Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
5cd99052 by Moritz Muehlenhoff at 2026-08-14T10:12:11+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -873,7 +873,7 @@ CVE-2026-66426 (Unauthenticated Cross Site Scripting (XSS) 
in WP-Stats <= 2.56 v
 CVE-2026-66424 (Unauthenticated Privilege Escalation in SMS Alert Order 
Notifications  ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66256 (** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted 
Data vuln ...)
-       TODO: check
+       NOT-FOR-US: Apache Shindig
 CVE-2026-65936 (A malformed Bluetooth connection request message can cause the 
RS9116W ...)
        NOT-FOR-US: Silicon Labs
 CVE-2026-65935 (Passkey entry Bluetooth LE legacy pairing can be bypassed in 
the RS911 ...)
@@ -923,25 +923,25 @@ CVE-2026-59765 (SSRF via Migration Asset Downloads 
Bypasses hostmatcher \u2014 R
 CVE-2026-59763 (Unbounded Arch package file metadata can cause resource 
amplification  ...)
        NOT-FOR-US: Gitea (used to be packaged in the Debian archive as 
src:gitea, but never in a stable release)
 CVE-2026-59507 (CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of 
Sensitive  ...)
-       TODO: check
+       NOT-FOR-US: Priority ERP
 CVE-2026-59506 (CWE-306: Missing Authentication for Critical Function)
-       TODO: check
+       NOT-FOR-US: Priority ERP
 CVE-2026-59505 (CWE-284: Improper Access Control)
-       TODO: check
+       NOT-FOR-US: Priority ERP
 CVE-2026-59504 (CWE-602: Client-Side Enforcement of Server-Side Security)
-       TODO: check
+       NOT-FOR-US: Priority ERP
 CVE-2026-59503 (CWE-200: Exposure of Sensitive Information to an Unauthorized 
Actor CW ...)
-       TODO: check
+       NOT-FOR-US: Priority ERP
 CVE-2026-59502 (CWE-203: Observable Discrepancy)
-       TODO: check
+       NOT-FOR-US: Priority ERP
 CVE-2026-59501 (CWE-284: Improper Access Control)
-       TODO: check
+       NOT-FOR-US: Priority ERP
 CVE-2026-59500 (CWE-287: Improper Authentication)
-       TODO: check
+       NOT-FOR-US: Priority ERP
 CVE-2026-59499 (CWE-200: Exposure of Sensitive Information to an Unauthorized 
Actor)
-       TODO: check
+       NOT-FOR-US: Priority ERP
 CVE-2026-59109 (SQL injection in the Zalktis accounting application via 
trading-partne ...)
-       TODO: check
+       NOT-FOR-US: Zalktis
 CVE-2026-58511 (Webhook Authorization Header Returned in Plaintext via API)
        NOT-FOR-US: Gitea (used to be packaged in the Debian archive as 
src:gitea, but never in a stable release)
 CVE-2026-58510 (GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API 
EditRepo p ...)
@@ -1031,15 +1031,15 @@ CVE-2026-54481 (Internal API HTTP client hardcodes 
InsecureSkipVerify:true with
 CVE-2026-50105 (RSS/Atom feed handlers bypass API-token scope & public-only 
confinemen ...)
        NOT-FOR-US: Gitea (used to be packaged in the Debian archive as 
src:gitea, but never in a stable release)
 CVE-2026-49857 (auth-fetch-mcp is an MCP server that lets AI assistants fetch 
content  ...)
-       TODO: check
+       NOT-FOR-US: auth-fetch-mcp
 CVE-2026-49856 (@jshookmcp/jshook is an MCP server that gives AI agents tools 
for Java ...)
-       TODO: check
+       NOT-FOR-US: jshookmcp/jshook
 CVE-2026-49827 (WebErpMesv2 is a Resource Management and Manufacturing 
execution syste ...)
-       TODO: check
+       NOT-FOR-US: WebErpMesv2
 CVE-2026-49820 (Probo is a self-hostable governance, risk, and compliance 
(GRC) platfo ...)
-       TODO: check
+       NOT-FOR-US: Probo
 CVE-2026-45819 (baseline-browser-mapping 2.x before 2.11.0 calls 
process.exit() instea ...)
-       TODO: check
+       NOT-FOR-US: baseline-browser-mapping
 CVE-2026-42931 (Denial of Service via Unbounded io.ReadAll in NPM Package Tag 
Endpoint)
        NOT-FOR-US: Gitea (used to be packaged in the Debian archive as 
src:gitea, but never in a stable release)
 CVE-2026-3639 (The PPWP \u2013 Password Protect Pages plugin for WordPress is 
vulnera ...)
@@ -1085,7 +1085,7 @@ CVE-2026-28156 (Subscriber SQL Injection in Do Lasso <= 
358 versions.)
 CVE-2026-28155 (Unauthenticated Insecure Direct Object References (IDOR) in Do 
Lasso < ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28154 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28149 (Unauthenticated PHP Object Injection in Headless Single Sign 
On <= 1.6 ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28148 (Unauthenticated Bypass Vulnerability in Headless Single Sign 
On <= 1.6 ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5cd990520013f45621311637cbb153fcfc2803f1

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5cd990520013f45621311637cbb153fcfc2803f1
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to