Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
f8dcdff3 by Moritz Muehlenhoff at 2026-08-12T16:04:01+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -109,7 +109,7 @@ CVE-2026-73232 (ffuf is a fast web fuzzer written in Go.
Prior to 2.2.0, ffuf al
CVE-2026-73231 (Faker generates massive amounts of fake data in the browser
and Node.j ...)
TODO: check
CVE-2026-73230 (Ente provides end-to-end encrypted cloud services and security
tools. ...)
- TODO: check
+ NOT-FOR-US: Ente
CVE-2026-73229 (Django REST framework is a powerful and flexible toolkit for
building ...)
- djangorestframework <unfixed>
NOTE:
https://github.com/encode/django-rest-framework/security/advisories/GHSA-g47c-3xmw-q6m2
@@ -128,39 +128,39 @@ CVE-2026-73031 (telegram-search contains a stored
cross-site scripting vulnerabi
CVE-2026-72526 (A flaw was found in the multicloud-integrations component. The
Applica ...)
TODO: check
CVE-2026-71845 (A flaw was found in insights-client. The setDefault() function
logs th ...)
- TODO: check
+ NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
CVE-2026-71475 (A flaw was found in insights-client. A compromised managed
cluster, re ...)
- TODO: check
+ NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
CVE-2026-71474 (A flaw was found in insights-client. When the application
receives a n ...)
- TODO: check
+ NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
CVE-2026-71468 (A flaw was found in acm-search-v2-api-rhel9. When the
`getFederationCo ...)
- TODO: check
+ NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
CVE-2026-71467 (A flaw was found in search-v2-api. The authentication
middleware in th ...)
- TODO: check
+ NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
CVE-2026-71290 (Improper TLS hostname verification vulnerability in Apache
HttpCompone ...)
TODO: check
CVE-2026-70398 (A flaw was found in multicloud-integrations, a component of
Red Hat Ad ...)
- TODO: check
+ NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
CVE-2026-70339 (Access of resource using incompatible type ('type confusion')
in Micro ...)
NOT-FOR-US: Microsoft
CVE-2026-6484 (In an UEFI, Lack of verified boot to certain FV may cause
arbitrary co ...)
NOT-FOR-US: Insyde
CVE-2026-68067 (The login endpoint on the Mira cloud API accepts any
format-valid stri ...)
- TODO: check
+ NOT-FOR-US: Mira
CVE-2026-67568 (The distributed Mira Android APK v4.5.15.4 allows an attacker
read/wri ...)
- TODO: check
+ NOT-FOR-US: Mira
CVE-2026-67558 (The Mira Android companion app v4.5.15.4 identifies the paired
Mira ho ...)
- TODO: check
+ NOT-FOR-US: Mira
CVE-2026-66878 (A flaw was found in multicloud-operators-subscription. A
privileged us ...)
- TODO: check
+ NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
CVE-2026-66875 (In the Mira hormone monitor device firmware v1.7.1.47 build
01070147, ...)
- TODO: check
+ NOT-FOR-US: Mira
CVE-2026-66832 (When the Mira Android app opens in-app WebView content (e.g.,
shop red ...)
- TODO: check
+ NOT-FOR-US: Mira
CVE-2026-66659 (Improper Neutralization of Special Elements used in an SQL
Command ('S ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-66340 (The Mira cloud authentication endpoints do not enforce
per-account rat ...)
- TODO: check
+ NOT-FOR-US: Mira
CVE-2026-66154 (An insufficient certificate validation in a privileged
communication w ...)
NOT-FOR-US: SonicWall
CVE-2026-66150 (Improper Control of Generation of Code ('Code Injection')
Vulnerabilit ...)
@@ -176,15 +176,15 @@ CVE-2026-66146 (Multiple Cross-Site Scripting (XSS)
vulnerabilities were identif
CVE-2026-66145 (An unauthenticated remote code execution vulnerability was
identified ...)
NOT-FOR-US: SonicWall
CVE-2026-66098 (The Mira hormone monitor device firmware accepts a 0x01 write
from any ...)
- TODO: check
+ NOT-FOR-US: Mira
CVE-2026-65655 (When OAuth authentication is enabled and browser-facing TLS
terminates ...)
TODO: check
CVE-2026-64954 (Velociraptor allows scheduling new collections via VQL queries
in note ...)
TODO: check
CVE-2026-64934 (The Mira cloud API accepts the firmware version reported by
the compan ...)
- TODO: check
+ NOT-FOR-US: Mira
CVE-2026-64927 (A flaw was found in the multicloud-operators-channel
component. This v ...)
- TODO: check
+ NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
CVE-2026-63177 (Malcolm is a network traffic analysis tool suite. Prior to
version 26. ...)
TODO: check
CVE-2026-63134 (Malcolm is a network traffic analysis tool suite. Prior to
version 26. ...)
@@ -1685,17 +1685,17 @@ CVE-2026-53414 (Missing bounds check in the annotator
function of Zoom Clients a
CVE-2026-53413 (Missing bounds check in the annotator function of Zoom Clients
allows ...)
NOT-FOR-US: Zoom
CVE-2026-51584 (An issue in usememos v0.27.1 allows a remote attacker to
achieve accou ...)
- TODO: check
+ NOT-FOR-US: usememos
CVE-2026-51583 (An issue in usememos through v0.30.0 allows a remote
authenticated att ...)
- TODO: check
+ NOT-FOR-US: usememos
CVE-2026-50516 (Missing authentication for critical function in Microsoft
Azure Kubern ...)
NOT-FOR-US: Microsoft
CVE-2026-50472 (Heap-based buffer overflow in Windows LUAFV allows an
authorized attac ...)
NOT-FOR-US: Microsoft
CVE-2026-50237 (A Server-Side Request Forgery and supply chain flaw was found
in the O ...)
- TODO: check
+ NOT-FOR-US: Red Hat OpenShift Container Platform
CVE-2026-50236 (An authenticated SSRF flaw was found in the OpenShift Console
Dev Cons ...)
- TODO: check
+ NOT-FOR-US: Red Hat OpenShift Container Platform
CVE-2026-50064 (A vulnerability has been identified in Solid Edge SE2025 (All
versions ...)
NOT-FOR-US: Siemens
CVE-2026-50063 (A vulnerability has been identified in Solid Edge SE2025 (All
versions ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f8dcdff38594506e955a76d24d4caf60f4bdd992
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f8dcdff38594506e955a76d24d4caf60f4bdd992
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits