Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
8342ea58 by security tracker role at 2026-07-31T19:19:14+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -9,7 +9,7 @@ CVE-2026-68575
 CVE-2026-68574
        REJECTED
 CVE-2026-67822 (Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow 
vulnera ...)
-       TODO: check
+       NOT-FOR-US: Tenda
 CVE-2026-67607 (LightFTP 2.3.1 contains a race condition vulnerability that 
allows rem ...)
        TODO: check
 CVE-2026-67350 (Serendipity before 2.6.1 contains an open redirect 
vulnerability in ex ...)
@@ -37,15 +37,15 @@ CVE-2026-58047 (HTTP Smuggling in cPanel allows potential 
leak of credentials.)
 CVE-2026-57232 (Contao is an Open Source CMS. From 5.3.35 through 5.3.47 and 
from 5.7. ...)
        TODO: check
 CVE-2026-56571 (HCL iControl was affected by Improper Error Handling 
vulnerabilities.  ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-56570 (HCL iControl was affected by Auto complete Enabled 
vulnerabilities. It ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-56569 (HCL iControl was affected by Sensitive Data Exposure 
vulnerabilities.  ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-56568 (HCL iControl was affected by Information Exposure Through 
Verbose Clie ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-56567 (HCL iControl v4.3.0 was affected by Security Misconfiguration 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-55824 (Contao is an Open Source CMS. In versions 4.13.40 through 
5.3.46 and 5 ...)
        TODO: check
 CVE-2026-55100 (hashi-vault-js is a Node.js module for interacting with the 
HashiCorp  ...)
@@ -167,27 +167,27 @@ CVE-2026-46594 (A reflected cross-site scripting (XSS) 
vulnerability has been id
 CVE-2026-46593 (A SQL injection vulnerability has been identified in the PHP 
Jabbers - ...)
        TODO: check
 CVE-2026-34497 (Improper neutralization of Script-Related HTML tags in a web 
page (bas ...)
-       TODO: check
+       NOT-FOR-US: Johnson Controls
 CVE-2026-34495 (Improper neutralization of input during web page generation 
('cross-si ...)
-       TODO: check
+       NOT-FOR-US: Johnson Controls
 CVE-2026-34490 (Cleartext storage of sensitive information vulnerability in 
Johnson Co ...)
-       TODO: check
+       NOT-FOR-US: Johnson Controls
 CVE-2026-28145 (Insufficient Verification of Data Authenticity vulnerability 
in Stylem ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28144 (Insertion of Sensitive Information Into Sent Data 
vulnerability in Fli ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-25552 (Ghost CLI before 1.30.1 contains an IP spoofing vulnerability 
that all ...)
        TODO: check
 CVE-2026-21662 (Unrestricted upload of file with dangerous type vulnerability 
in Johns ...)
-       TODO: check
+       NOT-FOR-US: Johnson Controls
 CVE-2026-18481 (Stored cross-site scripting in the participant URL handling in 
AWS Ops ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-18446 (fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal 
double forw ...)
        TODO: check
 CVE-2026-18437 (The MailerPress \u2013 Newsletter, email marketing & AI 
automation plu ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18436 (The MailPress plugin for WordPress is vulnerable to 
unauthorized acces ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18358 (A flaw was found in gnome-remote-desktop as shipped in Red Hat 
Enterpr ...)
        TODO: check
 CVE-2026-18321 (Buffer overflow in NTPsec's Zyfer refclock allows local 
attacker to cr ...)
@@ -215,7 +215,7 @@ CVE-2026-18141 (A flaw was found in aap-gateway, a 
component of Ansible Automati
 CVE-2026-17592
        REJECTED
 CVE-2026-17567 (The Fluent Forms \u2013 Customizable Contact Forms, Survey, 
Quiz, & Co ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-17566 (pgAdmin 4's Import/Export Data tool builds a psql \copy (...) 
command  ...)
        TODO: check
 CVE-2026-17561 (Improper Control of Generation of Code ('Code Injection') 
vulnerabilit ...)
@@ -233,7 +233,7 @@ CVE-2026-17347 (The MASTER_PASSWORD_HOOK setting, 
introduced in pgAdmin 4 7.2, l
 CVE-2026-17346 (The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened 
qtLiteral and sw ...)
        TODO: check
 CVE-2026-16843 (Some Hikvision Wireless Access Points are vulnerable to 
authenticated  ...)
-       TODO: check
+       NOT-FOR-US: Hikvision
 CVE-2026-16504 (Deployment of the VPS.org one-click Zulip template deploys a 
hardcoded ...)
        TODO: check
 CVE-2026-16503 (Deployment of the VPS.org one-click Supabase template deploys 
a Postgr ...)
@@ -247,9 +247,9 @@ CVE-2026-15227 (Missing authorization in Checkmk <2.5.0p10, 
<2.4.0p35, <2.3.0p49
 CVE-2026-11770 (A flaw was found in 389 Directory Server. An unauthenticated 
remote at ...)
        TODO: check
 CVE-2026-10686 (Zephyr's IPv6 forwarding path re-sent routed unicast packets 
without e ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-10685 (The Zephyr Bluetooth GATT client CCC-write response handler 
gatt_write ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-10079 (A flaw was found in Red Hat Advanced Cluster Security for 
Kubernetes ( ...)
        TODO: check
 CVE-2025-67651 (A Cross-Site Request Forgery (CSRF) vulnerability has been 
identified  ...)
@@ -259,7 +259,7 @@ CVE-2025-67650 (An authenticated SQL injection 
vulnerability has been identified
 CVE-2025-67649 (A SQL injection vulnerability has been identified in PHP 
Jabbers -Car  ...)
        TODO: check
 CVE-2025-62347 (HCL iControl was affected by Improper Input Validation 
vulnerability.  ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-XXXX [GHSA-6v6x-387m-rj4w: Project restriction bypass on network 
address sets]
        - incus 7.0.1-2
        [trixie] - incus <not-affected> (Vulnerable code not present)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8342ea58b26ee913489d80222b5e5366a5fba07f

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8342ea58b26ee913489d80222b5e5366a5fba07f
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to