Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
fd969e82 by security tracker role at 2026-08-12T19:14:50+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
 CVE-2026-8667 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
-       TODO: check
+       NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-7427 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
-       TODO: check
+       NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-73432 (Vulnerability-Lookup contains a server-side request forgery 
(SSRF) vul ...)
        TODO: check
 CVE-2026-73431 (Vulnerability-Lookup contains an  authentication weakness in 
its accou ...)
@@ -59,29 +59,29 @@ CVE-2026-73263 (Prowler is a cloud security platform. Prior 
to 5.36.0, the Kuber
 CVE-2026-73262 (Prowler is a cloud security platform. Prior to 5.37.0, 
Prowler's HTML  ...)
        TODO: check
 CVE-2026-73240 (Specifically crafted inputs may lead to git argument injection 
in Apac ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-73239 (Insecure Direct Object Reference (IDOR) due to missing 
permission chec ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-73238 (XSS vulnerability in code display in Apache Allura.  This 
issue affect ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-73237 (XSS vulnerability in Markdown handling in Apache Allura.  This 
issue a ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-71408 (A allocation of resources without limits or throttling 
vulnerability i ...)
-       TODO: check
+       NOT-FOR-US: Fortinet
 CVE-2026-71407 (A Stack-based Buffer Overflow vulnerability [CWE-121] 
vulnerability in ...)
-       TODO: check
+       NOT-FOR-US: Fortinet
 CVE-2026-70560 (Ultimate POS (Stock Management & Point of Sale) contains a 
stored cros ...)
        TODO: check
 CVE-2026-70547 (An authenticated user without repository read permission may 
access pa ...)
        TODO: check
 CVE-2026-70468 (A authentication bypass using an alternate path or channel 
vulnerabili ...)
-       TODO: check
+       NOT-FOR-US: Fortinet
 CVE-2026-70467 (A server-side request forgery (ssrf) vulnerability in Fortinet 
FortiSI ...)
-       TODO: check
+       NOT-FOR-US: Fortinet
 CVE-2026-70466 (A incomplete list of disallowed inputs vulnerability in 
Fortinet Forti ...)
-       TODO: check
+       NOT-FOR-US: Fortinet
 CVE-2026-70465 (A buffer copy without checking size of input ('classic buffer 
overflow ...)
-       TODO: check
+       NOT-FOR-US: Fortinet
 CVE-2026-69107 (An unauthenticated user may access restricted artifacts in 
JFrog Artif ...)
        TODO: check
 CVE-2026-69106 (A low-privileged user may poison cached artifact metadata 
under specif ...)
@@ -109,17 +109,17 @@ CVE-2026-68752 (A Project Resource Manager may gain 
broader administrative privi
 CVE-2026-67587 (Apache Airflow's Task SDK rebuilt a `Callback` object from 
serialized  ...)
        TODO: check
 CVE-2026-67287 (Joomla Extension - joomshaper.com - Unauthenticated comment 
creation i ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-67286 (Joomla Extension - joomshaper.com - Unauthenticated arbitrary 
director ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-67285 (Joomla Extension - joomshaper.com - Unauthenticated arbitrary 
local PH ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-67284 (Joomla Extension - tabaoca.org - Improper ACL implementation 
allows fi ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-67283 (Joomla Extension - tabaoca.org - Improper ACL implementation 
allows fi ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-67282 (Joomla Extension - fabrikar.com - Unauthenticated remote code 
executio ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-67260 (Apache Airflow 3.3.0 moved human-in-the-loop tasks from the 
triggerer  ...)
        TODO: check
 CVE-2026-66384 (An authenticated user may write data outside the intended 
Docker cache ...)
@@ -143,23 +143,23 @@ CVE-2026-66375 (A low-privilege authenticated user may 
permanently remove protec
 CVE-2026-66016 (Under specific self-hosted Helm configurations, generated TLS 
private  ...)
        TODO: check
 CVE-2026-65941 (In WhatsUp Gold versions released before 2026.0.2,an 
unauthenticated r ...)
-       TODO: check
+       NOT-FOR-US: Progress Software
 CVE-2026-65940 (In WhatsUp Gold versions released before 2026.0.2, a 
privileged attack ...)
-       TODO: check
+       NOT-FOR-US: Progress Software
 CVE-2026-65939 (In WhatsUp Gold versions released before 2026.0.2,a privileged 
attacke ...)
-       TODO: check
+       NOT-FOR-US: Progress Software
 CVE-2026-65938 (In WhatsUp Gold versions released before 2026.0.2,an 
improperauthoriza ...)
-       TODO: check
+       NOT-FOR-US: Progress Software
 CVE-2026-65937 (In WhatsUp Gold versions released before 2026.0.2, an 
authenticated at ...)
-       TODO: check
+       NOT-FOR-US: Progress Software
 CVE-2026-65926 (An anonymous caller when anonymous access is enabled, or a 
low-privile ...)
        TODO: check
 CVE-2026-64955 (When Microsoft Excel imports a CSV file, it executes cells 
beginning w ...)
-       TODO: check
+       NOT-FOR-US: Rapid7
 CVE-2026-64952 (The hunt_delete() VQL function allows deleting hunts.  
Velociraptor mi ...)
-       TODO: check
+       NOT-FOR-US: Rapid7
 CVE-2026-64951 (A rogue Velociraptor client can upload a malformed sparse file 
such th ...)
-       TODO: check
+       NOT-FOR-US: Rapid7
 CVE-2026-64639 (Incorrect database cloning process in Plesk from 18.0.52 
before 18.0.7 ...)
        TODO: check
 CVE-2026-58076 (Apache Airflow's serialization layer reconstructed exception 
nodes by  ...)
@@ -211,21 +211,21 @@ CVE-2026-44741 (Pimcore's Admin Classic Bundle provides a 
Backend UI for Pimcore
 CVE-2026-42018 (JFrog Artifactory could return an internal anonymous-user 
token to an  ...)
        TODO: check
 CVE-2026-26035 (An Improper Authentication vulnerability [CWE-287] 
vulnerability in Fo ...)
-       TODO: check
+       NOT-FOR-US: Fortinet
 CVE-2026-19548 (Multiple Use-After-Free vulnerabilities were found in the 
add_archive_ ...)
        TODO: check
 CVE-2026-19426 (POS System developed by FitSoft has a Missing Authentication 
vulnerabi ...)
        TODO: check
 CVE-2026-19311 (Missing authorization in the Execute Monitor API in Amazon 
OpenSearch  ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-18952 (Missing input validation in the threat intelligence feed 
parser in the ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-18847 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
unauthenticated atta ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18713 (IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to privilege 
escalation via  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18683 (IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege 
escalation via ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18678 (When an operator adds an HTTPS control plane profile to 
kumactl withou ...)
        TODO: check
 CVE-2026-18677 (In Kong Mesh running in universal mode with a MeshIdentity 
whose SPIFF ...)
@@ -237,101 +237,101 @@ CVE-2026-18675 (The dataplane token validator in 
kuma-cp performs an unchecked G
 CVE-2026-18673 (When kuma-dp is configured with the Envoy admin API on a Unix 
domain s ...)
        TODO: check
 CVE-2026-18669 (IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege 
escalation a ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18663 (A flaw was found in 389-ds-base. The 
get_ldapmessage_controls_ext() fu ...)
        TODO: check
 CVE-2026-18652 (Velociraptor allows reading Stacked result sets from the GUI. 
Velocira ...)
-       TODO: check
+       NOT-FOR-US: Rapid7
 CVE-2026-18499 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 
26.0.0.8 i ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18250 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18246 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18244 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
-       TODO: check
+       NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-18235 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18171 (Docker Sandboxes (sbx) applies the read-only intent of a 
runtime host  ...)
        TODO: check
 CVE-2026-18144 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18106 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18098 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18044 (The Estatik Real Estate Plugin WordPress plugin before 4.3.4 
does not  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-17420 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17419 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17418 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated 
attacke ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17276 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17271 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
cause a  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17268 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17266 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17248 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17222 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17218 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
execute  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17110 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17109 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17095 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17094 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17008 (The Quick Paypal Payments WordPress plugin through 5.7.50 does 
not ver ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16999 (Improper restriction of XML external entity reference 
vulnerability in ...)
        TODO: check
 CVE-2026-16990 (The Payment Button for PayPal WordPress plugin through 
1.2.3.44 does n ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16956 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote 
attacker t ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16931 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
cause a  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16907 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16906 (IBM i 7.6, and 7.5 could allow a remote authenticated attacker 
to exec ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16904 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16863 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16860 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16856 (IBM i 7.6, and 7.5 could allow a local attacker to gain 
elevated privi ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16747 (The Kirki WordPress plugin before 6.2.1 does not properly 
authorise it ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16694 (IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored 
cross-site script ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16627 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
-       TODO: check
+       NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-16621 (The Payment Gateway for PayPal on WooCommerce WordPress plugin 
before  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15803 (In Eclipse RDF4J, several XML parser entry points do not fully 
restric ...)
        TODO: check
 CVE-2026-15423 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
-       TODO: check
+       NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-15213 (The Welcart e-Commerce WordPress plugin before 2.11.33 does 
not verify ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15045 (The Wallet System for WooCommerce WordPress plugin before 
2.7.10 does  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14479 (A maliciously crafted input, when processed by the Autodesk 
Installer  ...)
-       TODO: check
+       NOT-FOR-US: Autodesk
 CVE-2026-14478 (A maliciously created executable, when executed on the 
victim's machin ...)
-       TODO: check
+       NOT-FOR-US: Autodesk
 CVE-2026-11325 (Description    Cloudflare was recently notified by external 
researcher ...)
        TODO: check
 CVE-2025-59327 (In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, 
bootxsa.efi ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fd969e8255465aaf2187abde13a62cbcea6b9afb

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fd969e8255465aaf2187abde13a62cbcea6b9afb
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to