Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
efa46235 by Salvatore Bonaccorso at 2026-09-21T20:18:12+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -11116,27 +11116,27 @@ CVE-2026-55244 (ASTEVAL is an evaluator of Python
expressions and statements. Pr
NOTE: Fixed by:
https://github.com/lmfit/asteval/commit/9c625b3674f8d05f206708bb85afca17a87694a4
(1.0.9)
NOTE: Fixed by:
https://github.com/lmfit/asteval/commit/c49c99a67acb63eb7410231932250bd820380e45
(1.0.9)
CVE-2026-55209 (resdata is software for reading and writing result files from
the Ecli ...)
- TODO: check
+ NOT-FOR-US: resdata
CVE-2026-55093 (Tract is a tiny, no-nonsense, self-contained TensorFlow and
ONNX infer ...)
- TODO: check
+ NOT-FOR-US: Tract
CVE-2026-54632 (SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET.
Prior t ...)
- TODO: check
+ NOT-FOR-US: SIPSorcery
CVE-2026-54629 (Anyquery is an SQL query engine built on top of SQLite. Prior
to 0.4.5 ...)
- TODO: check
+ NOT-FOR-US: Anyquery
CVE-2026-54628 (Anyquery is an SQL query engine built on top of SQLite. Prior
to 0.4.5 ...)
- TODO: check
+ NOT-FOR-US: Anyquery
CVE-2026-54559 (PocketSphinx is a small speech recognizer. Prior to 5.1.1, the
trie la ...)
- TODO: check
+ NOT-FOR-US: PocketSphinx
CVE-2026-54447 (garminconnect is a Python 3 API wrapper for Garmin Connect
that retrie ...)
- TODO: check
+ NOT-FOR-US: garminconnect
CVE-2026-54334 (UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware
structur ...)
NOT-FOR-US: uefi-firmware-parser
CVE-2026-54333 (UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware
structur ...)
NOT-FOR-US: uefi-firmware-parser
CVE-2026-54247 (Skipper is an HTTP router and reverse proxy for service
composition. P ...)
- TODO: check
+ NOT-FOR-US: Zalando Skipper
CVE-2026-54246 (Skipper is an HTTP router and reverse proxy for service
composition. P ...)
- TODO: check
+ NOT-FOR-US: Zalando Skipper
CVE-2026-53719 (Envoy Gateway is an open source project for managing Envoy
Proxy as a ...)
- envoyproxy <itp> (bug #987544)
CVE-2026-53718 (Envoy Gateway is an open source project for managing Envoy
Proxy as a ...)
@@ -11854,9 +11854,9 @@ CVE-2026-55236 (langgraph-api implements the LangGraph
API for rapid development
CVE-2026-55235 (langgraph-api implements the LangGraph API for rapid
development and t ...)
NOT-FOR-US: langgraph-api
CVE-2026-55102 (hashi-vault-js is a Node.js module for interacting with the
HashiCorp ...)
- TODO: check
+ NOT-FOR-US: hashi-vault-js Node.js module
CVE-2026-55091 (flat-to-nested converts a hierarchy from a flat representation
to a ne ...)
- TODO: check
+ NOT-FOR-US: flat-to-nested
CVE-2026-55073 (WeasyPrint helps web developers to create PDF documents. Prior
to 70.0 ...)
- weasyprint <unfixed> (bug #1148178)
[trixie] - weasyprint <no-dsa> (Minor issue)
@@ -11865,15 +11865,15 @@ CVE-2026-55073 (WeasyPrint helps web developers to
create PDF documents. Prior t
CVE-2026-55072 (Pimcore is an Open Source Data & Experience Management
Platform. Prior ...)
NOT-FOR-US: Pimcore
CVE-2026-54723 (devpi is a Python package index staging server and packaging,
testing, ...)
- TODO: check
+ NOT-FOR-US: devpi
CVE-2026-54567 (Flask-Reuploaded provides file uploads for Flask. From 1.5.0
until 1.6 ...)
- TODO: check
+ NOT-FOR-US: Flask-Reuploaded
CVE-2026-54542 (Nimiq is a Rust implementation of the Nimiq Proof-of-Stake
protocol ba ...)
- TODO: check
+ NOT-FOR-US: Nimiq
CVE-2026-54541 (Nimiq is a Rust implementation of the Nimiq Proof-of-Stake
protocol ba ...)
- TODO: check
+ NOT-FOR-US: Nimiq
CVE-2026-54529 (SQLAdmin is a flexible Admin interface for SQLAlchemy models.
Prior to ...)
- TODO: check
+ NOT-FOR-US: SQLAdmin
CVE-2026-54452 (safeurl is a server-side request forgery protection library.
Prior to ...)
TODO: check
CVE-2026-54182 (backpack/crud provides Create, Read, Update & Delete (CRUD)
functions ...)
@@ -11891,13 +11891,13 @@ CVE-2026-54176 (backpack/crud provides Create, Read,
Update & Delete (CRUD) func
CVE-2026-54175 (backpack/crud provides Create, Read, Update & Delete (CRUD)
functions ...)
NOT-FOR-US: backpack/crud
CVE-2026-54156 (node-opcua is an OPC UA implementation for TypeScript and
Node.js. Pri ...)
- TODO: check
+ NOT-FOR-US: node-opcua/node-opcua
CVE-2026-54155 (node-opcua is an OPC UA implementation for TypeScript and
Node.js. Pri ...)
- TODO: check
+ NOT-FOR-US: node-opcua/node-opcua
CVE-2026-54150 (next-video is a library for adding video to Next.js
applications. Prio ...)
NOT-FOR-US: Next.js
CVE-2026-54087 (EasyAdmin is a fast and modern admin generator for Symfony
application ...)
- TODO: check
+ NOT-FOR-US: EasyAdminEasyAdmin
CVE-2026-53752 (docx4j is an open source Java library for creating, editing,
and savin ...)
TODO: check
CVE-2026-53708 (ContextForge is an AI gateway, registry, and proxy that
provides centr ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/efa462356a94707b8f6b87efdadecd1cf777d5ff
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/efa462356a94707b8f6b87efdadecd1cf777d5ff
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits