Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
5cd99052 by Moritz Muehlenhoff at 2026-08-14T10:12:11+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -873,7 +873,7 @@ CVE-2026-66426 (Unauthenticated Cross Site Scripting (XSS)
in WP-Stats <= 2.56 v
CVE-2026-66424 (Unauthenticated Privilege Escalation in SMS Alert Order
Notifications ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-66256 (** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted
Data vuln ...)
- TODO: check
+ NOT-FOR-US: Apache Shindig
CVE-2026-65936 (A malformed Bluetooth connection request message can cause the
RS9116W ...)
NOT-FOR-US: Silicon Labs
CVE-2026-65935 (Passkey entry Bluetooth LE legacy pairing can be bypassed in
the RS911 ...)
@@ -923,25 +923,25 @@ CVE-2026-59765 (SSRF via Migration Asset Downloads
Bypasses hostmatcher \u2014 R
CVE-2026-59763 (Unbounded Arch package file metadata can cause resource
amplification ...)
NOT-FOR-US: Gitea (used to be packaged in the Debian archive as
src:gitea, but never in a stable release)
CVE-2026-59507 (CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of
Sensitive ...)
- TODO: check
+ NOT-FOR-US: Priority ERP
CVE-2026-59506 (CWE-306: Missing Authentication for Critical Function)
- TODO: check
+ NOT-FOR-US: Priority ERP
CVE-2026-59505 (CWE-284: Improper Access Control)
- TODO: check
+ NOT-FOR-US: Priority ERP
CVE-2026-59504 (CWE-602: Client-Side Enforcement of Server-Side Security)
- TODO: check
+ NOT-FOR-US: Priority ERP
CVE-2026-59503 (CWE-200: Exposure of Sensitive Information to an Unauthorized
Actor CW ...)
- TODO: check
+ NOT-FOR-US: Priority ERP
CVE-2026-59502 (CWE-203: Observable Discrepancy)
- TODO: check
+ NOT-FOR-US: Priority ERP
CVE-2026-59501 (CWE-284: Improper Access Control)
- TODO: check
+ NOT-FOR-US: Priority ERP
CVE-2026-59500 (CWE-287: Improper Authentication)
- TODO: check
+ NOT-FOR-US: Priority ERP
CVE-2026-59499 (CWE-200: Exposure of Sensitive Information to an Unauthorized
Actor)
- TODO: check
+ NOT-FOR-US: Priority ERP
CVE-2026-59109 (SQL injection in the Zalktis accounting application via
trading-partne ...)
- TODO: check
+ NOT-FOR-US: Zalktis
CVE-2026-58511 (Webhook Authorization Header Returned in Plaintext via API)
NOT-FOR-US: Gitea (used to be packaged in the Debian archive as
src:gitea, but never in a stable release)
CVE-2026-58510 (GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API
EditRepo p ...)
@@ -1031,15 +1031,15 @@ CVE-2026-54481 (Internal API HTTP client hardcodes
InsecureSkipVerify:true with
CVE-2026-50105 (RSS/Atom feed handlers bypass API-token scope & public-only
confinemen ...)
NOT-FOR-US: Gitea (used to be packaged in the Debian archive as
src:gitea, but never in a stable release)
CVE-2026-49857 (auth-fetch-mcp is an MCP server that lets AI assistants fetch
content ...)
- TODO: check
+ NOT-FOR-US: auth-fetch-mcp
CVE-2026-49856 (@jshookmcp/jshook is an MCP server that gives AI agents tools
for Java ...)
- TODO: check
+ NOT-FOR-US: jshookmcp/jshook
CVE-2026-49827 (WebErpMesv2 is a Resource Management and Manufacturing
execution syste ...)
- TODO: check
+ NOT-FOR-US: WebErpMesv2
CVE-2026-49820 (Probo is a self-hostable governance, risk, and compliance
(GRC) platfo ...)
- TODO: check
+ NOT-FOR-US: Probo
CVE-2026-45819 (baseline-browser-mapping 2.x before 2.11.0 calls
process.exit() instea ...)
- TODO: check
+ NOT-FOR-US: baseline-browser-mapping
CVE-2026-42931 (Denial of Service via Unbounded io.ReadAll in NPM Package Tag
Endpoint)
NOT-FOR-US: Gitea (used to be packaged in the Debian archive as
src:gitea, but never in a stable release)
CVE-2026-3639 (The PPWP \u2013 Password Protect Pages plugin for WordPress is
vulnera ...)
@@ -1085,7 +1085,7 @@ CVE-2026-28156 (Subscriber SQL Injection in Do Lasso <=
358 versions.)
CVE-2026-28155 (Unauthenticated Insecure Direct Object References (IDOR) in Do
Lasso < ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-28154 (Improper Neutralization of Input During Web Page Generation
('Cross-si ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28149 (Unauthenticated PHP Object Injection in Headless Single Sign
On <= 1.6 ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-28148 (Unauthenticated Bypass Vulnerability in Headless Single Sign
On <= 1.6 ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5cd990520013f45621311637cbb153fcfc2803f1
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5cd990520013f45621311637cbb153fcfc2803f1
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits