Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
8d4b559e by Salvatore Bonaccorso at 2026-09-22T08:28:32+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -9948,7 +9948,7 @@ CVE-2026-19641 (On affected platforms running Arista EOS
with password authentic
CVE-2026-19515 (The WSO2 Integrator MI VS Code extension fails to properly
sanitize or ...)
NOT-FOR-US: WSO2
CVE-2026-19504 (Fabric.js loadFromJSON Server-Side Request Forgery
Vulnerability. This ...)
- TODO: check
+ NOT-FOR-US: Fabric.js
CVE-2026-19407 (Bucket Squatting in Google Cloud Gemini Enterprise Agent
Platform SDK ...)
NOT-FOR-US: Google Cloud Gemini Enterprise Agent Platform SDK
CVE-2026-18115 (Concrete CMS 9.2.0 to 9.5.2 did not enforce per-field
edit_user_proper ...)
@@ -11951,7 +11951,7 @@ CVE-2026-54541 (Nimiq is a Rust implementation of the
Nimiq Proof-of-Stake proto
CVE-2026-54529 (SQLAdmin is a flexible Admin interface for SQLAlchemy models.
Prior to ...)
NOT-FOR-US: SQLAdmin
CVE-2026-54452 (safeurl is a server-side request forgery protection library.
Prior to ...)
- TODO: check
+ NOT-FOR-US: Doyensec safeurl
CVE-2026-54182 (backpack/crud provides Create, Read, Update & Delete (CRUD)
functions ...)
NOT-FOR-US: backpack/crud
CVE-2026-54181 (backpack/crud provides Create, Read, Update & Delete (CRUD)
functions ...)
@@ -11975,13 +11975,13 @@ CVE-2026-54150 (next-video is a library for adding
video to Next.js applications
CVE-2026-54087 (EasyAdmin is a fast and modern admin generator for Symfony
application ...)
NOT-FOR-US: EasyAdminEasyAdmin
CVE-2026-53752 (docx4j is an open source Java library for creating, editing,
and savin ...)
- TODO: check
+ NOT-FOR-US: docx4j
CVE-2026-53708 (ContextForge is an AI gateway, registry, and proxy that
provides centr ...)
NOT-FOR-US: ContextForge
CVE-2026-53659 (http4k is a functional toolkit for Kotlin HTTP applications.
Prior to ...)
NOT-FOR-US: http4k
CVE-2026-53496 (ExifReader is a JavaScript Exif information parser. Prior to
4.40.1, E ...)
- TODO: check
+ NOT-FOR-US: ExifReader
CVE-2026-53495 (containerd is an open-source container runtime. Prior to
1.7.35, 2.0.1 ...)
- containerd <unfixed> (bug #1148180)
NOTE:
https://github.com/containerd/containerd/security/advisories/GHSA-7jxh-36q5-gcqv
@@ -629708,7 +629708,7 @@ CVE-2021-3032 (An information exposure through log
file vulnerability exists in
CVE-2021-3031 (Padding bytes in Ethernet packets on PA-200, PA-220, PA-500,
PA-800, P ...)
NOT-FOR-US: Palo Alto Networks
CVE-2021-3030 (Cute Editor for ASP.NET 6.4 is vulnerable to reflected
cross-site scri ...)
- TODO: check
+ NOT-FOR-US: Cute Editor for ASP.NET
CVE-2021-23234
RESERVED
CVE-2021-23135 (Exposure of System Data to an Unauthorized Control Sphere
vulnerabilit ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8d4b559e1d4795a54dc7d65b11ddc86ab2486303
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8d4b559e1d4795a54dc7d65b11ddc86ab2486303
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits