Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
62db1477 by security tracker role at 2026-09-14T19:14:54+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -103,9 +103,9 @@ CVE-2026-90802 (A weakness has been identified in GNU 
Binutils 2.47. Affected is
 CVE-2026-90801 (A security flaw has been discovered in GNU Binutils 2.47. This 
impacts ...)
        TODO: check
 CVE-2026-90796 (A vulnerability was identified in itsourcecode Leave 
Management System ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-90795 (A vulnerability was determined in itsourcecode Loan Management 
System  ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-90794 (A vulnerability was found in GPAC up to f1219cde. The affected 
element ...)
        TODO: check
 CVE-2026-90793 (A vulnerability has been found in GPAC up to f1219cde. 
Impacted is the ...)
@@ -117,7 +117,7 @@ CVE-2026-90791 (A vulnerability was detected in GPAC up to 
f1219cde. This vulner
 CVE-2026-90790 (A security vulnerability has been detected in a2aproject 
a2a-python up ...)
        TODO: check
 CVE-2026-90789 (A weakness has been identified in itsourcecode Leave 
Management System ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-90788 (A security flaw has been discovered in magicblack MacCMS10 
2026.1000.4 ...)
        TODO: check
 CVE-2026-90787 (A vulnerability was identified in Soarkey StudentManagement up 
to e08f ...)
@@ -147,35 +147,35 @@ CVE-2026-90708 (A weakness has been identified in Yot CMS 
up to 3.3.1. Affected
 CVE-2026-90707 (A security flaw has been discovered in Open5GS up to 2.7.x. 
Affected i ...)
        TODO: check
 CVE-2026-90706 (A vulnerability was identified in D-Link DWR-M921 1.1.52. This 
impacts ...)
-       TODO: check
+       NOT-FOR-US: D-Link
 CVE-2026-90705 (A vulnerability was determined in D-Link DWR-M921 1.1.52. This 
affects ...)
-       TODO: check
+       NOT-FOR-US: D-Link
 CVE-2026-90704 (A vulnerability was found in D-Link DWR-M921 1.1.52. The 
impacted elem ...)
-       TODO: check
+       NOT-FOR-US: D-Link
 CVE-2026-90703 (A vulnerability has been found in D-Link DWR-M921 1.1.52. The 
affected ...)
-       TODO: check
+       NOT-FOR-US: D-Link
 CVE-2026-90702 (A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is 
the funct ...)
-       TODO: check
+       NOT-FOR-US: D-Link
 CVE-2026-90701 (A vulnerability was detected in subhajitkhan 
online-clinic-management- ...)
        TODO: check
 CVE-2026-90700 (A security vulnerability has been detected in itsourcecode 
Sales and I ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-90699 (A weakness has been identified in D-Link DWR-M920 1.1.7. This 
issue af ...)
-       TODO: check
+       NOT-FOR-US: D-Link
 CVE-2026-90698 (A security flaw has been discovered in memcached 
1.6.41/1.6.42/1.6.43. ...)
        TODO: check
 CVE-2026-90697 (A vulnerability was identified in SourceCodester Inventory 
Management  ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-90696 (A vulnerability was determined in SourceCodester Inventory 
Management  ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-90695 (A vulnerability was found in SourceCodester Inventory 
Management Syste ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-90694 (A vulnerability has been found in SourceCodester Inventory 
Management  ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-90693 (A flaw has been found in D-Link DIR-878 120B05. This impacts 
the funct ...)
-       TODO: check
+       NOT-FOR-US: D-Link
 CVE-2026-90692 (A vulnerability was detected in D-Link DIR-878 120B05. This 
affects th ...)
-       TODO: check
+       NOT-FOR-US: D-Link
 CVE-2026-90463 (A flaw was found in the sssd NSS responder. This input 
validation vuln ...)
        TODO: check
 CVE-2026-8821 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x 
<= 11.7 ...)
@@ -187,35 +187,35 @@ CVE-2026-89180 (EFence developed by Thinking Software 
Technology has a SQL Injec
 CVE-2026-89023 (ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 
contain ...)
        TODO: check
 CVE-2026-89021 (MikroTik RouterOS before 7.24.2 contains a path traversal 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: MikroTik
 CVE-2026-89020 (MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 
(stable) contai ...)
-       TODO: check
+       NOT-FOR-US: MikroTik
 CVE-2026-88932 (multer is a Node.js middleware for handling 
multipart/form-data upload ...)
        TODO: check
 CVE-2026-88819 (In Siglet current and past versions the refresh token handler 
do not e ...)
        TODO: check
 CVE-2026-87802 (Improper verification of cryptographic signature vulnerability 
in Apac ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-87785 (Authentication bypass by spoofing vulnerability in Apache 
Syncope.     ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-87779 (Insertion of sensitive information into log file vulnerability 
in Apac ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-87087
        REJECTED
 CVE-2026-86836 (In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent 
creates wor ...)
        TODO: check
 CVE-2026-86830 (Incorrect privilege assignment in Temporary Elevated Access 
Management ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-86460 (Cypher injection vulnerability in the Neo4j persistence layer 
when pro ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-86349 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x 
<= 11.7 ...)
        TODO: check
 CVE-2026-86348 (Mattermost versions <=11.9 11.0.9 11.4.8 11.7.7 10.22.11.0 
fail to rec ...)
        TODO: check
 CVE-2026-85921 (Double free in Windows Secure Kernel Mode allows an authorized 
attacke ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-85892 (Concurrent execution using shared resource with improper 
synchronizati ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-84445 (gRPC-Go is the Go language implementation of gRPC. Prior to 
1.82.2 and ...)
        TODO: check
 CVE-2026-84179 (Description    getTopologyPageInfo merged the Nimbus daemon 
configurat ...)
@@ -239,29 +239,29 @@ CVE-2026-82433 (Description  `getNimbusConf` returned the 
complete daemon config
 CVE-2026-82432 (Description  Nimbus validated `topology.blobstore.map` against 
the cal ...)
        TODO: check
 CVE-2026-82431 (Description  `SimpleACLAuthorizer` evaluated the user-level 
command se ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-82430 (Description  When launching a Docker or OCI worker, the 
setuid-root `w ...)
        TODO: check
 CVE-2026-82429 (Description  The setuid-root `worker-launcher` binary adjusts 
ownershi ...)
        TODO: check
 CVE-2026-82428 (Description  Dependency artifacts uploaded with `storm jar 
--artifacts ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-82427 (Description  A topology's `topology.blobstore.map` lets the 
submitter  ...)
        TODO: check
 CVE-2026-82426 (Description  Nimbus accepted the `uploadedJarLocation` 
argument of `su ...)
        TODO: check
 CVE-2026-82232 (Improper neutralization of special elements used in an SQL 
command ('S ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-82035 (PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a 
path trave ...)
        TODO: check
 CVE-2026-82019 (TripleLift's ad rendering script (video-bundle.js) contains a 
DOM-base ...)
        TODO: check
 CVE-2026-81566 (Joomla Extension - joomshaper.com - Missing Access Control in 
Menu Ite ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-81565 (Joomla Extension - joomshaper.com - Missing Directory 
Confinement in M ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-81564 (Joomla Extension - joomshaper.com - Missing Directory 
Confinement in M ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-81301 (Ekia File Manager 1.2.7 exposes 
com.ekia.filecontrolmanager.OpenFilePr ...)
        TODO: check
 CVE-2026-7848 (Alior Bank PrestaShop module "raty"for commercial partners is 
vulnerab ...)
@@ -269,31 +269,31 @@ CVE-2026-7848 (Alior Bank PrestaShop module "raty"for 
commercial partners is vul
 CVE-2026-7208 (Yealink SIP-T33G firmware versions 124.86.x.x prior to 
124.87.0.0 cont ...)
        TODO: check
 CVE-2026-79701 (Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA 
Bypass in  ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-79700 (Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA 
Bypass via ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-78375 (Joomla Extension - joomshaper.com - Authenticated Privileged 
SQL Injec ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-78336 (Insertion of sensitive information into sent data 
vulnerability in Apa ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-78330 (Incorrect privilege assignment vulnerability in Apache 
Syncope.  When  ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-78318 (Improper neutralization of input during web page generation 
('cross-si ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-78299 (In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack 
archive  ...)
        TODO: check
 CVE-2026-77884 (Gallery - Private Photo Vault 1.0.41 starts an unauthenticated 
HTTP se ...)
        TODO: check
 CVE-2026-77883 (Exposure of sensitive information through data queries 
vulnerability i ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-77181 (Incorrect Authorization vulnerability in Apache Syncope.    An 
adminis ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-77147 (Improper Control of Generation of Code ('Code Injection') 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-77051 (Improper Neutralization of Special Elements used in an SQL 
Command ('S ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-76461 (A vulnerability in the email parsing of Cisco AsyncOS Software 
for Cis ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-76443 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
        TODO: check
 CVE-2026-76442 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
@@ -303,27 +303,27 @@ CVE-2026-76441 (As part of Cisco's ongoing commitment to 
proactive security and
 CVE-2026-76440 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
        TODO: check
 CVE-2026-75030 (Missing Authorization vulnerability in Apache Syncope.    An 
administr ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-75015 (Insufficiently Protected Credentials vulnerability in Apache 
Syncope.  ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-73668 (Incorrect Authorization vulnerability in Apache Syncope.      
An admin ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-73579 (Incorrect Authorization vulnerability in Apache Syncope.    
Any search ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-73494 (blaze is a Scala library for building asynchronous pipelines, 
with a f ...)
        TODO: check
 CVE-2026-73470 (Improper Privilege Management vulnerability in Apache Syncope. 
     De ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-73370 (Incorrect Authorization vulnerability in Apache Syncope.    
Delegated  ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-73236 (Incorrect Authorization vulnerability in Apache Syncope.    
Delegated  ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-73195 (Improper Encoding or Escaping of Output vulnerability in 
Apache Syncop ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-73191 (URL Redirection to Untrusted Site ('Open Redirect') 
vulnerability in A ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-73178 (Exposure of Sensitive Information to an Unauthorized Actor 
vulnerabili ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-72524 (Incorrect Authorization vulnerability in Apache Doris allows 
an authen ...)
        TODO: check
 CVE-2026-70658 (Pay is a payments engine for Ruby on Rails 6.0 and higher. 
Prior to 11 ...)
@@ -339,9 +339,9 @@ CVE-2026-5132 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x 
<= 11.8.4, 11.7.x <=
 CVE-2026-59960 (Argos JavaScript provides official Argos SDKs for JavaScript. 
Prior to ...)
        TODO: check
 CVE-2026-59570 (On affected versions of Zscaler client connector, a 
pre-installed peer ...)
-       TODO: check
+       NOT-FOR-US: Zscaler
 CVE-2026-59569 (An improper input validation vulnerability in Zscaler Client 
Connector ...)
-       TODO: check
+       NOT-FOR-US: Zscaler
 CVE-2026-59178 (ESPHome Device Builder Dashboard is a dashboard for the 
ESPHome home m ...)
        TODO: check
 CVE-2026-57583 (OpenZeppelin Contracts Wizard is a web application to 
interactively bu ...)
@@ -401,7 +401,7 @@ CVE-2026-55837 (dbt-mcp is a Model Context Protocol server 
for interacting with
 CVE-2026-55832 (Tract is a tiny, no-nonsense, self-contained TensorFlow and 
ONNX infer ...)
        TODO: check
 CVE-2026-55795 (Craft Commerce is an ecommerce platform for Craft CMS. From 
4.0.0 unti ...)
-       TODO: check
+       NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-55451 (gettext-converter provides gettext resource conversion 
utilities for J ...)
        TODO: check
 CVE-2026-55416 (Pimcore is an Open Source Data & Experience Management 
Platform. Prior ...)
@@ -451,7 +451,7 @@ CVE-2026-54156 (node-opcua is an OPC UA implementation for 
TypeScript and Node.j
 CVE-2026-54155 (node-opcua is an OPC UA implementation for TypeScript and 
Node.js. Pri ...)
        TODO: check
 CVE-2026-54150 (next-video is a library for adding video to Next.js 
applications. Prio ...)
-       TODO: check
+       NOT-FOR-US: Next.js
 CVE-2026-54087 (EasyAdmin is a fast and modern admin generator for Symfony 
application ...)
        TODO: check
 CVE-2026-53752 (docx4j is an open source Java library for creating, editing, 
and savin ...)
@@ -471,7 +471,7 @@ CVE-2026-50270 (dd-trace-java is a Datadog APM client for 
Java. Prior to 1.62.0,
 CVE-2026-50157 (Auth0 Symfony is a Symfony SDK for Auth0 Authentication and 
Management ...)
        TODO: check
 CVE-2026-4103 (Insufficient HTML sanitization in the Publisher Portal and 
Developer P ...)
-       TODO: check
+       NOT-FOR-US: WSO2
 CVE-2026-49400 (October System provides the system module for October Content 
Manageme ...)
        TODO: check
 CVE-2026-49250 (Conform, a type-safe form validation library, allows the 
parsing of ne ...)
@@ -483,25 +483,25 @@ CVE-2026-46696 (October System provides the system module 
for October Content Ma
 CVE-2026-44162 (fluent-plugin-s3 is an Amazon S3 input and output plugin for 
Fluentd.  ...)
        TODO: check
 CVE-2026-34151 (XWiki Platform is a generic wiki platform. Prior to 17.10.5 
and 18.2.0 ...)
-       TODO: check
+       NOT-FOR-US: XWiki
 CVE-2026-25687 (A race condition in the ZPA tunnel handler of affected 
versions of Zsc ...)
-       TODO: check
+       NOT-FOR-US: Zscaler
 CVE-2026-21391 (An improper validation vulnerability exists within PingAM 
where a well ...)
-       TODO: check
+       NOT-FOR-US: Ping Identity Corporation
 CVE-2026-20773 (A role-based access control issue was identified in the 
administrative ...)
-       TODO: check
+       NOT-FOR-US: Ping Identity Corporation
 CVE-2026-20353 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-19543 (IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, 
ART 9.0, ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18515 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18151 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-15923 (The Zephyr SDIO subsystem function 
sdio_io_rw_extended_helper() in sub ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-15893 (net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c 
derives a  ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-15814 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x 
<= 11.7 ...)
        TODO: check
 CVE-2026-15600 (Alior Bank PrestaShop module "raty" for commercial partners is 
vulnera ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/62db14776f15d035ae41a35205d8e0b74299984c

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/62db14776f15d035ae41a35205d8e0b74299984c
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to