Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
e5121407 by Salvatore Bonaccorso at 2026-09-25T08:58:52+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -194,15 +194,15 @@ CVE-2026-93541 (An out-of-bounds read in libXi's
XQueryDeviceState() in libXi be
- libxi <unfixed>
NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
CVE-2026-93425 (Dokploy is a free, self-hostable Platform as a Service (PaaS).
Prior t ...)
- TODO: check
+ NOT-FOR-US: Dokploy
CVE-2026-93405 (Mailspring is a fast, cross-platform, open-source email
client. Prior ...)
- TODO: check
+ NOT-FOR-US: Mailspring
CVE-2026-92905 (ZohoCorp ManageEngine EventLog Analyzer and Log360 before
build 13071 ...)
NOT-FOR-US: Zoho
CVE-2026-92680 (Araxis Merge for Windows version 2011.4074 through 2026.0
stores user- ...)
NOT-FOR-US: Araxis Merge
CVE-2026-91187 (Improper Verification of Cryptographic Signature vulnerability
in dash ...)
- TODO: check
+ NOT-FOR-US: dashbit nimble_zta
CVE-2026-91161 (OpenWA is a free, open source, self-hosted WhatsApp API
gateway. Prior ...)
NOT-FOR-US: OpenWA
CVE-2026-91160 (OpenWA is a free, open source, self-hosted WhatsApp API
gateway. Prior ...)
@@ -224,11 +224,11 @@ CVE-2026-91120 (Discourse is an open-source discussion
platform. Prior to 2026.1
CVE-2026-91119 (Discourse is an open-source discussion platform. Prior to
2026.1.8, 20 ...)
NOT-FOR-US: Discourse
CVE-2026-90959 (A path traversal vulnerability was found in pulpcore. The
content uplo ...)
- TODO: check
+ NOT-FOR-US: pulpcore
CVE-2026-90481 (In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise
Edition ...)
NOT-FOR-US: PortSwigger Burp Suite
CVE-2026-89325 (An uncontrolled search path element in InsightVM assessment
content in ...)
- TODO: check
+ NOT-FOR-US: Rapid7 Insight Agent
CVE-2026-88916 (Incorrect Authorization vulnerability in T\xdcB\u0130TAK
ULAKB\u0130M ...)
NOT-FOR-US: ULAKBIM UlakPDF
CVE-2026-88907 (Incorrect Authorization vulnerability in T\xdcB\u0130TAK
ULAKB\u0130M ...)
@@ -1667,13 +1667,13 @@ CVE-2026-93526 (Unauthenticated Cross Site Scripting
(XSS) in Event Tickets <= 5
CVE-2026-93513 (Contributor Insecure Direct Object References (IDOR) in
SiteSkite <= 2 ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-93421 (Mesop is a Python-based UI framework that allows users to
build web ap ...)
- TODO: check
+ NOT-FOR-US: Mesop
CVE-2026-93368 (The Rename wp-login.php to anything you want plugin for
WordPress is v ...)
NOT-FOR-US: WordPress plugin
CVE-2026-93352 (Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete
patch for C ...)
NOT-FOR-US: Laravel-Mediable
CVE-2026-93349 (Frictionless through 5.20.0rc1 contains an OS command
injection vulner ...)
- TODO: check
+ NOT-FOR-US: Frictionless
CVE-2026-92874 (GitLab has remediated an issue in GitLab CE/EE affecting all
versions ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as
src:gitlab, but never in a stable release)
CVE-2026-92730 (LimeSurvey Community Edition 7.0.14 contains a reflected
cross-site sc ...)
@@ -1682,7 +1682,7 @@ CVE-2026-92700 (Caddy is an extensible server platform
that uses TLS by default.
- caddy <undetermined>
TODO: check references, refers to GHSA-j8px-rmrx-76h9 which is for
CVE-2026-77281
CVE-2026-92692 (Sulu is an open-source PHP content management system based on
the Symf ...)
- TODO: check
+ NOT-FOR-US: Sulu
CVE-2026-92628 (GitLab has remediated an issue in GitLab CE/EE affecting all
versions ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as
src:gitlab, but never in a stable release)
CVE-2026-92530 (GitLab has remediated an issue in GitLab CE/EE affecting all
versions ...)
@@ -1692,14 +1692,14 @@ CVE-2026-92529 (GitLab has remediated an issue in
GitLab EE affecting all versio
CVE-2026-92470 (GitLab has remediated an issue in GitLab EE affecting all
versions fro ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as
src:gitlab, but never in a stable release)
CVE-2026-92419 (WEBCON BPS is vulnerable to Insecure Direct Object Reference
(IDOR) in ...)
- TODO: check
+ NOT-FOR-US: WEBCON BPS
CVE-2026-92378 (A session management vulnerability exists in the Legacy UI
Reduced Fun ...)
NOT-FOR-US: Canon
CVE-2026-92284 (Caddy is an extensible server platform that uses TLS by
default. In ve ...)
- caddy <undetermined>
TODO: check references, refers to GHSA-j8px-rmrx-76h9 which is for
CVE-2026-77281
CVE-2026-92164 (Streamlink is a CLI utility which pipes video streams from
various ser ...)
- TODO: check
+ NOT-FOR-US: Streamlink
CVE-2026-92001 (Improper restriction of recursive entity references in DTDs
('XML enti ...)
TODO: check
CVE-2026-91999 (Improper neutralization of input during web page generation
('cross-si ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e5121407a17bb92e7696a18342f7f94508229ca4
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e5121407a17bb92e7696a18342f7f94508229ca4
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits