Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
2e6532d8 by Salvatore Bonaccorso at 2026-09-24T10:30:22+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -12,24 +12,24 @@ CVE-2026-97176 (A flaw was found in the Level of 
Authentication enforcement mech
 CVE-2026-97168
        REJECTED
 CVE-2026-97155 (Fabasoft Folio Client before 2026, a locally installed 
component that  ...)
-       TODO: check
+       NOT-FOR-US: Fabasoft Folio Client
 CVE-2026-97152 (Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a 
remotely expl ...)
        - nanomsg <unfixed>
        NOTE: https://github.com/nanomsg/nanomsg/pull/1130
        NOTE: Fixed by: 
https://github.com/nanomsg/nanomsg/commit/867c475cca52df0f705420dd7751da4ce5c2adfc
 (1.2.3)
        NOTE: Fixed by: 
https://github.com/nanomsg/nanomsg/commit/6dac4ea9bd0f8cd215925aefd7fdcc62714f67d7
 (1.2.3)
 CVE-2026-97151 (mammoth (aka mammoth.js) before 1.12.2 is vulnerable to 
prototype poll ...)
-       TODO: check
+       NOT-FOR-US: mammoth (aka mammoth.js) Node.js module
 CVE-2026-97149 (In OpenStack Swift before 2.38.2, the tempurl middleware does 
not reje ...)
        - swift <unfixed> (bug #1148834)
        NOTE: https://launchpad.net/bugs/2166876
        NOTE: https://security.openstack.org/ossa/OSSA-2026-041.html
 CVE-2026-97056 (SigNoz versions from v0.98.0 up to (but not including) 
v0.143.0, when  ...)
-       TODO: check
+       NOT-FOR-US: SigNoz
 CVE-2026-97055 (SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer 
signing  ...)
-       TODO: check
+       NOT-FOR-US: SigNoz
 CVE-2026-96898 (A vulnerability was detected in yhx070424 ShopXO up to 2.2.7. 
Affected ...)
-       TODO: check
+       NOT-FOR-US: yhx070424 ShopXO
 CVE-2026-96892 (A flaw has been found in Edimax BR-6428nC 1.16. The impacted 
element i ...)
        NOT-FOR-US: Edimax
 CVE-2026-96891 (A vulnerability was identified in D-Link DIR-825 3.00b32. 
Affected is  ...)
@@ -41,81 +41,81 @@ CVE-2026-96889 (A flaw was found in librsvg. When 
processing an SVG document con
        NOTE: https://gitlab.gnome.org/GNOME/librsvg/-/work_items/1241
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/librsvg/-/commit/8a1b0cd319e9af2d1e9cf878081dd77f227a0504
 (2.63.1)
 CVE-2026-96884 (A security flaw has been discovered in MantisZip up to 0.4.5. 
Affected ...)
-       TODO: check
+       NOT-FOR-US: MantisZip
 CVE-2026-96882 (A vulnerability was identified in TaleLin lin-cms-spring-boot 
up to 0. ...)
-       TODO: check
+       NOT-FOR-US: TaleLin lin-cms-spring-boot
 CVE-2026-96881 (A vulnerability was determined in TaleLin lin-cms-spring-boot 
up to 0. ...)
-       TODO: check
+       NOT-FOR-US: TaleLin lin-cms-spring-boot
 CVE-2026-96880 (A vulnerability was found in TaleLin lin-cms-spring-boot up to 
0.2.1.  ...)
-       TODO: check
+       NOT-FOR-US: TaleLin lin-cms-spring-boot
 CVE-2026-96872 (Improper handling of insufficient permissions or privileges 
vulnerabil ...)
        NOT-FOR-US: MediaWiki extensions/skins not packaged in Debian
 CVE-2026-96826 (Improper Neutralization of Special Elements used in an SQL 
Command ('S ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-96810 (A vulnerability was identified in huanzi-qch base-admin up to 
52816b76 ...)
-       TODO: check
+       NOT-FOR-US: huanzi-qch base-admin
 CVE-2026-96804 (MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits 
the MLFLOW ...)
        NOT-FOR-US: mlflow
 CVE-2026-96803 (A vulnerability was identified in java110 MicroCommunity up to 
2.0. Af ...)
-       TODO: check
+       NOT-FOR-US: java110 MicroCommunity
 CVE-2026-96777 (A vulnerability was determined in Forma LMS up to 4.1.43. This 
impacts ...)
-       TODO: check
+       NOT-FOR-US: Forma LMS
 CVE-2026-96775 (MLflow's dspy flavor, versions >= 2.0,  applies the 
MLFLOW_ALLOW_PICKL ...)
        NOT-FOR-US: mlflow
 CVE-2026-96774 (A vulnerability was found in SPON Communications IP Network 
Audio Devi ...)
-       TODO: check
+       NOT-FOR-US: SPON Communications IP Network Audio Device
 CVE-2026-96773 (A weakness has been identified in Intelliants Subrion CMS up 
to 4.2.1. ...)
-       TODO: check
+       NOT-FOR-US: Intelliants Subrion CMS
 CVE-2026-96772 (A security flaw has been discovered in Intelliants Subrion CMS 
up to 4 ...)
-       TODO: check
+       NOT-FOR-US: Intelliants Subrion CMS
 CVE-2026-96770 (All published s2s-proxy versions through 0.2.2 are affected. 
In versio ...)
        NOT-FOR-US: Temporal Technologies
 CVE-2026-96764 (A weakness has been identified in kvcache-ai mooncake up to 
0.3.12/0.3 ...)
-       TODO: check
+       NOT-FOR-US: kvcache-ai mooncake
 CVE-2026-96763 (A security flaw has been discovered in kvcache-ai mooncake up 
to 0.3.1 ...)
-       TODO: check
+       NOT-FOR-US: kvcache-ai mooncake
 CVE-2026-96762 (A vulnerability was determined in kvcache-ai mooncake up to 
0.3.12/0.3 ...)
-       TODO: check
+       NOT-FOR-US: kvcache-ai mooncake
 CVE-2026-96759 (orval before 8.29.0 fails to escape the operationId parameter 
when emi ...)
-       TODO: check
+       NOT-FOR-US: Orval
 CVE-2026-96758 (orval @orval/core before 8.28.0 contains a code injection 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: Orval
 CVE-2026-96757 (orval before 8.29.0 fails to escape OpenAPI media-type keys 
when emitt ...)
-       TODO: check
+       NOT-FOR-US: Orval
 CVE-2026-96756 (orval versions before 8.30.0 contain a code injection 
vulnerability in ...)
-       TODO: check
+       NOT-FOR-US: Orval
 CVE-2026-96755 (orval versions 8.14.0 through 8.28.1 contain a code injection 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: Orval
 CVE-2026-96754 (orval versions before 8.29.0 contain a code injection 
vulnerability in ...)
-       TODO: check
+       NOT-FOR-US: Orval
 CVE-2026-96751 (A vulnerability has been found in pmTicket 
Project-Management-Software ...)
-       TODO: check
+       NOT-FOR-US: pmTicket Project-Management-Software
 CVE-2026-96739 (A flaw has been found in SEMCMS up to 4.2. Affected by this 
issue is s ...)
-       TODO: check
+       NOT-FOR-US: SEMCMS
 CVE-2026-96680 (A vulnerability was detected in ByteDance Coze Scraper 
Extension up to ...)
-       TODO: check
+       NOT-FOR-US: ByteDance Coze Scraper Extension
 CVE-2026-96678 (A security vulnerability has been detected in weiqingwen 
spring-boot-f ...)
-       TODO: check
+       NOT-FOR-US: weiqingwen spring-boot-forum
 CVE-2026-96676 (A vulnerability was identified in Fast FAC1900R 
20190827_2.0.2. The im ...)
-       TODO: check
+       NOT-FOR-US: Fast FAC1900R
 CVE-2026-96675 (alsa-lib through 1.2.16.1 contains a denial of service 
vulnerability i ...)
        TODO: check
 CVE-2026-96674 (alsa-lib through 1.2.16.1 computes combined topology element 
size usin ...)
        TODO: check
 CVE-2026-96673 (Photoview through 2.4.0 contains an SQL injection 
vulnerability in the ...)
-       TODO: check
+       NOT-FOR-US: Photoview
 CVE-2026-96672 (Frappe ERPNext versions before 16.34.1 fail to validate that 
Financial ...)
-       TODO: check
+       NOT-FOR-US: Frappe ERPNext
 CVE-2026-96656 (Plex Media Server before 1.43.3.10861 allows an admin user to 
write ar ...)
        TODO: check
 CVE-2026-96655 (Plex Media Server before 1.43.3.10861 allows an authenticated 
user to  ...)
-       TODO: check
+       NOT-FOR-US: Plex Media Server
 CVE-2026-96654 (Plex Media Server before 1.43.3.10861 does not correctly 
neutralize UR ...)
-       TODO: check
+       NOT-FOR-US: Plex Media Server
 CVE-2026-96652 (Plex Media Server before 1.43.3.10861 allows SSRF via 
'/player/timelin ...)
-       TODO: check
+       NOT-FOR-US: Plex Media Server
 CVE-2026-96651 (Plex Media Server before 1.43.3.10861 builds a file path from 
the url  ...)
-       TODO: check
+       NOT-FOR-US: Plex Media Server
 CVE-2026-96611 (FFmpeg before 9.0 has a signed integer overflow in 
libavformat/mov.c.  ...)
        TODO: check
 CVE-2026-96609 (Robur Albatross 1.0.0 through 2.x before 2.7.2 does not limit 
use of t ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2e6532d84376849f17478a22c02238588d587311

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2e6532d84376849f17478a22c02238588d587311
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to