Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
5236899e by security tracker role at 2026-07-30T19:14:20+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,5 +1,5 @@
CVE-2026-9322 (IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere
Applic ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-7849 (Due to improper neutralization of special elements, an
unauthenticated ...)
TODO: check
CVE-2026-6540 (Calico's Application Layer Policy (disabled by default), which
enforce ...)
@@ -33,7 +33,7 @@ CVE-2026-62663 (Banks generates meaningful LLM prompts using
a simple template l
CVE-2026-61536 (Banks generates meaningful LLM prompts using a simple template
languag ...)
TODO: check
CVE-2026-5582 (The FuseWP plugin for WordPress is vulnerable to Cross-Site
Request Fo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-5219 (Cross-Site request forgery (CSRF) vulnerability in Softtr
Information ...)
TODO: check
CVE-2026-59881 (AIOHTTP is an asynchronous HTTP client/server framework for
asyncio an ...)
@@ -47,7 +47,7 @@ CVE-2026-57862 (Kanboard 1.2.52 and prior contains a
server-side request forgery
CVE-2026-57859 (e107 prior to version 2.3.8 contains a code execution
vulnerability in ...)
TODO: check
CVE-2026-56428 (The SSH service on BSH ELP (Electronic Platform) modules
contains a pl ...)
- TODO: check
+ NOT-FOR-US: Bosch
CVE-2026-54885 (Server-Side Request Forgery vulnerability in malach-it Boruta
allows a ...)
TODO: check
CVE-2026-54722 (DSSRF is a Node.js library that provides a wide range of
utilities and ...)
@@ -145,13 +145,13 @@ CVE-2026-28812 (UserManager lack of checks allows
impersonation in Apache JSPWik
CVE-2026-28811 (Debug Messages Revealing Unnecessary Information in Apache
JSPWiki up ...)
TODO: check
CVE-2026-28323 (SolarWinds Web Help Desk is found to be affected by a SAML
authenticat ...)
- TODO: check
+ NOT-FOR-US: SolarWinds
CVE-2026-22622 (Improper input validation in one of the session management
interface o ...)
- TODO: check
+ NOT-FOR-US: Eaton
CVE-2026-22621 (Improper input validation in one of the session management
interface o ...)
- TODO: check
+ NOT-FOR-US: Eaton
CVE-2026-22620 (Improper input validation in the authentication component
ofEaton's Tr ...)
- TODO: check
+ NOT-FOR-US: Eaton
CVE-2026-18382 (A flaw was found in koku-metrics-operator. The operator's
CostManageme ...)
TODO: check
CVE-2026-18381 (A flaw was found in the koku-metrics-operator for Red Hat
OpenShift. T ...)
@@ -169,11 +169,11 @@ CVE-2026-18361 (The IRIS web application in version
2.4.26 and possibly others i
CVE-2026-18360 (The IRIS web application in version 2.4.26 and possibly others
is vuln ...)
TODO: check
CVE-2026-18353 (PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and
checks ...)
- TODO: check
+ NOT-FOR-US: Eclipse
CVE-2026-18245 (Improper control of code generation in Amazon
@aws-amplify/codegen-ui- ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-18140 (Uncontrolled recursion in the unknown-key skip path of the
aws-smithy- ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-16971 (The IRIS web application in version 2.4.26 and possibly others
does no ...)
TODO: check
CVE-2026-16970 (The IRIS web application in version 2.4.26 and possibly others
contain ...)
@@ -181,7 +181,7 @@ CVE-2026-16970 (The IRIS web application in version 2.4.26
and possibly others c
CVE-2026-16969 (The IRIS web application in version 2.4.26 and possibly others
is vuln ...)
TODO: check
CVE-2026-16308 (IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and
3.33.1 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-15978 (SGLang contains a model weight exfiltration vulnerability when
no API ...)
TODO: check
CVE-2026-15977 (SGLang contains a credential leakage vulnerability in the
/server_info ...)
@@ -199,75 +199,75 @@ CVE-2026-15658 (A vulnerability in the foreUP customer
REST API allows any authe
CVE-2026-15657 (A vulnerability in the foreUP customer REST API allows any
authenticat ...)
TODO: check
CVE-2026-15435 (IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and
12.0.1.0 thr ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-15397 (The Subscriptions for WooCommerce plugin for WordPress is
vulnerable t ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14980 (IBM WebSphere Application Server - Liberty 17.0.0.3 through
26.0.0.8 i ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-14522 (IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and
12.0.1.0 thr ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-14519 (IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and
12.0.1.0 thr ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-14227 (An API session\u2011management flaw in products with the
MikroTik Rout ...)
- TODO: check
+ NOT-FOR-US: MikroTik
CVE-2026-13584 (Improper Enforcement of Message Integrity During Transmission
in a Com ...)
- TODO: check
+ NOT-FOR-US: Mitsubishi
CVE-2026-13444 (IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to
access ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-13435 (IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper
input valid ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-13379 (The Windows interactive service in OpenVPN 2.7_alpha1 through
2.7.4 al ...)
TODO: check
CVE-2026-12947 (IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and
12.0.1.0 thr ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-12945 (IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated
users to ac ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-12943 (IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC
V11.1.1110.0 thro ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-12942 (IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote
attacker to ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-12940 (IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to
unauthenticate ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-12733 (IBM DataPower Gateway could allow a remote attacker to cause a
denial ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-12722 (Missing authentication for critical function vulnerability in
FTC Soft ...)
TODO: check
CVE-2026-12118 (IBM webMethods Integration (on prem) 10.15, 10.11 could allow
an unaut ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-11980 (IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow
arbitrary code e ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-11904 (IBM Verify Identity Access 11.0 through 11.0.2 and IBM
Security Verify ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-11897 (IBM WebSphere Application Server - Liberty 17.0.0.3 through
26.0.0.7 i ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-11885 (IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00
through ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-11707 (IBM Tivoli System Automation Application Manager 4.1 and IBM
WebSphere ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-11383 (IBM Tivoli System Automation Application Manager 4.1 and IBM
WebSphere ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-10842 (IBM WebSphere Application Server 8.5, and 9.0 and IBM
WebSphere Applic ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-10700 (IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken
access c ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-10695 (IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable
to a deni ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-10545 (IBM Planning Analytics Local 2.1.0 through 2.1.21 is
vulnerable to an ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-10535 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is
vulnerable ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2025-36431 (IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM
Sterling ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2025-36374 (IBM DataPower Gateway is vulnerable to an XML external entity
injectio ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2025-36298 (IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0
through ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2025-0152 (IBM Engineering Requirements Management DOORS and DOORS Web
Access 9.7 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2024-40683 (IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1,
1.3.5.2, 1.3 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2024-25039 (IBM Engineering Requirements Management DOORS and DOORS Web
Access 9.7 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-60075 (Date::Manip versions through 6.99 for Perl allow CPU
exhaustion via qu ...)
- libdate-manip-perl <unfixed> (bug #1143125)
[trixie] - libdate-manip-perl <no-dsa> (Minor issue)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5236899e23a0ee5eaae7cbebdb9e3e131876f1e9
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5236899e23a0ee5eaae7cbebdb9e3e131876f1e9
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits