Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
422f2efd by security tracker role at 2026-08-10T19:14:48+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -51,31 +51,31 @@ CVE-2026-72734 (Dokploy is a free, self-hostable Platform 
as a Service (PaaS). F
 CVE-2026-72733 (Dokploy is a free, self-hostable Platform as a Service (PaaS). 
Prior t ...)
        TODO: check
 CVE-2026-72732 (Discourse is an open-source discussion platform. Prior to 
2026.1.6, 20 ...)
-       TODO: check
+       NOT-FOR-US: Discourse
 CVE-2026-72731 (Discourse is an open-source discussion platform. From 
2026.1.0-latest  ...)
-       TODO: check
+       NOT-FOR-US: Discourse
 CVE-2026-72730 (Discourse is an open-source discussion platform. Prior to 
2026.1.6, 20 ...)
-       TODO: check
+       NOT-FOR-US: Discourse
 CVE-2026-72729 (Discourse is an open-source discussion platform. Prior to 
2026.1.6, 20 ...)
-       TODO: check
+       NOT-FOR-US: Discourse
 CVE-2026-72728 (Discourse is an open-source discussion platform. Prior to 
2026.1.7, an ...)
-       TODO: check
+       NOT-FOR-US: Discourse
 CVE-2026-72727 (Discourse is an open-source discussion platform. Prior to 
026.1.6, 202 ...)
-       TODO: check
+       NOT-FOR-US: Discourse
 CVE-2026-72726 (Discourse is an open-source discussion platform. Prior to 
2026.1.6, 20 ...)
-       TODO: check
+       NOT-FOR-US: Discourse
 CVE-2026-72725 (Discourse is an open-source discussion platform. Prior to 
2026.1.6, th ...)
-       TODO: check
+       NOT-FOR-US: Discourse
 CVE-2026-72724 (Discourse is an open-source discussion platform. Prior to 
2026.1.6, 20 ...)
-       TODO: check
+       NOT-FOR-US: Discourse
 CVE-2026-72723 (Discourse is an open-source discussion platform. Prior to 
2026.1.6, 20 ...)
-       TODO: check
+       NOT-FOR-US: Discourse
 CVE-2026-72722 (Discourse is an open-source discussion platform. Prior to 
2026.1.6, 20 ...)
-       TODO: check
+       NOT-FOR-US: Discourse
 CVE-2026-72721 (Discourse is an open-source discussion platform. Prior to 
2026.1.6, 20 ...)
-       TODO: check
+       NOT-FOR-US: Discourse
 CVE-2026-72720 (Discourse is an open-source discussion platform. Prior to 
2026.1.7, 20 ...)
-       TODO: check
+       NOT-FOR-US: Discourse
 CVE-2026-72719 (Chatwoot is a customer engagement suite. Prior to 4.9.0, 
Chatwoot allo ...)
        TODO: check
 CVE-2026-72718 (goose is general-purpose AI agent that runs on your machine. 
Prior to  ...)
@@ -161,7 +161,7 @@ CVE-2026-71967 (OP-TEE OS through 4.10.0, fixed in commit 
0aadfc2, contains a nu
 CVE-2026-71964 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an 
arbitrary file  ...)
        TODO: check
 CVE-2026-71962 (Flowise versions 2.2.4 through 3.1.4 contain a missing 
authorization v ...)
-       TODO: check
+       NOT-FOR-US: Flowise
 CVE-2026-71959 (Bitwarden Server before 2026.7.2 does not verify that the 
caller is a  ...)
        TODO: check
 CVE-2026-71577 (A flaw was found in multicluster-global-hub. During a 
ManagedClusterMi ...)
@@ -185,11 +185,11 @@ CVE-2026-6373 (Exposure of sensitive system information 
to an unauthorized contr
 CVE-2026-6368 (Calling wordexp with WRDE_APPEND in the GNU C Library version 
2.0 to v ...)
        TODO: check
 CVE-2026-66915 (Joomla Extension - fabrikar.com - Remote code execution in 
Fabrik < 4. ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-66738 (SPIP before 4.4.18 contains a code injection vulnerability in 
SQLite-b ...)
        TODO: check
 CVE-2026-66642 (Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella 
allows  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66486 (GNU cpio is vulnerable to improper encoding or escaping of 
output in i ...)
        TODO: check
 CVE-2026-66485 (GNU cpio is vulnerable to an uncontrolled memory allocation in 
the mak ...)
@@ -215,11 +215,11 @@ CVE-2026-66404 (DEEBOT PRO M1 and DEEBOT PRO K1VAC do not 
validate server certif
 CVE-2026-66403 (DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for 
debugging  ...)
        TODO: check
 CVE-2026-65948 (UnixAuth lacks brute-force protection in Apache Ranger 
versions <= 2.8 ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-65945 (Logs contain replayable JWT tokens in Apache Ranger versions 
<= 2.8.0  ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-65942 (TLS hostname verification issue in Apache Ranger Client Code 
in versio ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-64941 (URL Redirection to Untrusted Site ('Open Redirect') 
vulnerability in p ...)
        TODO: check
 CVE-2026-64940 (Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi 
Factory contai ...)
@@ -245,29 +245,29 @@ CVE-2026-59087 (A flaw was found in the GIMP image 
manipulation program, specifi
 CVE-2026-57279 (Cybozu Garoon contains a cross-site scripting vulnerability. 
If this v ...)
        TODO: check
 CVE-2026-56620 (HCL BigFix Mobileis vulnerable to information disclosure due 
to improp ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-56619 (HCL BigFix Mobile is vulnerable to Reflected Cross-Site 
Scripting (Ref ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-55814 (Missing Authentication in Apache Ranger Download APIs on 
versions <= 2 ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-55799 (Remote Code Execution Vulnerability in 
GraalScriptEngineCreator in Apa ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-48159 (use-reducer-async is a React useReducer with async actions. 
Between 20 ...)
        TODO: check
 CVE-2026-48158 (use-context-selector is a React useContextSelector hook in 
userland Be ...)
        TODO: check
 CVE-2026-48048 (XWiki Platform is a generic wiki platform. XWiki discovered 
that the p ...)
-       TODO: check
+       NOT-FOR-US: XWiki
 CVE-2026-47754 (Metacat is data repository software that helps researchers 
preserve, s ...)
        TODO: check
 CVE-2026-44630 (Improper validation of length fields in the Apache IoTDB RPC 
service m ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-44416 (Remote Code Execution via Arbitrary Class Instantiation 
inplugin-schem ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-42537 (Remote Code Execution via JDBC URL Injectionin Apache Ranger 
<= 2.8.0  ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-40920 (Privilege Escalation via URL Parameteris reported in Apache 
Ranger ver ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-40512
        REJECTED
 CVE-2026-35028
@@ -283,7 +283,7 @@ CVE-2026-35005
 CVE-2026-34423
        REJECTED
 CVE-2026-32227 (SQL Injection vulnerability vulnerability in Apache Ranger.  
This issu ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-29517
        REJECTED
 CVE-2026-29033
@@ -317,7 +317,7 @@ CVE-2026-28999
 CVE-2026-28998
        REJECTED
 CVE-2026-28672 (Improper Neutralization of Special Elements used in a Command 
('Comman ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-28534
        REJECTED
 CVE-2026-28533
@@ -365,59 +365,59 @@ CVE-2026-22652
 CVE-2026-22651
        REJECTED
 CVE-2026-21084 (Improper access control in SmartThings prior to version 
1.8.47.24 allo ...)
-       TODO: check
+       NOT-FOR-US: Samsung Mobile
 CVE-2026-21083 (Improper input validation in Smart Switch prior to version 
3.7.72.6 al ...)
-       TODO: check
+       NOT-FOR-US: Samsung Mobile
 CVE-2026-21082 (Relative path traversal in Samsung Health prior to version 
7.0.0 allow ...)
-       TODO: check
+       NOT-FOR-US: Samsung Mobile
 CVE-2026-21081 (Improper export of android application components in 
SamsungPassAutofi ...)
-       TODO: check
+       NOT-FOR-US: Samsung Mobile
 CVE-2026-21080 (Cleartext storage of sensitive information in Smart Switch 
prior to ve ...)
-       TODO: check
+       NOT-FOR-US: Samsung Mobile
 CVE-2026-21079 (Missing encryption of sensitive data in Smart Switch prior to 
version  ...)
-       TODO: check
+       NOT-FOR-US: Samsung Mobile
 CVE-2026-21078 (Insufficient verification of data authenticity in Smart Switch 
trouble ...)
-       TODO: check
+       NOT-FOR-US: Samsung Mobile
 CVE-2026-21077 (Incorrect authorization in Samsung Health prior to version 
7.0.0 allow ...)
-       TODO: check
+       NOT-FOR-US: Samsung Mobile
 CVE-2026-21076 (Incorrect authorization in Samsung Health prior to version 
7.0.0 allow ...)
-       TODO: check
+       NOT-FOR-US: Samsung Mobile
 CVE-2026-21075 (Improper authorization in handler for custom URL scheme in My 
Galaxy p ...)
-       TODO: check
+       NOT-FOR-US: Samsung Mobile
 CVE-2026-21074 (Incorrect default permissions in Bixby prior to version 
4.0.86.0 allow ...)
-       TODO: check
+       NOT-FOR-US: Samsung Mobile
 CVE-2026-21073 (Improper input validation in Galaxy Themes prior to SMR 
Aug-2026 Relea ...)
-       TODO: check
+       NOT-FOR-US: Samsung Mobile
 CVE-2026-21072 (Improper input validation in VC1 codec in libsavsvc.so prior 
to SMR Au ...)
-       TODO: check
+       NOT-FOR-US: Samsung Mobile
 CVE-2026-21071 (Improper input validation in MPEG4 codec in libsavsvc.so prior 
to SMR  ...)
-       TODO: check
+       NOT-FOR-US: Samsung Mobile
 CVE-2026-21070 (Improper input validation in Samsung Message prior to SMR 
Aug-2026 Rel ...)
-       TODO: check
+       NOT-FOR-US: Samsung Mobile
 CVE-2026-21069 (Incorrect conversion between numeric types in VC1 codec in 
libsavsvc.s ...)
-       TODO: check
+       NOT-FOR-US: Samsung Mobile
 CVE-2026-21068 (Stack-based buffer overflow in libril_sem.so prior to SMR 
Aug-2026 Rel ...)
-       TODO: check
+       NOT-FOR-US: Samsung Mobile
 CVE-2026-21067 (Improper input validation in libsmsd.so prior to SMR Aug-2026 
Release  ...)
-       TODO: check
+       NOT-FOR-US: Samsung Mobile
 CVE-2026-21066 (Improper input validation in libcodec2_sec_flacdec.so prior to 
SMR Aug ...)
-       TODO: check
+       NOT-FOR-US: Samsung Mobile
 CVE-2026-21065 (Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR 
Aug-2026 R ...)
-       TODO: check
+       NOT-FOR-US: Samsung Mobile
 CVE-2026-21064 (Improper access control in Weaver prior to SMR Aug-2026 
Release 1 allo ...)
-       TODO: check
+       NOT-FOR-US: Samsung Mobile
 CVE-2026-21063 (Improper export of android application components in AppLock 
prior to  ...)
-       TODO: check
+       NOT-FOR-US: Samsung Mobile
 CVE-2026-21062 (Authorization bypass in SemClipboardService prior to SMR 
Aug-2026 Rele ...)
-       TODO: check
+       NOT-FOR-US: Samsung Mobile
 CVE-2026-21061 (Improper input validation in Samsung Dialer prior to SMR 
Aug-2026 Rele ...)
-       TODO: check
+       NOT-FOR-US: Samsung Mobile
 CVE-2026-21060 (Improper input validation in Samsung Contacts prior to SMR 
Aug-2026 Re ...)
-       TODO: check
+       NOT-FOR-US: Samsung Mobile
 CVE-2026-21059 (Improper export of android application components in Samsung 
Contacts  ...)
-       TODO: check
+       NOT-FOR-US: Samsung Mobile
 CVE-2026-21058 (Improper input validation in Samsung Contacts prior to SMR 
Aug-2026 Re ...)
-       TODO: check
+       NOT-FOR-US: Samsung Mobile
 CVE-2026-19433 (Authorization Bypass Through User-Controlled Key in the 
contact manage ...)
        TODO: check
 CVE-2026-19429 (Jenkins FilePath.untarFrom() in all versions, including those 
with the ...)
@@ -449,7 +449,7 @@ CVE-2026-12984 (Insufficiently Protected Credentials 
vulnerability in Zyxel Netw
 CVE-2026-12624 (Vault\u2019s ACL policy engine did not consistently enforce a 
wildcard ...)
        TODO: check
 CVE-2026-12339 (A Zip Slip vulnerability in the WebUI ISP Upgrade 
functionality allows ...)
-       TODO: check
+       NOT-FOR-US: TPLink
 CVE-2026-10754 (Pega Platform versions 8.5.0 through 25.1.2 are affected by an 
imprope ...)
        TODO: check
 CVE-2026-68870 (The Azure Key Vault secrets backend in Apache Airflow's 
Microsoft Azur ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/422f2efd6483320728456feda473fb8b75bee7fe

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/422f2efd6483320728456feda473fb8b75bee7fe
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to