Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
3be8a7ea by Salvatore Bonaccorso at 2026-09-18T11:25:44+02:00
Process more NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -505,73 +505,73 @@ CVE-2026-92973 (ansi2html versions 1.7.0a0 through 1.9.3 
contain a cross-site sc
        - python-ansi2html <unfixed>
        NOTE: 
https://github.com/pycontribs/ansi2html/commit/89d1c231c60ac52005f3b21bbba551c786c554fc
 (v1.9.4)
 CVE-2026-92972 (SGLang through 0.5.19 in prefill/decode disaggregation mode 
contains a ...)
-       TODO: check
+       NOT-FOR-US: SGLang
 CVE-2026-92971 (InternLM LMDeploy through 0.17.0 contains a reachable 
assertion vulner ...)
-       TODO: check
+       NOT-FOR-US: InternLM LMDeploy
 CVE-2026-92970 (HUBzero CMS through 2.2.32 contains a path traversal 
vulnerability in  ...)
-       TODO: check
+       NOT-FOR-US: HUBzero CMS
 CVE-2026-92963 (vm2 versions before 3.11.2 fail to properly restrict access to 
the VM2 ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92962 (vm2 is a sandbox for running untrusted JavaScript. In vm2 
versions up  ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92961 (vm2 before 3.11.6 fails to enforce bufferAllocLimit on 
ArrayBuffer, Sh ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92960 (vm2 before 3.11.6 fails to restrict access to os and dns 
builtins unde ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92959 (vm2 before 3.11.8 does not fully enforce the allowAsync: false 
option  ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92958 (vm2 through 3.11.6 contains a builtin-module denylist bypass 
in NodeVM ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92957 (vm2 through 3.11.6 does not normalize `node:`-prefixed builtin 
specifi ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92956 (vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape 
reachable  ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92955 (vm2 before 3.11.8 contains a sandbox escape vulnerability in 
NodeVM th ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92954 (vm2 is a sandbox library for running untrusted JavaScript in 
Node.js.  ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92953 (vm2 versions from 3.11.0 before 3.11.8 fail to protect host 
TypedArray ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92952 (vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js 
registe ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92951 (vm2 before 3.11.7 contains an incorrect authorization 
vulnerability in ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92950 (vm2 before 3.11.7 contains a sandbox escape vulnerability in 
the CLI t ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92949 (vm2 versions from 3.9.6 before 3.11.7 fail to properly 
restrict access ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92948 (vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM 
builtin a ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92947 (vm2 before 3.11.7 exposes Node's shared Buffer pool to 
sandboxed code, ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92946 (vm2 before 3.11.7 contains a remote code execution 
vulnerability when  ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92945 (vm2 before 3.11.7 contains a module allowlist bypass 
vulnerability in  ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92944 (vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape 
vulnerabil ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92943 (Improper validation of certificate with host mismatch in the 
MQTT clie ...)
        NOT-FOR-US: Amazon
 CVE-2026-92942 (vm2 before 3.11.7 (affected versions <= 3.11.6) does not 
enforce the V ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92941 (vm2 versions from 3.11.3 before 3.11.7 expose the host tls 
module to N ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92940 (vm2 versions 3.11.3 through 3.11.6 expose the host process's 
real http ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92939 (vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto 
module to a  ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92938 (vm2 versions 3.11.3 through 3.11.6 expose Node.js's host 
node:sqlite m ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92937 (vm2 3.11.6 is vulnerable to a sandbox escape leading to remote 
code ex ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92936 (vm2 versions 3.11.0 through 3.11.6 leak absolute host 
filesystem paths ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92935 (vm2 is a sandbox for running untrusted Node.js code. In 
versions >= 3. ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92934 (vm2 before 3.11.8 contains an incomplete fix for Error.cause 
sanitizat ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92933 (vm2 is a sandbox for running untrusted Node.js code. In 
versions <= 3. ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-92932 (In the MISP sachertortephp library, the Xml::build() static 
method in  ...)
        - misp <itp> (bug #1144317)
 CVE-2026-92927 (A vulnerability was found in SourceCodester Drug 
Recommendation System ...)
@@ -581,17 +581,17 @@ CVE-2026-92926 (A vulnerability has been found in 
code-projects Matrimonial Syst
 CVE-2026-92925 (A flaw was found in Redis community. The cluster bus packet 
parser, re ...)
        TODO: check
 CVE-2026-92921 (admin3 through 3.0.0 stores account passwords using 
single-round MD5 w ...)
-       TODO: check
+       NOT-FOR-US: cjbi admin3
 CVE-2026-92920 (admin3 through 3.0.0 fails to invalidate existing sessions 
when disabl ...)
-       TODO: check
+       NOT-FOR-US: cjbi admin3
 CVE-2026-92919 (admin3 through 3.0.0 fails to sanitize client-supplied 
filenames in th ...)
-       TODO: check
+       NOT-FOR-US: cjbi admin3
 CVE-2026-92918 (admin3 through 3.0.0 persists user session tokens in the audit 
log eve ...)
-       TODO: check
+       NOT-FOR-US: cjbi admin3
 CVE-2026-92917 (Grav is a flat-file CMS. In versions 2.0.0-rc.1 through 
2.0.21, the Tw ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS
 CVE-2026-92916 (Grav is a flat-file CMS. In Grav 1.7.0 through 1.7.53.2 and 
2.0.0 thro ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS
 CVE-2026-92915 (WWBN AVideo through commit e01e41ecc (no patched version 
available) co ...)
        NOT-FOR-US: WWBN AVideo
 CVE-2026-92914 (AVideo LoginControl contains an authentication bypass 
vulnerability in ...)
@@ -609,13 +609,13 @@ CVE-2026-92894 (A flaw was found in the foreman_ansible 
plugin's Ansible overrid
 CVE-2026-92893 (A flaw was found in the foreman_ansible plugin's Ansible 
inventory API ...)
        TODO: check
 CVE-2026-92881 (A security vulnerability has been detected in vgmstream. The 
affected  ...)
-       TODO: check
+       NOT-FOR-US: vgmstream
 CVE-2026-92880 (A weakness has been identified in vgmstream up to r2117. 
Impacted is t ...)
-       TODO: check
+       NOT-FOR-US: vgmstream
 CVE-2026-92879 (A security flaw has been discovered in vgmstream up to r2117. 
This iss ...)
-       TODO: check
+       NOT-FOR-US: vgmstream
 CVE-2026-92860 (A security flaw has been discovered in rcourtman Pulse up to 
6.0.4/6.1 ...)
-       TODO: check
+       NOT-FOR-US: rcourtman Pulse
 CVE-2026-92758 (If logging mode is set to DEBUG or a malformed MongoDB 
connection stri ...)
        TODO: check
 CVE-2026-92756 (Applications built on MongoDB Entity Framework Core Provider 
which com ...)
@@ -3245,7 +3245,7 @@ CVE-2026-92749 (SafeLine through 9.4.1 derives the 
management console session-si
 CVE-2026-92748 (BC Security Empire before 6.7.1 fails to validate the 
multipart filena ...)
        NOT-FOR-US: BC Security Empire
 CVE-2026-92599 (joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 
and >=18.0 ...)
-       TODO: check
+       NOT-FOR-US: Node joi
 CVE-2026-92598 (Nodemailer before 9.1.0 fails to apply UTS-46 normalization 
when encod ...)
        TODO: check
 CVE-2026-92597 (Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 
comments  ...)
@@ -3291,9 +3291,9 @@ CVE-2026-92578 (WWBN AVideo through 29.0 contains an 
authentication bypass vulne
 CVE-2026-92577 (In AVideo through 29.0, the API get_api_video endpoint 
contains a brok ...)
        NOT-FOR-US: WWBN AVideo
 CVE-2026-92576 (HKUDS nanobot before 0.3.0 contains a server-side request 
forgery vuln ...)
-       TODO: check
+       NOT-FOR-US: HKUDS nanobot
 CVE-2026-92527 (A vulnerability has been found in chatwoot up to 4.17.1. This 
impacts  ...)
-       TODO: check
+       NOT-FOR-US: chatwoot
 CVE-2026-92526 (A flaw has been found in itsourcecode Leave Management System 
1.0. Thi ...)
        NOT-FOR-US: itsourcecode System
 CVE-2026-92475 (A weakness has been identified in GPAC 26.08-DEV. This impacts 
the fun ...)
@@ -3694,17 +3694,17 @@ CVE-2026-92600 (Guns through 8.3.5 contains an 
information disclosure vulnerabil
 CVE-2026-92571
        REJECTED
 CVE-2026-92570 (reNgine through 2.2.0 contains an authorization bypass 
vulnerability i ...)
-       TODO: check
+       NOT-FOR-US: reNgine
 CVE-2026-92569 (Hippo4j through 1.5.0 contains a server-side request forgery 
vulnerabi ...)
-       TODO: check
+       NOT-FOR-US: Hippo4j
 CVE-2026-92568 (MLRun through 1.11.0 contains a server-side request forgery 
vulnerabil ...)
-       TODO: check
+       NOT-FOR-US: MLRun
 CVE-2026-92567 (TDuck survey form through version 5.0 contains an 
authorization bypass ...)
-       TODO: check
+       NOT-FOR-US: TDuck survey
 CVE-2026-92566 (DataGear through 6.0.0 contains a server-side request forgery 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: DataGear
 CVE-2026-92565 (Rallly before 4.15.0 contains an information disclosure 
vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: Rallly
 CVE-2026-92472 (A vulnerability was determined in GPAC 26.08-DEV. The affected 
element ...)
        - gpac <removed>
 CVE-2026-92469 (zlt2000 microservices-platform through 6.0.0 contains an 
authorization ...)
@@ -3736,7 +3736,7 @@ CVE-2026-92456 (yshop-crm through 2.1.3 fails to enforce 
authorization on the sa
 CVE-2026-92455 (yshop-crm through 2.1.3 fails to enforce authorization on the 
sendSms  ...)
        NOT-FOR-US: yshop-crm
 CVE-2026-92418 (A vulnerability was determined in ChangeWeDer crm up to 
c07bd4c9714152 ...)
-       TODO: check
+       NOT-FOR-US: ChangeWeDer CRM
 CVE-2026-92417 (A vulnerability was found in Open5GS up to 2.8.0. This affects 
the fun ...)
        - open5gs <itp> (bug #1094791)
 CVE-2026-92416 (A vulnerability has been found in Open5GS up to 2.8.0. 
Affected by thi ...)
@@ -3748,9 +3748,9 @@ CVE-2026-92406 (A vulnerability was detected in 
SourceCodester Inventory and Mon
 CVE-2026-92405 (A security vulnerability has been detected in SourceCodester 
Inventory ...)
        NOT-FOR-US: SourceCodester
 CVE-2026-92402 (A security flaw has been discovered in ChangeWeDer crm up to 
c07bd4c97 ...)
-       TODO: check
+       NOT-FOR-US: ChangeWeDer CRM
 CVE-2026-92401 (A vulnerability was identified in ChangeWeDer crm up to 
c07bd4c9714152 ...)
-       TODO: check
+       NOT-FOR-US: ChangeWeDer CRM
 CVE-2026-92399 (A vulnerability was determined in GPAC 26.07.0. This affects 
the funct ...)
        - gpac <removed>
 CVE-2026-92398 (A vulnerability was found in Ruijie RG-EW3000GX 
EW_3.0(1)B11P380. Affe ...)
@@ -3774,21 +3774,21 @@ CVE-2026-92365 (A vulnerability was found in 
vllm-project vllm up to 0.29.0. Aff
 CVE-2026-92364 (A vulnerability has been found in itsourcecode Leave 
Management System ...)
        NOT-FOR-US: itsourcecode System
 CVE-2026-92363 (A flaw has been found in ag-ui-protocol ag-ui 1.0. Affected is 
an unkn ...)
-       TODO: check
+       NOT-FOR-US: ag-ui-protocol ag-ui
 CVE-2026-92362 (A vulnerability was detected in ag-ui-protocol ag-ui 1.0. This 
impacts ...)
-       TODO: check
+       NOT-FOR-US: ag-ui-protocol ag-ui
 CVE-2026-92361 (A security vulnerability has been detected in ag-ui-protocol 
ag-ui 1.0 ...)
-       TODO: check
+       NOT-FOR-US: ag-ui-protocol ag-ui
 CVE-2026-92360 (A weakness has been identified in ag-ui-protocol ag-ui 1.0. 
The impact ...)
-       TODO: check
+       NOT-FOR-US: ag-ui-protocol ag-ui
 CVE-2026-92359 (A security flaw has been discovered in ag-ui-protocol ag-ui 
0.3.0. The ...)
-       TODO: check
+       NOT-FOR-US: ag-ui-protocol ag-ui
 CVE-2026-92358 (A flaw was found in the first broker login flow of Keycloak. 
When a us ...)
        - keycloak <itp> (bug #1088287)
 CVE-2026-92357 (A vulnerability was identified in a2ui-project a2ui 
0.8/0.9/1.0. Impac ...)
-       TODO: check
+       NOT-FOR-US: a2ui-project a2ui
 CVE-2026-92356 (A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1. 
This is ...)
-       TODO: check
+       NOT-FOR-US: a2ui-project a2ui
 CVE-2026-92355 (In affected versions of Octopus Server, a user with permission 
to modi ...)
        NOT-FOR-US: Octopus Deploy
 CVE-2026-92299 (@jitsi/electron-sdk before 10.0.5 exposes getDesktopSources() 
via cont ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3be8a7eacf3dd938769c014c69e1d199d19b86a9

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3be8a7eacf3dd938769c014c69e1d199d19b86a9
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to