85293 (InvoicePlane is a self-hosted open source application for managing inv ...)
@@ -1165,7 +1165,7 @@ CVE-2026-55217 (GLPI is a free asset and IT management software package. From 0.
 CVE-2026-55214 (GLPI is a free asset and IT management software package. From 11.0.6 u ...)
 	- glpi <removed>
 CVE-2026-54790 (InvoicePlane is a self-hosted open source application for managing inv ...)
-	TODO: check
+	NOT-FOR-US: InvoicePlane
 CVE-2026-53629 (GLPI is a free asset and IT management software package. From 9.4.0 un ...)
 	- glpi <removed>
 CVE-2026-53628 (GLPI is a free asset and IT management software package. From 0.84 unt ...)
@@ -1181,27 +1181,27 @@ CVE-2026-53610 (GLPI is a free asset and IT management software package. From 11
 CVE-2026-53493 (containerd is an open-source container runtime. Prior to versions 1.7. ...)
 	TODO: check
 CVE-2026-52622 (An issue in Wellav Technologies Co., Ltd Wellav WES Emergency Broadcas ...)
-	TODO: check
+	NOT-FOR-US: Wellav
 CVE-2026-51773 (An issue in the VMware datastore driver of OpenStack glance_store. Whe ...)
 	TODO: check
 CVE-2026-51772 (A Server-Side Request Forgery (SSRF) vulnerability exists in the Image ...)
 	TODO: check
 CVE-2026-50547 (InvoicePlane is a self-hosted open source application for managing inv ...)
-	TODO: check
+	NOT-FOR-US: InvoicePlane
 CVE-2026-49850 (InvoicePlane is a self-hosted open source application for managing inv ...)
-	TODO: check
+	NOT-FOR-US: InvoicePlane
 CVE-2026-49470 (GLPI is a free asset and IT management software package. From 11.0.0 u ...)
 	- glpi <removed>
 CVE-2026-49469 (GLPI is a free asset and IT management software package. From 0.70 unt ...)
 	- glpi <removed>
 CVE-2026-48543 (Krayin CRM through 2.2.6 contains a stored client-side template inject ...)
-	TODO: check
+	NOT-FOR-US: Krayin CRM
 CVE-2026-48542 (Krayin CRM through 2.2.6 contains a stored client-side template inject ...)
-	TODO: check
+	NOT-FOR-US: Krayin CRM
 CVE-2026-48541 (Krayin CRM through 2.2.6 contains a stored client-side template inject ...)
-	TODO: check
+	NOT-FOR-US: Krayin CRM
 CVE-2026-48540 (Krayin CRM through 2.2.6 contains a stored client-side template inject ...)
-	TODO: check
+	NOT-FOR-US: Krayin CRM
 CVE-2026-48482 (GLPI is a free asset and IT management software package. From 11.0.0 u ...)
 	- glpi <removed>
 CVE-2026-47679 (GLPI is a free asset and IT management software package. From 10.0.0 u ...)
@@ -1217,23 +1217,23 @@ CVE-2026-42323 (Piwigo is a full featured open source photo gallery application
 CVE-2026-42322 (Piwigo is a full featured open source photo gallery application for th ...)
 	- piwigo <removed>
 CVE-2026-39372 (InvoicePlane is a self-hosted open source application for managing inv ...)
-	TODO: check
+	NOT-FOR-US: InvoicePlane
 CVE-2026-39353 (InvoicePlane is a self-hosted open source application for managing inv ...)
-	TODO: check
+	NOT-FOR-US: InvoicePlane
 CVE-2026-33639 (InvoicePlane is a self-hosted open source application for managing inv ...)
-	TODO: check
+	NOT-FOR-US: InvoicePlane
 CVE-2026-27867 (An attacker with access via network to the Regesta Smart HD-PLC of the ...)
-	TODO: check
+	NOT-FOR-US: Regesta Smart HD-PLC TLDPH16D2
 CVE-2026-19804 (The s2Member \u2013 Excellent for All Kinds of Memberships, Content Re ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-19775 (The OpenStation \u2014 Desktop Windows, Dock & Virtual Desktops for WP ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-18320 (Readwise Reader for Android uses a sanitize-html configuration that pe ...)
-	TODO: check
+	NOT-FOR-US: Readwise Reader for Android
 CVE-2026-18312 (Readwise Reader for Android constructs URLs in its WebView using attac ...)
-	TODO: check
+	NOT-FOR-US: Readwise Reader for Android
 CVE-2026-18311 (Readwise Reader for Android contains a cross-site scripting vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: Readwise Reader for Android
 CVE-2026-17602 (The SSL Zen \u2014 SSL Certificate Installer & HTTPS Redirects plugin  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-17577 (The SSL Zen plugin for WordPress is vulnerable to Reflected Cross-Site ...)
@@ -3181,9 +3181,9 @@ CVE-2026-57175 (Python Social Auth is a social authentication/registration mecha
 CVE-2026-56792 (Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain a ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-56744 (`@bsv/wallet-toolbox` provides BRC-100 wallet signing and storage comp ...)
-	TODO: check
+	NOT-FOR-US: bsv-blockchain/wallet-toolbox
 CVE-2026-56739 (Logto is the modern, open-source auth infrastructure for SaaS and AI a ...)
-	TODO: check
+	NOT-FOR-US: Logto
 CVE-2026-56738 (phpMyFAQ is an open source FAQ web application. The `StopWords::add()` ...)
 	NOT-FOR-US: phpMyFAQ
 CVE-2026-56737 (phpMyFAQ is an open source FAQ web application. Versions 3.2.0 through ...)
@@ -4999,9 +4999,9 @@ CVE-2026-57854
 CVE-2026-57168
 	REJECTED
 CVE-2026-55632 (GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the int ...)
-	TODO: check
+	NOT-FOR-US: GoCD
 CVE-2026-55610 (InvoiceShelf is an open-source web & mobile app that helps track expen ...)
-	TODO: check
+	NOT-FOR-US: InvoiceShelf
 CVE-2026-55456
 	REJECTED
 CVE-2026-53979
@@ -5013,7 +5013,7 @@ CVE-2026-53969
 CVE-2026-53968
 	REJECTED
 CVE-2026-52744 (GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the int ...)
-	TODO: check
+	NOT-FOR-US: GoCD
 CVE-2026-50228 (An unauthenticated local attacker can connect to the Electron DevTools ...)
 	NOT-FOR-US: Acer
 CVE-2026-50227 (An unauthenticated local attacker can connect to the MQTT broker over  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ca447bb5e9f840c2cd81e681e3e3b99f49131f6d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ca447bb5e9f840c2cd81e681e3e3b99f49131f6d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260926/0587a8db/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list