Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
3be8a7ea by Salvatore Bonaccorso at 2026-09-18T11:25:44+02:00
Process more NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -505,73 +505,73 @@ CVE-2026-92973 (ansi2html versions 1.7.0a0 through 1.9.3
contain a cross-site sc
- python-ansi2html <unfixed>
NOTE:
https://github.com/pycontribs/ansi2html/commit/89d1c231c60ac52005f3b21bbba551c786c554fc
(v1.9.4)
CVE-2026-92972 (SGLang through 0.5.19 in prefill/decode disaggregation mode
contains a ...)
- TODO: check
+ NOT-FOR-US: SGLang
CVE-2026-92971 (InternLM LMDeploy through 0.17.0 contains a reachable
assertion vulner ...)
- TODO: check
+ NOT-FOR-US: InternLM LMDeploy
CVE-2026-92970 (HUBzero CMS through 2.2.32 contains a path traversal
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: HUBzero CMS
CVE-2026-92963 (vm2 versions before 3.11.2 fail to properly restrict access to
the VM2 ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92962 (vm2 is a sandbox for running untrusted JavaScript. In vm2
versions up ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92961 (vm2 before 3.11.6 fails to enforce bufferAllocLimit on
ArrayBuffer, Sh ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92960 (vm2 before 3.11.6 fails to restrict access to os and dns
builtins unde ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92959 (vm2 before 3.11.8 does not fully enforce the allowAsync: false
option ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92958 (vm2 through 3.11.6 contains a builtin-module denylist bypass
in NodeVM ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92957 (vm2 through 3.11.6 does not normalize `node:`-prefixed builtin
specifi ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92956 (vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape
reachable ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92955 (vm2 before 3.11.8 contains a sandbox escape vulnerability in
NodeVM th ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92954 (vm2 is a sandbox library for running untrusted JavaScript in
Node.js. ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92953 (vm2 versions from 3.11.0 before 3.11.8 fail to protect host
TypedArray ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92952 (vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js
registe ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92951 (vm2 before 3.11.7 contains an incorrect authorization
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92950 (vm2 before 3.11.7 contains a sandbox escape vulnerability in
the CLI t ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92949 (vm2 versions from 3.9.6 before 3.11.7 fail to properly
restrict access ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92948 (vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM
builtin a ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92947 (vm2 before 3.11.7 exposes Node's shared Buffer pool to
sandboxed code, ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92946 (vm2 before 3.11.7 contains a remote code execution
vulnerability when ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92945 (vm2 before 3.11.7 contains a module allowlist bypass
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92944 (vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape
vulnerabil ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92943 (Improper validation of certificate with host mismatch in the
MQTT clie ...)
NOT-FOR-US: Amazon
CVE-2026-92942 (vm2 before 3.11.7 (affected versions <= 3.11.6) does not
enforce the V ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92941 (vm2 versions from 3.11.3 before 3.11.7 expose the host tls
module to N ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92940 (vm2 versions 3.11.3 through 3.11.6 expose the host process's
real http ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92939 (vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto
module to a ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92938 (vm2 versions 3.11.3 through 3.11.6 expose Node.js's host
node:sqlite m ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92937 (vm2 3.11.6 is vulnerable to a sandbox escape leading to remote
code ex ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92936 (vm2 versions 3.11.0 through 3.11.6 leak absolute host
filesystem paths ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92935 (vm2 is a sandbox for running untrusted Node.js code. In
versions >= 3. ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92934 (vm2 before 3.11.8 contains an incomplete fix for Error.cause
sanitizat ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92933 (vm2 is a sandbox for running untrusted Node.js code. In
versions <= 3. ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-92932 (In the MISP sachertortephp library, the Xml::build() static
method in ...)
- misp <itp> (bug #1144317)
CVE-2026-92927 (A vulnerability was found in SourceCodester Drug
Recommendation System ...)
@@ -581,17 +581,17 @@ CVE-2026-92926 (A vulnerability has been found in
code-projects Matrimonial Syst
CVE-2026-92925 (A flaw was found in Redis community. The cluster bus packet
parser, re ...)
TODO: check
CVE-2026-92921 (admin3 through 3.0.0 stores account passwords using
single-round MD5 w ...)
- TODO: check
+ NOT-FOR-US: cjbi admin3
CVE-2026-92920 (admin3 through 3.0.0 fails to invalidate existing sessions
when disabl ...)
- TODO: check
+ NOT-FOR-US: cjbi admin3
CVE-2026-92919 (admin3 through 3.0.0 fails to sanitize client-supplied
filenames in th ...)
- TODO: check
+ NOT-FOR-US: cjbi admin3
CVE-2026-92918 (admin3 through 3.0.0 persists user session tokens in the audit
log eve ...)
- TODO: check
+ NOT-FOR-US: cjbi admin3
CVE-2026-92917 (Grav is a flat-file CMS. In versions 2.0.0-rc.1 through
2.0.21, the Tw ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-92916 (Grav is a flat-file CMS. In Grav 1.7.0 through 1.7.53.2 and
2.0.0 thro ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-92915 (WWBN AVideo through commit e01e41ecc (no patched version
available) co ...)
NOT-FOR-US: WWBN AVideo
CVE-2026-92914 (AVideo LoginControl contains an authentication bypass
vulnerability in ...)
@@ -609,13 +609,13 @@ CVE-2026-92894 (A flaw was found in the foreman_ansible
plugin's Ansible overrid
CVE-2026-92893 (A flaw was found in the foreman_ansible plugin's Ansible
inventory API ...)
TODO: check
CVE-2026-92881 (A security vulnerability has been detected in vgmstream. The
affected ...)
- TODO: check
+ NOT-FOR-US: vgmstream
CVE-2026-92880 (A weakness has been identified in vgmstream up to r2117.
Impacted is t ...)
- TODO: check
+ NOT-FOR-US: vgmstream
CVE-2026-92879 (A security flaw has been discovered in vgmstream up to r2117.
This iss ...)
- TODO: check
+ NOT-FOR-US: vgmstream
CVE-2026-92860 (A security flaw has been discovered in rcourtman Pulse up to
6.0.4/6.1 ...)
- TODO: check
+ NOT-FOR-US: rcourtman Pulse
CVE-2026-92758 (If logging mode is set to DEBUG or a malformed MongoDB
connection stri ...)
TODO: check
CVE-2026-92756 (Applications built on MongoDB Entity Framework Core Provider
which com ...)
@@ -3245,7 +3245,7 @@ CVE-2026-92749 (SafeLine through 9.4.1 derives the
management console session-si
CVE-2026-92748 (BC Security Empire before 6.7.1 fails to validate the
multipart filena ...)
NOT-FOR-US: BC Security Empire
CVE-2026-92599 (joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7
and >=18.0 ...)
- TODO: check
+ NOT-FOR-US: Node joi
CVE-2026-92598 (Nodemailer before 9.1.0 fails to apply UTS-46 normalization
when encod ...)
TODO: check
CVE-2026-92597 (Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322
comments ...)
@@ -3291,9 +3291,9 @@ CVE-2026-92578 (WWBN AVideo through 29.0 contains an
authentication bypass vulne
CVE-2026-92577 (In AVideo through 29.0, the API get_api_video endpoint
contains a brok ...)
NOT-FOR-US: WWBN AVideo
CVE-2026-92576 (HKUDS nanobot before 0.3.0 contains a server-side request
forgery vuln ...)
- TODO: check
+ NOT-FOR-US: HKUDS nanobot
CVE-2026-92527 (A vulnerability has been found in chatwoot up to 4.17.1. This
impacts ...)
- TODO: check
+ NOT-FOR-US: chatwoot
CVE-2026-92526 (A flaw has been found in itsourcecode Leave Management System
1.0. Thi ...)
NOT-FOR-US: itsourcecode System
CVE-2026-92475 (A weakness has been identified in GPAC 26.08-DEV. This impacts
the fun ...)
@@ -3694,17 +3694,17 @@ CVE-2026-92600 (Guns through 8.3.5 contains an
information disclosure vulnerabil
CVE-2026-92571
REJECTED
CVE-2026-92570 (reNgine through 2.2.0 contains an authorization bypass
vulnerability i ...)
- TODO: check
+ NOT-FOR-US: reNgine
CVE-2026-92569 (Hippo4j through 1.5.0 contains a server-side request forgery
vulnerabi ...)
- TODO: check
+ NOT-FOR-US: Hippo4j
CVE-2026-92568 (MLRun through 1.11.0 contains a server-side request forgery
vulnerabil ...)
- TODO: check
+ NOT-FOR-US: MLRun
CVE-2026-92567 (TDuck survey form through version 5.0 contains an
authorization bypass ...)
- TODO: check
+ NOT-FOR-US: TDuck survey
CVE-2026-92566 (DataGear through 6.0.0 contains a server-side request forgery
vulnerab ...)
- TODO: check
+ NOT-FOR-US: DataGear
CVE-2026-92565 (Rallly before 4.15.0 contains an information disclosure
vulnerability ...)
- TODO: check
+ NOT-FOR-US: Rallly
CVE-2026-92472 (A vulnerability was determined in GPAC 26.08-DEV. The affected
element ...)
- gpac <removed>
CVE-2026-92469 (zlt2000 microservices-platform through 6.0.0 contains an
authorization ...)
@@ -3736,7 +3736,7 @@ CVE-2026-92456 (yshop-crm through 2.1.3 fails to enforce
authorization on the sa
CVE-2026-92455 (yshop-crm through 2.1.3 fails to enforce authorization on the
sendSms ...)
NOT-FOR-US: yshop-crm
CVE-2026-92418 (A vulnerability was determined in ChangeWeDer crm up to
c07bd4c9714152 ...)
- TODO: check
+ NOT-FOR-US: ChangeWeDer CRM
CVE-2026-92417 (A vulnerability was found in Open5GS up to 2.8.0. This affects
the fun ...)
- open5gs <itp> (bug #1094791)
CVE-2026-92416 (A vulnerability has been found in Open5GS up to 2.8.0.
Affected by thi ...)
@@ -3748,9 +3748,9 @@ CVE-2026-92406 (A vulnerability was detected in
SourceCodester Inventory and Mon
CVE-2026-92405 (A security vulnerability has been detected in SourceCodester
Inventory ...)
NOT-FOR-US: SourceCodester
CVE-2026-92402 (A security flaw has been discovered in ChangeWeDer crm up to
c07bd4c97 ...)
- TODO: check
+ NOT-FOR-US: ChangeWeDer CRM
CVE-2026-92401 (A vulnerability was identified in ChangeWeDer crm up to
c07bd4c9714152 ...)
- TODO: check
+ NOT-FOR-US: ChangeWeDer CRM
CVE-2026-92399 (A vulnerability was determined in GPAC 26.07.0. This affects
the funct ...)
- gpac <removed>
CVE-2026-92398 (A vulnerability was found in Ruijie RG-EW3000GX
EW_3.0(1)B11P380. Affe ...)
@@ -3774,21 +3774,21 @@ CVE-2026-92365 (A vulnerability was found in
vllm-project vllm up to 0.29.0. Aff
CVE-2026-92364 (A vulnerability has been found in itsourcecode Leave
Management System ...)
NOT-FOR-US: itsourcecode System
CVE-2026-92363 (A flaw has been found in ag-ui-protocol ag-ui 1.0. Affected is
an unkn ...)
- TODO: check
+ NOT-FOR-US: ag-ui-protocol ag-ui
CVE-2026-92362 (A vulnerability was detected in ag-ui-protocol ag-ui 1.0. This
impacts ...)
- TODO: check
+ NOT-FOR-US: ag-ui-protocol ag-ui
CVE-2026-92361 (A security vulnerability has been detected in ag-ui-protocol
ag-ui 1.0 ...)
- TODO: check
+ NOT-FOR-US: ag-ui-protocol ag-ui
CVE-2026-92360 (A weakness has been identified in ag-ui-protocol ag-ui 1.0.
The impact ...)
- TODO: check
+ NOT-FOR-US: ag-ui-protocol ag-ui
CVE-2026-92359 (A security flaw has been discovered in ag-ui-protocol ag-ui
0.3.0. The ...)
- TODO: check
+ NOT-FOR-US: ag-ui-protocol ag-ui
CVE-2026-92358 (A flaw was found in the first broker login flow of Keycloak.
When a us ...)
- keycloak <itp> (bug #1088287)
CVE-2026-92357 (A vulnerability was identified in a2ui-project a2ui
0.8/0.9/1.0. Impac ...)
- TODO: check
+ NOT-FOR-US: a2ui-project a2ui
CVE-2026-92356 (A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1.
This is ...)
- TODO: check
+ NOT-FOR-US: a2ui-project a2ui
CVE-2026-92355 (In affected versions of Octopus Server, a user with permission
to modi ...)
NOT-FOR-US: Octopus Deploy
CVE-2026-92299 (@jitsi/electron-sdk before 10.0.5 exposes getDesktopSources()
via cont ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3be8a7eacf3dd938769c014c69e1d199d19b86a9
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3be8a7eacf3dd938769c014c69e1d199d19b86a9
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits