Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
d550a0b3 by security tracker role at 2026-08-17T19:13:47+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,329 @@
+CVE-2026-9771 (The flash_copy() system call is verified by z_vrfy_flash_copy() 
in dri ...)
+       TODO: check
+CVE-2026-75060 (In JetBrains PyCharm before 2026.2.1 code execution was 
possible via u ...)
+       TODO: check
+CVE-2026-75059 (In JetBrains PyCharm before 2026.2.1 code execution via Quick 
Document ...)
+       TODO: check
+CVE-2026-75058 (In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in 
the Ecl ...)
+       TODO: check
+CVE-2026-75057 (In JetBrains IntelliJ IDEA before 2026.1.5 git credentials 
were writte ...)
+       TODO: check
+CVE-2026-75056 (In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown 
export too ...)
+       TODO: check
+CVE-2026-75055 (In JetBrains IntelliJ IDEA before 2026.2.1 hadoop 
ResourceManager coul ...)
+       TODO: check
+CVE-2026-75054 (In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible 
via the O ...)
+       TODO: check
+CVE-2026-75053 (In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible 
via the D ...)
+       TODO: check
+CVE-2026-75052 (In JetBrains IntelliJ IDEA before 2026.2.1 command execution 
via craft ...)
+       TODO: check
+CVE-2026-75051 (In JetBrains YouTrack before 2026.2.17917 unauthorised project 
transfe ...)
+       TODO: check
+CVE-2026-75050 (In JetBrains YouTrack before 2026.1.13901,  2026.2.17950 doS 
attack wa ...)
+       TODO: check
+CVE-2026-75049 (In JetBrains YouTrack before 2026.1.13903,  2026.2.17950 an 
authentica ...)
+       TODO: check
+CVE-2026-75048 (In JetBrains YouTrack before 2026.2.18068 stored XSS via the 
fenced co ...)
+       TODO: check
+CVE-2026-75047 (In JetBrains YouTrack before 2026.2.18177 doS attack was 
possible via  ...)
+       TODO: check
+CVE-2026-75046 (In JetBrains YouTrack before 2026.2.18112 an authenticated 
user could  ...)
+       TODO: check
+CVE-2026-75045 (In JetBrains YouTrack before 2025.3.156085,  2026.1.13913,  
2026.2.181 ...)
+       TODO: check
+CVE-2026-75044 (In JetBrains YouTrack before 2025.3.156085,  2026.1.13914,  
2026.2.180 ...)
+       TODO: check
+CVE-2026-75011 (A flaw has been found in kylecui NetForensicMCP 2.1.0. 
Impacted is the ...)
+       TODO: check
+CVE-2026-74901 (openssl_encrypt versions before 1.4.0 contain an 
authentication bypass ...)
+       TODO: check
+CVE-2026-74900 (openssl_encrypt versions before 1.4.0 contain a critical 
vulnerability ...)
+       TODO: check
+CVE-2026-74899 (openssl_encrypt versions before 1.4.0 contain a sandbox escape 
vulnera ...)
+       TODO: check
+CVE-2026-74896 (openssl_encrypt versions before 1.4.0 contain a sandbox escape 
vulnera ...)
+       TODO: check
+CVE-2026-74895 (openssl_encrypt versions before 1.4.0 fail to apply sandbox 
restrictio ...)
+       TODO: check
+CVE-2026-74894 (openssl_encrypt before 1.4.0 contains an authentication bypass 
vulnera ...)
+       TODO: check
+CVE-2026-74893 (openssl_encrypt versions before 1.4.0 contain hardcoded 
default JWT si ...)
+       TODO: check
+CVE-2026-74892 (openssl_encrypt versions before 1.4.0 contain a hardcoded 
default secr ...)
+       TODO: check
+CVE-2026-74891 (openssl_encrypt versions before 1.4.0 contain hardcoded 
database crede ...)
+       TODO: check
+CVE-2026-74890 (openssl_encrypt versions before 1.4.0 contain an 
authentication bypass ...)
+       TODO: check
+CVE-2026-74889 (openssl_encrypt versions before 1.4.0 use HKDF with no salt 
and static ...)
+       TODO: check
+CVE-2026-74888 (openssl_encrypt versions before 1.4.0 use a non-standard 
PBKDF2 key de ...)
+       TODO: check
+CVE-2026-74887 (openssl_encrypt before 1.4.0 imports Python's 
non-cryptographic 'rando ...)
+       TODO: check
+CVE-2026-74886 (openssl_encrypt versions before 1.4.0 contain a plugin sandbox 
bypass  ...)
+       TODO: check
+CVE-2026-74885 (openssl_encrypt versions before 1.4.0 contain a logging bug in 
restore ...)
+       TODO: check
+CVE-2026-74884 (openssl_encrypt versions before 1.4.0 contain a path traversal 
vulnera ...)
+       TODO: check
+CVE-2026-74883 (openssl_encrypt versions before 1.4.0 contain a sandbox bypass 
vulnera ...)
+       TODO: check
+CVE-2026-74882 (openssl_encrypt versions before 1.4.0 contain an insecure 
default conf ...)
+       TODO: check
+CVE-2026-74881 (openssl_encrypt versions before 1.4.0 configure CORS with 
allow_origin ...)
+       TODO: check
+CVE-2026-74880 (openssl_encrypt versions before 1.4.0 accept refresh tokens as 
URL que ...)
+       TODO: check
+CVE-2026-74879 (openssl_encrypt versions before 1.4.0 contain an information 
disclosur ...)
+       TODO: check
+CVE-2026-74878 (openssl_encrypt versions before 1.4.0 use an in-memory rate 
limiter fo ...)
+       TODO: check
+CVE-2026-74877 (openssl_encrypt versions before 1.4.0 contain a missing 
ownership veri ...)
+       TODO: check
+CVE-2026-74876 (openssl_encrypt versions before 1.4.0 contain a vulnerability 
in Publi ...)
+       TODO: check
+CVE-2026-74875 (openssl_encrypt versions before 1.4.0 silently skip JSON 
schema valida ...)
+       TODO: check
+CVE-2026-74874 (openssl_encrypt versions before 1.4.0 use Python's 
non-cryptographic r ...)
+       TODO: check
+CVE-2026-74873 (openssl_encrypt versions before 1.4.0 expose passwords passed 
via the  ...)
+       TODO: check
+CVE-2026-74872 (openssl_encrypt versions before 1.4.0 contain an arbitrary 
code execut ...)
+       TODO: check
+CVE-2026-74871 (openssl_encrypt versions before 1.4.6 contain a key derivation 
flaw in ...)
+       TODO: check
+CVE-2026-74870 (openssl_encrypt (pip) versions <= 1.4.7 contain an information 
exposur ...)
+       TODO: check
+CVE-2026-74869 (stoatchat before 0.15.0 contains a missing authorization 
vulnerability ...)
+       TODO: check
+CVE-2026-74868 (SiYuan versions before 3.7.4 contain an unthrottled 
brute-force vulner ...)
+       TODO: check
+CVE-2026-74867 (SiYuan versions before 3.7.4 contain a cross-site request 
forgery vuln ...)
+       TODO: check
+CVE-2026-74858 (A vulnerability has been found in jae-jae fetcher-mcp up to 
0.3.9. Imp ...)
+       TODO: check
+CVE-2026-74845 (Official Document Management System developed by 2100 
Technology has a ...)
+       TODO: check
+CVE-2026-74843 (A vulnerability was determined in Wavlink WN531P3 and WN535M1 
V250922. ...)
+       TODO: check
+CVE-2026-74842 (A vulnerability was found in Kira-Pgr PromptShopMCP up to 
5bc0cd17358e ...)
+       TODO: check
+CVE-2026-74802 (SiYuan versions before 3.7.4 contain a cross-site WebSocket 
hijacking  ...)
+       TODO: check
+CVE-2026-74801 (SiYuan before 3.7.4 fails to properly escape workspace 
directory paths ...)
+       TODO: check
+CVE-2026-74800 (SiYuan before v3.7.4 fails to set Content-Disposition and 
X-Content-Ty ...)
+       TODO: check
+CVE-2026-74799 (SiYuan before 3.7.4 registers Go net/http/pprof debug 
endpoints includ ...)
+       TODO: check
+CVE-2026-74798 (SiYuan kernel before v3.7.4 contains a path traversal 
vulnerability in ...)
+       TODO: check
+CVE-2026-74254 (Joomla Extension - joomlack.fr - SQL injection in Page Builder 
CK < 3. ...)
+       TODO: check
+CVE-2026-74253 (Joomla Extension - regularlabs.com - Unauthenticated RCE 
through unver ...)
+       TODO: check
+CVE-2026-74238 (TIER IV Nebula through 1.2.0 contains an out-of-bounds read 
vulnerabil ...)
+       TODO: check
+CVE-2026-73851 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 
1.29.1  ...)
+       TODO: check
+CVE-2026-73646 (PostCSS takes a CSS file and provides an API to analyze and 
modify its ...)
+       TODO: check
+CVE-2026-73523 (COVESA Open1722 through 0.9.2 contains an integer truncation 
vulnerabi ...)
+       TODO: check
+CVE-2026-73522 (COVESA Open1722 through 0.9.2 contains a stack buffer overflow 
vulnera ...)
+       TODO: check
+CVE-2026-73424 (Astro is a web framework for content-driven websites. From 
10.0.3 unti ...)
+       TODO: check
+CVE-2026-71980 (Belledonne Communications bcg729 through 1.1.2 contains an 
out-of-boun ...)
+       TODO: check
+CVE-2026-71979 (INDI (Instrument Neutral Distributed Interface) indiserver 
through 2.2 ...)
+       TODO: check
+CVE-2026-71693
+       REJECTED
+CVE-2026-71567 (Inopenshift-metal3/fakefish there is a repeated pattern in 
some of the ...)
+       TODO: check
+CVE-2026-71566 (FakeFish handles incoming credentials by passing them down  to 
scripts ...)
+       TODO: check
+CVE-2026-71491 (sqlparse is a non-validating SQL parser module for Python. 
Prior to 0. ...)
+       TODO: check
+CVE-2026-71479 (New API is a large language mode (LLM) gateway and artificial 
intellig ...)
+       TODO: check
+CVE-2026-70412 (Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, 
version p ...)
+       TODO: check
+CVE-2026-68762 (In JetBrains Ktor before 3.4.1 potential DoS attack via 
WebSocket deco ...)
+       TODO: check
+CVE-2026-68520 (Glances is an open-source system cross-platform monitoring 
tool. Prior ...)
+       TODO: check
+CVE-2026-68519 (Glances is an open-source system cross-platform monitoring 
tool. Prior ...)
+       TODO: check
+CVE-2026-68518 (Glances is an open-source system cross-platform monitoring 
tool. Prior ...)
+       TODO: check
+CVE-2026-68517 (Glances is an open-source system cross-platform monitoring 
tool. Prior ...)
+       TODO: check
+CVE-2026-66792 (A flaw was found in the multicloud-operators-subscription 
component. T ...)
+       TODO: check
+CVE-2026-64868 (New API is a large language mode (LLM) gateway and artificial 
intellig ...)
+       TODO: check
+CVE-2026-64866 (New API is a large language mode (LLM) gateway and artificial 
intellig ...)
+       TODO: check
+CVE-2026-64865 (New API is a large language mode (LLM) gateway and artificial 
intellig ...)
+       TODO: check
+CVE-2026-64859 (New API is a large language mode (LLM) gateway and artificial 
intellig ...)
+       TODO: check
+CVE-2026-62982 (Glances is an open-source system cross-platform monitoring 
tool. From  ...)
+       TODO: check
+CVE-2026-61666 (websocket-driver is a WebSocket protocol handler with 
pluggable I/O. P ...)
+       TODO: check
+CVE-2026-60107
+       REJECTED
+CVE-2026-60106
+       REJECTED
+CVE-2026-59911 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an 
Insertion o ...)
+       TODO: check
+CVE-2026-59910 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an 
Improper Ne ...)
+       TODO: check
+CVE-2026-59909 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path 
Travers ...)
+       TODO: check
+CVE-2026-59903 (Netty is an asynchronous, event-driven network application 
framework.  ...)
+       TODO: check
+CVE-2026-59902 (Netty is an asynchronous, event-driven network application 
framework.  ...)
+       TODO: check
+CVE-2026-59894 (sqlparse is a non-validating SQL parser module for Python. 
Prior to 0. ...)
+       TODO: check
+CVE-2026-59893 (sqlparse is a non-validating SQL parser module for Python. 
Prior to 0. ...)
+       TODO: check
+CVE-2026-59829 (Discourse is an open-source discussion platform. Prior to 
2026.1.6, 20 ...)
+       TODO: check
+CVE-2026-58561 (Null pointer dereference issue in the image codec 
module.Impact: Succe ...)
+       TODO: check
+CVE-2026-58560 (Null pointer dereference issue in the image codec 
module.Impact: Succe ...)
+       TODO: check
+CVE-2026-56686 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an 
Improper Ne ...)
+       TODO: check
+CVE-2026-56685 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an 
Improper Ne ...)
+       TODO: check
+CVE-2026-56090 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an 
Uncontrolle ...)
+       TODO: check
+CVE-2026-56089 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path 
Travers ...)
+       TODO: check
+CVE-2026-55704 (Discourse is an open-source discussion platform. Prior o 
2026.1.6, 202 ...)
+       TODO: check
+CVE-2026-55674 (Discourse is an open-source discussion platform. Prior to 
2026.1.6, 20 ...)
+       TODO: check
+CVE-2026-54284 (sqlparse is a non-validating SQL parser module for Python. 
Prior to 0. ...)
+       TODO: check
+CVE-2026-53960 (Discourse is an open-source discussion platform. Prior to 
2026.1.6, 20 ...)
+       TODO: check
+CVE-2026-51346 (SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 
5.4.x bef ...)
+       TODO: check
+CVE-2026-50776 (Directory Traversal vulnerability in Pronis Loisirs 
Billetterie CSE -  ...)
+       TODO: check
+CVE-2026-50775 (A blind SSRF attack in DataHub v.1.5.0.1 allows a remote 
attacker to e ...)
+       TODO: check
+CVE-2026-50774 (An issue in GAPTEQ Designer v.3.5 allows a remote attacker to 
escalate ...)
+       TODO: check
+CVE-2026-50773 (An issue in CGM Germany - CompuGroup Medical CGM ISIS MED 
2510.1.0.20  ...)
+       TODO: check
+CVE-2026-50772 (An issue in Squirro Cognitive Search < 3.14.2 allows a remote 
attacker ...)
+       TODO: check
+CVE-2026-50771 (Cross Site Scripting vulnerability in Squirro Cognitive Search 
< 3.14. ...)
+       TODO: check
+CVE-2026-50770 (An issue in Squirro Cognitive Search before v.3.14.2 allows a 
remote a ...)
+       TODO: check
+CVE-2026-50769 (The CRM+ application before and including version 2025.6 from 
Brainfor ...)
+       TODO: check
+CVE-2026-50768 (File Upload vulnerability in T-Systems International GmbH 
ImageMaster  ...)
+       TODO: check
+CVE-2026-49308 (Permission control vulnerability in the clipboard 
module.Impact: Succe ...)
+       TODO: check
+CVE-2026-49307 (Permission control vulnerability in the multi-mode input 
module.Impact ...)
+       TODO: check
+CVE-2026-49306 (UAF vulnerability in the time and time zone module.Impact: 
Successful  ...)
+       TODO: check
+CVE-2026-49305 (Permission control vulnerability in the Wi-Fi enhancement 
module.Impac ...)
+       TODO: check
+CVE-2026-49304 (Permission control vulnerability in the device key management 
module.I ...)
+       TODO: check
+CVE-2026-49303 (Permission control vulnerability in the notification 
module.Impact: Su ...)
+       TODO: check
+CVE-2026-49302 (Permission control vulnerability in the notification service 
module.Im ...)
+       TODO: check
+CVE-2026-49301 (Permission control vulnerability in the Gallery module.Impact: 
Success ...)
+       TODO: check
+CVE-2026-48053 (Kolibri is an offline-first education platform. Prior to 
version 0.19. ...)
+       TODO: check
+CVE-2026-46345 (compliance-trestle is a tooling platform for managing 
compliance as co ...)
+       TODO: check
+CVE-2026-40145 (A vulnerability exists in the interaction between a Endpoint 
Privilege ...)
+       TODO: check
+CVE-2026-40144 (A memory-corruption vulnerability exists in a kernel-mode 
component of ...)
+       TODO: check
+CVE-2026-40126 (OutSystems Service Center is vulnerable to a DOM-based 
Cross-Site Scri ...)
+       TODO: check
+CVE-2026-33437 (Stirling-PDF is a locally hosted web application that 
facilitates vari ...)
+       TODO: check
+CVE-2026-20000 (A vulnerability was detected in itsourcecode Hospital 
Management Syste ...)
+       TODO: check
+CVE-2026-19999 (A security vulnerability has been detected in Open Asset 
Import Librar ...)
+       TODO: check
+CVE-2026-19998 (A weakness has been identified in code-projects Online 
Shopping System ...)
+       TODO: check
+CVE-2026-19693 (extract-zip through 2.0.1 containment-checks only the parent 
directory ...)
+       TODO: check
+CVE-2026-18674 (On a Kong Mesh global control plane, resources received over 
the zone- ...)
+       TODO: check
+CVE-2026-17639 (Certain HP Smart Tank All-in-One printers may be potentially 
vulnerabl ...)
+       TODO: check
+CVE-2026-16471 (Missing Authorization vulnerability in Dolusoft Software 
Technologies  ...)
+       TODO: check
+CVE-2026-16467 (Missing Authorization vulnerability in Dolusoft Software 
Technologies  ...)
+       TODO: check
+CVE-2026-16139 (In Progress ShareFile Storage Zones Controller versions <= 
5.12.5 and  ...)
+       TODO: check
+CVE-2026-16138 (In Progress ShareFile Storage Zones Controller v5.12.5 and 
below versi ...)
+       TODO: check
+CVE-2026-16137 (In Progress ShareFile Storage Zones Controller v5.12.5 and 
below, a pa ...)
+       TODO: check
+CVE-2026-16049 (Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The 
Mattermost G ...)
+       TODO: check
+CVE-2026-16048 (Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 
10.11.x <= 10. ...)
+       TODO: check
+CVE-2026-16047 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 
11.8.x <= 1 ...)
+       TODO: check
+CVE-2026-16046 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail 
to enfo ...)
+       TODO: check
+CVE-2026-16045 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 
Mattermost f ...)
+       TODO: check
+CVE-2026-16044 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail 
to prev ...)
+       TODO: check
+CVE-2026-15754 (Mattermost versions 11.7.x <= 11.7.6, 11.8.x <= 11.8.3 The 
access cont ...)
+       TODO: check
+CVE-2026-15218 (A flaw was found in the maas-api and maas-controller 
ServiceAccounts w ...)
+       TODO: check
+CVE-2026-14564 (Insufficiently Protected Credentials vulnerability in Innotim 
Software ...)
+       TODO: check
+CVE-2026-13202 (A vulnerability in OpenText Opentext Directory Services allows 
Input D ...)
+       TODO: check
+CVE-2026-12630 (Zephyr's 6LoWPAN IP Header Compression (IPHC) uncompression 
code conta ...)
+       TODO: check
+CVE-2026-12629 (The ARM PL011 UART driver in drivers/serial/uart_pl011.c fails 
to ackn ...)
+       TODO: check
+CVE-2026-12553 (HP has identified a potential vulnerability in HP Web Jetadmin 
(WJA) t ...)
+       TODO: check
+CVE-2026-12519 (The WNC-M14A2A LTE-M modem driver mishandles unsolicited 
%NOTIFYEV: ev ...)
+       TODO: check
+CVE-2026-10527 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 
11.8.x <= 1 ...)
+       TODO: check
+CVE-2025-27772 (UpTrain is an open-source platform to evaluate and improve 
generative  ...)
+       TODO: check
+CVE-2025-27771 (UpTrain is an open-source platform to evaluate and improve 
generative  ...)
+       TODO: check
+CVE-2025-27770 (UpTrain is an open-source platform to evaluate and improve 
generative  ...)
+       TODO: check
+CVE-2025-27621 (UpTrain is an open-source platform to evaluate and improve 
generative  ...)
+       TODO: check
 CVE-2026-XXXX [heap out-of-bounds write during Unicode font-name conversion]
        - antiword <unfixed> (bug #1144645)
 CVE-2026-XXXX [heap out-of-bounds write during OLE PPS name decoding]
@@ -7499,7 +7825,8 @@ CVE-2026-73405 (An authorization bypass vulnerability in 
Vulnerability-Lookup al
        NOT-FOR-US: vulnerability-lookup
 CVE-2026-73374 (A stored cross-site scripting (XSS) vulnerability existed in 
Vulnerabi ...)
        NOT-FOR-US: vulnerability-lookup
-CVE-2026-73327 (Joomla 6.1.1 contains a path traversal vulnerability in the 
com_joomla ...)
+CVE-2026-73327
+       REJECTED
        NOT-FOR-US: Joomla
 CVE-2026-73325 (Fujitsu Research's OneCompression library 1.2.0 contains an 
unsafe des ...)
        NOT-FOR-US: Fujitsu Research's OneCompression library
@@ -8767,7 +9094,8 @@ CVE-2026-72542 (A missing authorization vulnerability in 
Windmill Labs Windmill
        NOT-FOR-US: Windmill
 CVE-2026-72541 (A missing authorization vulnerability in Windmill Labs 
Windmill throug ...)
        NOT-FOR-US: Windmill
-CVE-2026-72540 (An insecure direct object reference vulnerability in 
PhotoPrism throug ...)
+CVE-2026-72540
+       REJECTED
        NOT-FOR-US: PhotoPrism
 CVE-2026-72539 (An information disclosure vulnerability in Windmill Labs 
Windmill thro ...)
        NOT-FOR-US: Windmill
@@ -9436,7 +9764,7 @@ CVE-2026-62724 (Use after free in Windows Telephony 
Service allows an authorized
        NOT-FOR-US: Microsoft
 CVE-2026-62723 (Use after free in Windows Telephony Service allows an 
authorized attac ...)
        NOT-FOR-US: Microsoft
-CVE-2026-62722 (Heap-based buffer overflow in Windows Bind Filter Driver 
allows an aut ...)
+CVE-2026-62722 (Heap-based buffer overflow in Windows Brokering File System 
allows an  ...)
        NOT-FOR-US: Microsoft
 CVE-2026-62721 (Insufficient granularity of access control in User-Mode Power 
Service  ...)
        NOT-FOR-US: Microsoft
@@ -10882,7 +11210,8 @@ CVE-2026-72570 (A stored cross-site scripting (XSS) 
vulnerability in cube-root/d
        NOT-FOR-US: cube-root/directory-serve
 CVE-2026-72569 (A path traversal vulnerability in cube-root/directory-serve 
through 1. ...)
        NOT-FOR-US: cube-root/directory-serve
-CVE-2026-72568 (An out-of-bounds read vulnerability in Redis through 8.8.1 
allows an a ...)
+CVE-2026-72568
+       REJECTED
        - redis <undetermined>
        TODO: check, assigned by a "Turan Security" CNA without further details
 CVE-2026-72567 (An improper path validation vulnerability in 
AsyncFuncAI/deepwiki-open ...)
@@ -11263,36 +11592,36 @@ CVE-2026-68871 (The Yandex Lockbox secrets backend in 
Apache Airflow's Yandex pr
        NOT-FOR-US: Apache Airflow provider
 CVE-2026-68872 (The AWS Systems Manager Parameter Store and Secrets Manager 
backends i ...)
        NOT-FOR-US: Apache Airflow provider
-CVE-2026-74998 [Content proxied by the css proxy is not validated validation]
+CVE-2026-74998 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, 
responses f ...)
        - roundcube 1.6.18+dfsg-1 (bug #1144059)
        NOTE: Fixed by: 
https://github.com/roundcube/roundcubemail/commit/62d33c8a0dc3fd0dd03984220dc9709e8e0de43b
 (1.6.18)
-CVE-2026-75006 [SSRF bypass]
+CVE-2026-75006 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, 
insufficien ...)
        - roundcube 1.6.18+dfsg-1 (bug #1144059)
        NOTE: Fixed by: 
https://github.com/roundcube/roundcubemail/commit/8a92380b06b5df1481e034c4f40d6a6546c21223
 (1.6.18)
        NOTE: Fixed by: 
https://github.com/roundcube/roundcubemail/commit/92f85c883594e5be757154f94548a9ba903455c9
 (1.6.18)
-CVE-2026-75003 [Remote content blocking bypass via unclosed url() in a FuncIRI 
attribute]
+CVE-2026-75003 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an 
unclosed ...)
        - roundcube 1.6.18+dfsg-1 (bug #1144059)
        NOTE: Fixed by: 
https://github.com/roundcube/roundcubemail/commit/1cebea03474305d9f75a9a33d30880d290b5591b
 (1.6.18)
-CVE-2026-75007 [LDAP filter injection via unescaped %u/%fu/%d substitution 
into the `search_filter`]
+CVE-2026-75007 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the 
LDAP se ...)
        - roundcube 1.6.18+dfsg-1 (bug #1144059)
        NOTE: Fixed by: 
https://github.com/roundcube/roundcubemail/commit/e6cc1e121effeaec6d916feb4e019d2828924540
 (1.6.18)
-CVE-2026-75004 [Arbitrary sieve script injection via a filter rule name 
bypassing `managesieve_disabled_actions`]
+CVE-2026-75004 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, 
improper ru ...)
        - roundcube 1.6.18+dfsg-1 (bug #1144059)
        NOTE: Fixed by: 
https://github.com/roundcube/roundcubemail/commit/a1afb8fd1f00ed4cb9376c072bb5ca5ded64495e
 (1.6.18)
-CVE-2026-74997 [RCE in the `cmd_learn` driver of markasjunk plugin]
+CVE-2026-74997 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the 
cmd_lea ...)
        - roundcube 1.6.18+dfsg-1 (bug #1144059)
        NOTE: Fixed by: 
https://github.com/roundcube/roundcubemail/commit/b8f90e28a46d42e79a69568cba897f8f4223d9cd
 (1.6.18)
        NOTE: Follow-up: 
https://github.com/roundcube/roundcubemail/commit/495d211638f222336b20f4744545c53712426c2a
 (1.6.18)
-CVE-2026-75002 [IMAP command injection via mail search and LITERAL+ byte-count 
desynchronization]
+CVE-2026-75002 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, 
mail search ...)
        - roundcube 1.6.18+dfsg-1 (bug #1144059)
        NOTE: Fixed by: 
https://github.com/roundcube/roundcubemail/commit/73233abe581b3b31cefd00041c7086c40e1793ea
 (1.6.18)
-CVE-2026-75010 [The modoboa driver of the passwd plugin leaks an 
authentication token to a user-controlled host]
+CVE-2026-75010 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the 
modoboa ...)
        - roundcube 1.6.18+dfsg-1 (bug #1144059)
        NOTE: Fixed by: 
https://github.com/roundcube/roundcubemail/commit/65b8ea9d8304b10f1d3bda5bcc82f9c682cf804c
 (1.6.18)
-CVE-2026-74999 [Stored XSS in "Add to address book" action]
+CVE-2026-74999 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the 
"Add to ...)
        - roundcube 1.6.18+dfsg-1 (bug #1144059)
        NOTE: Fixed by: 
https://github.com/roundcube/roundcubemail/commit/32f20c6bfd12dff9cfb6880ae303e740f0804fe8
 (1.6.18)
-CVE-2026-75000 [HTML/CSS sanitization bypass via SVG animate `by` attribute]
+CVE-2026-75000 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, 
improper HT ...)
        - roundcube 1.6.18+dfsg-1 (bug #1144059)
        NOTE: Fixed by: 
https://github.com/roundcube/roundcubemail/commit/4a2bb87d9ea93578acb9bb03599abf754c33a33f
 (1.6.18)
 CVE-2026-6791 (When expanding paths that begin with a tilde (~) followed by a 
usernam ...)
@@ -13347,7 +13676,7 @@ CVE-2026-9030 (A denial-of-service vulnerability exists 
in httpd service on Arch
        NOT-FOR-US: TPLink
 CVE-2026-8798 (In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, 
the nati ...)
        NOT-FOR-US: FIPS provider for Bouncycastle, not part of the Debian 
package for Bouncycastle
-CVE-2026-71381 (Adobe Genuine Software Integrity Service was affected by an 
Incorrect  ...)
+CVE-2026-71381 (Adobe Genuine Software Integrity Service on Windows is 
affected by an  ...)
        NOT-FOR-US: Adobe
 CVE-2026-70624
        REJECTED
@@ -15566,7 +15895,8 @@ CVE-2026-71247 (Documenso's sign-field-with-token.ts, 
used by the live document-
        NOT-FOR-US: Documenso
 CVE-2026-71246 (Pixelfed's SearchController (behind the auth middleware) 
accepts a URL ...)
        NOT-FOR-US: Pixelfed
-CVE-2026-71245 (Mautic's getLeadIdsByFieldValueAction 
(LeadBundle/Controller/AjaxContr ...)
+CVE-2026-71245
+       REJECTED
        NOT-FOR-US: Mautic
 CVE-2026-71244 (Paperless-ngx's MailAccountViewSet.test action, when called 
with an ex ...)
        NOT-FOR-US: Paperless-ngx
@@ -34746,23 +35076,23 @@ CVE-2026-5674 (A flaw was found in PipeWire, a 
multimedia server. This vulnerabi
        - pipewire <unfixed> (bug #1142416)
        [trixie] - pipewire <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2455341
-CVE-2026-59867 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 
1.32.5, ...)
+CVE-2026-59867 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 
1.29.1  ...)
        NOT-FOR-US: Kiota
-CVE-2026-59866 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 
1.32.5, ...)
+CVE-2026-59866 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 
1.29.1  ...)
        NOT-FOR-US: Kiota
-CVE-2026-59865 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 
1.32.5, ...)
+CVE-2026-59865 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 
1.29.1  ...)
        NOT-FOR-US: Kiota
-CVE-2026-59864 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 
1.32.5, ...)
+CVE-2026-59864 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 
1.29.1  ...)
        NOT-FOR-US: Kiota
-CVE-2026-59863 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 
1.32.5, ...)
+CVE-2026-59863 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 
1.29.1  ...)
        NOT-FOR-US: Kiota
-CVE-2026-59862 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 
1.32.0, ...)
+CVE-2026-59862 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 
1.29.1  ...)
        NOT-FOR-US: Kiota
-CVE-2026-59861 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 
1.32.0, ...)
+CVE-2026-59861 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 
1.29.1  ...)
        NOT-FOR-US: Kiota
-CVE-2026-59860 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 
1.32.3, ...)
+CVE-2026-59860 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 
1.29.1  ...)
        NOT-FOR-US: Kiota
-CVE-2026-59859 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 
1.32.4, ...)
+CVE-2026-59859 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 
1.29.1  ...)
        NOT-FOR-US: Kiota
 CVE-2026-59249 (Inconsistent interpretation of HTTP requests (HTTP response 
smuggling) ...)
        NOT-FOR-US: elixir-mint mint
@@ -40605,9 +40935,11 @@ CVE-2026-57825
        NOTE: Testcase: 
https://github.com/ocaml/opam/commit/362f5dc08c1436be964e14aa50a5837050124d36 
(2.5.2)
        NOTE: Fixed by: 
https://github.com/ocaml/opam/commit/175a5d777806ad32fa6cdd95f2501dc4bd5e584e 
(2.5.2)
 CVE-2026-44918 (OpenStack Ironic through before 37.0.1 allows creation or 
modification ...)
+       {DSA-6445-1}
        - ironic 1:35.0.1-8 (bug #1141716)
        NOTE: https://security.openstack.org/ossa/OSSA-2026-026.html
 CVE-2026-54423 (In OpenStack Ironic before 37.0.1, an Ironic user with the 
ability to  ...)
+       {DSA-6445-1}
        - ironic 1:35.0.1-8 (bug #1141717)
        NOTE: https://security.openstack.org/ossa/OSSA-2026-025.html
 CVE-2026-3886 [virtio-gpu: fix overflow check when allocating 2d image]
@@ -59686,7 +60018,7 @@ CVE-2026-XXXX [RUSTSEC-2026-0176]
        [bookworm] - rust-pyo3 <not-affected> (Vulnerable code not present, 
only affects 0.24 and later)
        NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0176.html
 CVE-2026-54421 (In OpenStack Ironic before 37.0.1, when applying a PATCH to 
update fie ...)
-       {DLA-4743-1}
+       {DSA-6445-1 DLA-4743-1}
        - ironic 1:35.0.1-6 (bug #1140012)
        NOTE: https://bugs.launchpad.net/ironic/+bug/2155049
 CVE-2026-54420 (LiteSpeed cPanel plugin before 2.4.8 (as distributed in 
LiteSpeed WHM  ...)
@@ -62493,7 +62825,7 @@ CVE-2026-41985 (UAF vulnerability in the package 
management module.Impact: Succe
        NOT-FOR-US: Huawei
 CVE-2026-41984 (UAF vulnerability in the package management module.Impact: 
Successful  ...)
        NOT-FOR-US: Huawei
-CVE-2026-41983 (DoS vulnerability in the browser kernel.Impact: Successful 
exploitatio ...)
+CVE-2026-41983 (Null pointer dereference vulnerability in the browser 
module.Impact: S ...)
        NOT-FOR-US: Huawei
 CVE-2026-41982 (Race condition vulnerability in the IPC module.Impact: 
Successful expl ...)
        NOT-FOR-US: Huawei
@@ -79847,7 +80179,7 @@ CVE-2026-45699 (Netatalk is a Free and Open Source file 
server suite for Unix-li
        {DSA-6280-1}
        - netatalk 4.4.3~ds-1 (bug #1137125)
        NOTE: https://netatalk.io/security/CVE-2026-45699
-CVE-2026-45698
+CVE-2026-45698 (Netatalk is a Free and Open Source file server suite for 
Unix-like ope ...)
        {DSA-6280-1}
        - netatalk 4.4.3~ds-1 (bug #1137126)
        NOTE: https://netatalk.io/security/CVE-2026-45698
@@ -90063,7 +90395,7 @@ CVE-2026-43504 (An issue was discovered in Prosody 
before 0.12.6 and 1.0.0 throu
        NOTE: https://prosody.im/security/advisory_735dd9d3/
        NOTE: https://hg.prosody.im/trunk/rev/4bbb17445ed9
 CVE-2026-43003 (An issue was discovered in OpenStack ironic-python-agent 1.0.0 
through ...)
-       {DLA-4743-1}
+       {DSA-6445-1 DLA-4743-1}
        - ironic 1:35.0.1-7 (bug #1140187)
        - ironic-python-agent 11.5.0-3 (bug #1135646)
        [trixie] - ironic-python-agent <no-dsa> (Minor issue)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d550a0b34e1ca1ae2dcf52d31cfcb6dbf6347fcb

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d550a0b34e1ca1ae2dcf52d31cfcb6dbf6347fcb
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to