Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
cb8c765c by Salvatore Bonaccorso at 2026-09-25T21:59:26+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -47,69 +47,69 @@ CVE-2026-97764 (django-allauth before 65.19.4 does not have
the expected limits
NOTE: Fixed by:
https://codeberg.org/allauth/django-allauth/commit/4379e7931fe7572aacc4f3b4b5f2298d5f3ecc96
(65.19.4)
NOTE: Fixed by:
https://codeberg.org/allauth/django-allauth/commit/4e252aa2be7cef5d72d78049d6fb07cb27a89c83
(65.19.4)
CVE-2026-97737 (In Wakapi before 2.17.6, the user caching service allows a
lookup to b ...)
- TODO: check
+ NOT-FOR-US: Wakapi
CVE-2026-97736 (tinyauth before 5.1.3 allows rule bypass by appending an
allowed route ...)
- TODO: check
+ NOT-FOR-US: Tinyauth
CVE-2026-97735 (ITFlow before 26.08 allows SVG attachments in the ticket email
parser ...)
- TODO: check
+ NOT-FOR-US: ITFlow
CVE-2026-97732 (IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver
that au ...)
- TODO: check
+ NOT-FOR-US: IRONMACE Ironshield
CVE-2026-97731 (MinIO through 7aac2a2 does not verify that every x-amz-*
header presen ...)
TODO: check
CVE-2026-97730 (In Netgate pfSense Plus before 26.07 and pfSense CE before
2.9.0, a Lo ...)
- TODO: check
+ NOT-FOR-US: Netgate pfSense Plus
CVE-2026-97724 (A prototype pollution vulnerability in Software Mansion React
Native W ...)
- TODO: check
+ NOT-FOR-US: Software Mansion React Native Worklets
CVE-2026-97723 (madpsy ka9q_ubersdr before 0.1.58 has a stored cross-site
scripting (X ...)
- TODO: check
+ NOT-FOR-US: madpsy ka9q_ubersdr
CVE-2026-97721 (A weakness has been identified in Sanluan PublicCMS up to
6.202506.e. ...)
- TODO: check
+ NOT-FOR-US: Sanluan PublicCMS
CVE-2026-97650 (A vulnerability has been found in ningzichun
student-management-system ...)
- TODO: check
+ NOT-FOR-US: ningzichun student-management-system
CVE-2026-97649 (A flaw has been found in ningzichun student-management-system
up to 98 ...)
- TODO: check
+ NOT-FOR-US: ningzichun student-management-system
CVE-2026-97648 (A vulnerability was detected in ningzichun
student-management-system u ...)
- TODO: check
+ NOT-FOR-US: ningzichun student-management-system
CVE-2026-97647 (A security vulnerability has been detected in ningzichun
student-manag ...)
- TODO: check
+ NOT-FOR-US: ningzichun student-management-system
CVE-2026-97646 (A weakness has been identified in ningzichun
student-management-system ...)
- TODO: check
+ NOT-FOR-US: ningzichun student-management-system
CVE-2026-97636 (Apache Airflow HashiCorp provider: the HashiCorp Vault secrets
backend ...)
- TODO: check
+ NOT-FOR-US: Apache Airflow HashiCorp provider
CVE-2026-97622
REJECTED
CVE-2026-97469 (PostgreSQL Anonymizer contains a vulnerability that allows
unprivilege ...)
- TODO: check
+ NOT-FOR-US: PostgreSQL Anonymizer
CVE-2026-97387
REJECTED
CVE-2026-97368 (A weakness has been identified in chillzhuang SpringBlade up
to 5.0.2. ...)
- TODO: check
+ NOT-FOR-US: chillzhuang SpringBlade
CVE-2026-97366 (A security flaw has been discovered in jhen0409
react-native-debugger ...)
- TODO: check
+ NOT-FOR-US: jhen0409 react-native-debugger
CVE-2026-97365 (A vulnerability was determined in chonkie-inc littrs
0.6.1/0.6.2. Impa ...)
- TODO: check
+ NOT-FOR-US: chonkie-inc littrs
CVE-2026-97326 (A weakness has been identified in songxinjianqwe Chat up to
ac63d25297 ...)
- TODO: check
+ NOT-FOR-US: songxinjianqwe Chat
CVE-2026-97325 (A security flaw has been discovered in YunaiV/zhijiantianya
ruoyi-vue- ...)
- TODO: check
+ NOT-FOR-US: YunaiV/zhijiantianya ruoyi-vue-pro
CVE-2026-97324 (A vulnerability was identified in YunaiV/zhijiantianya
ruoyi-vue-pro u ...)
- TODO: check
+ NOT-FOR-US: YunaiV/zhijiantianya ruoyi-vue-pro
CVE-2026-97228 (Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer
from a Grap ...)
- TODO: check
+ NOT-FOR-US: Rapid7 Bulk Export MCP
CVE-2026-97222 (A heap use-after-free flaw was found in Gnumeric. When a user
opens a ...)
TODO: check
CVE-2026-97064 (X-SpringBoot through 6.0 ships with a hardcoded static master
login ve ...)
- TODO: check
+ NOT-FOR-US: X-SpringBoot
CVE-2026-97063 (X-SpringBoot through 6.0 returns login verification codes in
HTTP resp ...)
- TODO: check
+ NOT-FOR-US: X-SpringBoot
CVE-2026-97060 (X-SpringBoot through 6.0 lacks object-level authorization in
user mana ...)
- TODO: check
+ NOT-FOR-US: X-SpringBoot
CVE-2026-96883 (pgcollection is an open source extension to PostgreSQL. A type
confusi ...)
NOT-FOR-US: Amazon
CVE-2026-96874 (Improper neutralization of input during web page generation
('cross-si ...)
- TODO: check
+ NOT-FOR-US: X-SpringBoot
CVE-2026-96812 (Improper Exposure of Resource to Wrong Sphere in the host file
helper ...)
- TODO: check
+ NOT-FOR-US: Google gVisor
CVE-2026-96766 (The GeoDirectory \u2013 WP Business Directory Plugin and
Classified Li ...)
NOT-FOR-US: WordPress plugin
CVE-2026-96752 (The Zero Spam for WordPress plugin for WordPress is vulnerable
to Stor ...)
@@ -131,7 +131,7 @@ CVE-2026-95834 (Use After Free in the drag source path of
the drag and drop prot
CVE-2026-95832 (Improper Neutralization of Special Elements in Output Used by
a Downst ...)
TODO: check
CVE-2026-95699 (Prior to 9/18/2026, the iSteamX mobile application's AWS
policy could ...)
- TODO: check
+ NOT-FOR-US: iSteamX mobile application
CVE-2026-94573 (The Repeater Fields for Elementor Forms plugin for WordPress
is vulner ...)
NOT-FOR-US: WordPress plugin
CVE-2026-94445 (A malicious txtar could escape the intended execution context
and forc ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb8c765c91d27e0d45ae8dc40f36131feaa020c1
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb8c765c91d27e0d45ae8dc40f36131feaa020c1
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits