Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
2e6532d8 by Salvatore Bonaccorso at 2026-09-24T10:30:22+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -12,24 +12,24 @@ CVE-2026-97176 (A flaw was found in the Level of
Authentication enforcement mech
CVE-2026-97168
REJECTED
CVE-2026-97155 (Fabasoft Folio Client before 2026, a locally installed
component that ...)
- TODO: check
+ NOT-FOR-US: Fabasoft Folio Client
CVE-2026-97152 (Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a
remotely expl ...)
- nanomsg <unfixed>
NOTE: https://github.com/nanomsg/nanomsg/pull/1130
NOTE: Fixed by:
https://github.com/nanomsg/nanomsg/commit/867c475cca52df0f705420dd7751da4ce5c2adfc
(1.2.3)
NOTE: Fixed by:
https://github.com/nanomsg/nanomsg/commit/6dac4ea9bd0f8cd215925aefd7fdcc62714f67d7
(1.2.3)
CVE-2026-97151 (mammoth (aka mammoth.js) before 1.12.2 is vulnerable to
prototype poll ...)
- TODO: check
+ NOT-FOR-US: mammoth (aka mammoth.js) Node.js module
CVE-2026-97149 (In OpenStack Swift before 2.38.2, the tempurl middleware does
not reje ...)
- swift <unfixed> (bug #1148834)
NOTE: https://launchpad.net/bugs/2166876
NOTE: https://security.openstack.org/ossa/OSSA-2026-041.html
CVE-2026-97056 (SigNoz versions from v0.98.0 up to (but not including)
v0.143.0, when ...)
- TODO: check
+ NOT-FOR-US: SigNoz
CVE-2026-97055 (SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer
signing ...)
- TODO: check
+ NOT-FOR-US: SigNoz
CVE-2026-96898 (A vulnerability was detected in yhx070424 ShopXO up to 2.2.7.
Affected ...)
- TODO: check
+ NOT-FOR-US: yhx070424 ShopXO
CVE-2026-96892 (A flaw has been found in Edimax BR-6428nC 1.16. The impacted
element i ...)
NOT-FOR-US: Edimax
CVE-2026-96891 (A vulnerability was identified in D-Link DIR-825 3.00b32.
Affected is ...)
@@ -41,81 +41,81 @@ CVE-2026-96889 (A flaw was found in librsvg. When
processing an SVG document con
NOTE: https://gitlab.gnome.org/GNOME/librsvg/-/work_items/1241
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/librsvg/-/commit/8a1b0cd319e9af2d1e9cf878081dd77f227a0504
(2.63.1)
CVE-2026-96884 (A security flaw has been discovered in MantisZip up to 0.4.5.
Affected ...)
- TODO: check
+ NOT-FOR-US: MantisZip
CVE-2026-96882 (A vulnerability was identified in TaleLin lin-cms-spring-boot
up to 0. ...)
- TODO: check
+ NOT-FOR-US: TaleLin lin-cms-spring-boot
CVE-2026-96881 (A vulnerability was determined in TaleLin lin-cms-spring-boot
up to 0. ...)
- TODO: check
+ NOT-FOR-US: TaleLin lin-cms-spring-boot
CVE-2026-96880 (A vulnerability was found in TaleLin lin-cms-spring-boot up to
0.2.1. ...)
- TODO: check
+ NOT-FOR-US: TaleLin lin-cms-spring-boot
CVE-2026-96872 (Improper handling of insufficient permissions or privileges
vulnerabil ...)
NOT-FOR-US: MediaWiki extensions/skins not packaged in Debian
CVE-2026-96826 (Improper Neutralization of Special Elements used in an SQL
Command ('S ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-96810 (A vulnerability was identified in huanzi-qch base-admin up to
52816b76 ...)
- TODO: check
+ NOT-FOR-US: huanzi-qch base-admin
CVE-2026-96804 (MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits
the MLFLOW ...)
NOT-FOR-US: mlflow
CVE-2026-96803 (A vulnerability was identified in java110 MicroCommunity up to
2.0. Af ...)
- TODO: check
+ NOT-FOR-US: java110 MicroCommunity
CVE-2026-96777 (A vulnerability was determined in Forma LMS up to 4.1.43. This
impacts ...)
- TODO: check
+ NOT-FOR-US: Forma LMS
CVE-2026-96775 (MLflow's dspy flavor, versions >= 2.0, applies the
MLFLOW_ALLOW_PICKL ...)
NOT-FOR-US: mlflow
CVE-2026-96774 (A vulnerability was found in SPON Communications IP Network
Audio Devi ...)
- TODO: check
+ NOT-FOR-US: SPON Communications IP Network Audio Device
CVE-2026-96773 (A weakness has been identified in Intelliants Subrion CMS up
to 4.2.1. ...)
- TODO: check
+ NOT-FOR-US: Intelliants Subrion CMS
CVE-2026-96772 (A security flaw has been discovered in Intelliants Subrion CMS
up to 4 ...)
- TODO: check
+ NOT-FOR-US: Intelliants Subrion CMS
CVE-2026-96770 (All published s2s-proxy versions through 0.2.2 are affected.
In versio ...)
NOT-FOR-US: Temporal Technologies
CVE-2026-96764 (A weakness has been identified in kvcache-ai mooncake up to
0.3.12/0.3 ...)
- TODO: check
+ NOT-FOR-US: kvcache-ai mooncake
CVE-2026-96763 (A security flaw has been discovered in kvcache-ai mooncake up
to 0.3.1 ...)
- TODO: check
+ NOT-FOR-US: kvcache-ai mooncake
CVE-2026-96762 (A vulnerability was determined in kvcache-ai mooncake up to
0.3.12/0.3 ...)
- TODO: check
+ NOT-FOR-US: kvcache-ai mooncake
CVE-2026-96759 (orval before 8.29.0 fails to escape the operationId parameter
when emi ...)
- TODO: check
+ NOT-FOR-US: Orval
CVE-2026-96758 (orval @orval/core before 8.28.0 contains a code injection
vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: Orval
CVE-2026-96757 (orval before 8.29.0 fails to escape OpenAPI media-type keys
when emitt ...)
- TODO: check
+ NOT-FOR-US: Orval
CVE-2026-96756 (orval versions before 8.30.0 contain a code injection
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: Orval
CVE-2026-96755 (orval versions 8.14.0 through 8.28.1 contain a code injection
vulnerab ...)
- TODO: check
+ NOT-FOR-US: Orval
CVE-2026-96754 (orval versions before 8.29.0 contain a code injection
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: Orval
CVE-2026-96751 (A vulnerability has been found in pmTicket
Project-Management-Software ...)
- TODO: check
+ NOT-FOR-US: pmTicket Project-Management-Software
CVE-2026-96739 (A flaw has been found in SEMCMS up to 4.2. Affected by this
issue is s ...)
- TODO: check
+ NOT-FOR-US: SEMCMS
CVE-2026-96680 (A vulnerability was detected in ByteDance Coze Scraper
Extension up to ...)
- TODO: check
+ NOT-FOR-US: ByteDance Coze Scraper Extension
CVE-2026-96678 (A security vulnerability has been detected in weiqingwen
spring-boot-f ...)
- TODO: check
+ NOT-FOR-US: weiqingwen spring-boot-forum
CVE-2026-96676 (A vulnerability was identified in Fast FAC1900R
20190827_2.0.2. The im ...)
- TODO: check
+ NOT-FOR-US: Fast FAC1900R
CVE-2026-96675 (alsa-lib through 1.2.16.1 contains a denial of service
vulnerability i ...)
TODO: check
CVE-2026-96674 (alsa-lib through 1.2.16.1 computes combined topology element
size usin ...)
TODO: check
CVE-2026-96673 (Photoview through 2.4.0 contains an SQL injection
vulnerability in the ...)
- TODO: check
+ NOT-FOR-US: Photoview
CVE-2026-96672 (Frappe ERPNext versions before 16.34.1 fail to validate that
Financial ...)
- TODO: check
+ NOT-FOR-US: Frappe ERPNext
CVE-2026-96656 (Plex Media Server before 1.43.3.10861 allows an admin user to
write ar ...)
TODO: check
CVE-2026-96655 (Plex Media Server before 1.43.3.10861 allows an authenticated
user to ...)
- TODO: check
+ NOT-FOR-US: Plex Media Server
CVE-2026-96654 (Plex Media Server before 1.43.3.10861 does not correctly
neutralize UR ...)
- TODO: check
+ NOT-FOR-US: Plex Media Server
CVE-2026-96652 (Plex Media Server before 1.43.3.10861 allows SSRF via
'/player/timelin ...)
- TODO: check
+ NOT-FOR-US: Plex Media Server
CVE-2026-96651 (Plex Media Server before 1.43.3.10861 builds a file path from
the url ...)
- TODO: check
+ NOT-FOR-US: Plex Media Server
CVE-2026-96611 (FFmpeg before 9.0 has a signed integer overflow in
libavformat/mov.c. ...)
TODO: check
CVE-2026-96609 (Robur Albatross 1.0.0 through 2.x before 2.7.2 does not limit
use of t ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2e6532d84376849f17478a22c02238588d587311
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2e6532d84376849f17478a22c02238588d587311
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits