Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
5236899e by security tracker role at 2026-07-30T19:14:20+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,5 +1,5 @@
 CVE-2026-9322 (IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere 
Applic ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-7849 (Due to improper neutralization of special elements, an 
unauthenticated ...)
        TODO: check
 CVE-2026-6540 (Calico's Application Layer Policy (disabled by default), which 
enforce ...)
@@ -33,7 +33,7 @@ CVE-2026-62663 (Banks generates meaningful LLM prompts using 
a simple template l
 CVE-2026-61536 (Banks generates meaningful LLM prompts using a simple template 
languag ...)
        TODO: check
 CVE-2026-5582 (The FuseWP plugin for WordPress is vulnerable to Cross-Site 
Request Fo ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-5219 (Cross-Site request forgery (CSRF) vulnerability in Softtr 
Information  ...)
        TODO: check
 CVE-2026-59881 (AIOHTTP is an asynchronous HTTP client/server framework for 
asyncio an ...)
@@ -47,7 +47,7 @@ CVE-2026-57862 (Kanboard 1.2.52 and prior contains a 
server-side request forgery
 CVE-2026-57859 (e107 prior to version 2.3.8 contains a code execution 
vulnerability in ...)
        TODO: check
 CVE-2026-56428 (The SSH service on BSH ELP (Electronic Platform) modules 
contains a pl ...)
-       TODO: check
+       NOT-FOR-US: Bosch
 CVE-2026-54885 (Server-Side Request Forgery vulnerability in malach-it Boruta 
allows a ...)
        TODO: check
 CVE-2026-54722 (DSSRF is a Node.js library that provides a wide range of 
utilities and ...)
@@ -145,13 +145,13 @@ CVE-2026-28812 (UserManager lack of checks allows 
impersonation in Apache JSPWik
 CVE-2026-28811 (Debug Messages Revealing Unnecessary Information in Apache 
JSPWiki up  ...)
        TODO: check
 CVE-2026-28323 (SolarWinds Web Help Desk is found to be affected by a SAML 
authenticat ...)
-       TODO: check
+       NOT-FOR-US: SolarWinds
 CVE-2026-22622 (Improper input validation in one of the session management 
interface o ...)
-       TODO: check
+       NOT-FOR-US: Eaton
 CVE-2026-22621 (Improper input validation in one of the session management 
interface o ...)
-       TODO: check
+       NOT-FOR-US: Eaton
 CVE-2026-22620 (Improper input validation in the authentication component 
ofEaton's Tr ...)
-       TODO: check
+       NOT-FOR-US: Eaton
 CVE-2026-18382 (A flaw was found in koku-metrics-operator. The operator's 
CostManageme ...)
        TODO: check
 CVE-2026-18381 (A flaw was found in the koku-metrics-operator for Red Hat 
OpenShift. T ...)
@@ -169,11 +169,11 @@ CVE-2026-18361 (The IRIS web application in version 
2.4.26 and possibly others i
 CVE-2026-18360 (The IRIS web application in version 2.4.26 and possibly others 
is vuln ...)
        TODO: check
 CVE-2026-18353 (PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and 
checks  ...)
-       TODO: check
+       NOT-FOR-US: Eclipse
 CVE-2026-18245 (Improper control of code generation in Amazon 
@aws-amplify/codegen-ui- ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-18140 (Uncontrolled recursion in the unknown-key skip path of the 
aws-smithy- ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-16971 (The IRIS web application in version 2.4.26 and possibly others 
does no ...)
        TODO: check
 CVE-2026-16970 (The IRIS web application in version 2.4.26 and possibly others 
contain ...)
@@ -181,7 +181,7 @@ CVE-2026-16970 (The IRIS web application in version 2.4.26 
and possibly others c
 CVE-2026-16969 (The IRIS web application in version 2.4.26 and possibly others 
is vuln ...)
        TODO: check
 CVE-2026-16308 (IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 
3.33.1  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-15978 (SGLang contains a model weight exfiltration vulnerability when 
no API  ...)
        TODO: check
 CVE-2026-15977 (SGLang contains a credential leakage vulnerability in the 
/server_info ...)
@@ -199,75 +199,75 @@ CVE-2026-15658 (A vulnerability in the foreUP customer 
REST API allows any authe
 CVE-2026-15657 (A vulnerability in the foreUP customer REST API allows any 
authenticat ...)
        TODO: check
 CVE-2026-15435 (IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 
12.0.1.0 thr ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-15397 (The Subscriptions for WooCommerce plugin for WordPress is 
vulnerable t ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14980 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 
26.0.0.8 i ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-14522 (IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 
12.0.1.0 thr ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-14519 (IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 
12.0.1.0 thr ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-14227 (An API session\u2011management flaw in products with the 
MikroTik Rout ...)
-       TODO: check
+       NOT-FOR-US: MikroTik
 CVE-2026-13584 (Improper Enforcement of Message Integrity During Transmission 
in a Com ...)
-       TODO: check
+       NOT-FOR-US: Mitsubishi
 CVE-2026-13444 (IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to 
access  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-13435 (IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper 
input valid ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-13379 (The Windows interactive service in OpenVPN 2.7_alpha1 through 
2.7.4 al ...)
        TODO: check
 CVE-2026-12947 (IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 
12.0.1.0 thr ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-12945 (IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated 
users to ac ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-12943 (IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC 
V11.1.1110.0 thro ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-12942 (IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote 
attacker to ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-12940 (IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to 
unauthenticate ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-12733 (IBM DataPower Gateway could allow a remote attacker to cause a 
denial  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-12722 (Missing authentication for critical function vulnerability in 
FTC Soft ...)
        TODO: check
 CVE-2026-12118 (IBM webMethods Integration (on prem) 10.15, 10.11 could allow 
an unaut ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-11980 (IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow 
arbitrary code e ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-11904 (IBM Verify Identity Access 11.0 through 11.0.2 and IBM 
Security Verify ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-11897 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 
26.0.0.7 i ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-11885 (IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 
through  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-11707 (IBM Tivoli System Automation Application Manager 4.1 and IBM 
WebSphere ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-11383 (IBM Tivoli System Automation Application Manager 4.1 and IBM 
WebSphere ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-10842 (IBM WebSphere Application Server 8.5, and 9.0 and IBM 
WebSphere Applic ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-10700 (IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken 
access c ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-10695 (IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable 
to a deni ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-10545 (IBM Planning Analytics Local 2.1.0 through 2.1.21 is 
vulnerable to an  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-10535 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is 
vulnerable ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2025-36431 (IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM 
Sterling ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2025-36374 (IBM DataPower Gateway is vulnerable to an XML external entity 
injectio ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2025-36298 (IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 
through ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2025-0152 (IBM Engineering Requirements Management DOORS and DOORS Web 
Access 9.7 ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2024-40683 (IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 
1.3.5.2, 1.3 ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2024-25039 (IBM Engineering Requirements Management DOORS and DOORS Web 
Access 9.7 ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-60075 (Date::Manip versions through 6.99 for Perl allow CPU 
exhaustion via qu ...)
        - libdate-manip-perl <unfixed> (bug #1143125)
        [trixie] - libdate-manip-perl <no-dsa> (Minor issue)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5236899e23a0ee5eaae7cbebdb9e3e131876f1e9

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5236899e23a0ee5eaae7cbebdb9e3e131876f1e9
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to