Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
cb8c765c by Salvatore Bonaccorso at 2026-09-25T21:59:26+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -47,69 +47,69 @@ CVE-2026-97764 (django-allauth before 65.19.4 does not have 
the expected limits
        NOTE: Fixed by: 
https://codeberg.org/allauth/django-allauth/commit/4379e7931fe7572aacc4f3b4b5f2298d5f3ecc96
 (65.19.4)
        NOTE: Fixed by: 
https://codeberg.org/allauth/django-allauth/commit/4e252aa2be7cef5d72d78049d6fb07cb27a89c83
 (65.19.4)
 CVE-2026-97737 (In Wakapi before 2.17.6, the user caching service allows a 
lookup to b ...)
-       TODO: check
+       NOT-FOR-US: Wakapi
 CVE-2026-97736 (tinyauth before 5.1.3 allows rule bypass by appending an 
allowed route ...)
-       TODO: check
+       NOT-FOR-US: Tinyauth
 CVE-2026-97735 (ITFlow before 26.08 allows SVG attachments in the ticket email 
parser  ...)
-       TODO: check
+       NOT-FOR-US: ITFlow
 CVE-2026-97732 (IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver 
that au ...)
-       TODO: check
+       NOT-FOR-US: IRONMACE Ironshield
 CVE-2026-97731 (MinIO through 7aac2a2 does not verify that every x-amz-* 
header presen ...)
        TODO: check
 CVE-2026-97730 (In Netgate pfSense Plus before 26.07 and pfSense CE before 
2.9.0, a Lo ...)
-       TODO: check
+       NOT-FOR-US: Netgate pfSense Plus
 CVE-2026-97724 (A prototype pollution vulnerability in Software Mansion React 
Native W ...)
-       TODO: check
+       NOT-FOR-US: Software Mansion React Native Worklets
 CVE-2026-97723 (madpsy ka9q_ubersdr before 0.1.58 has a stored cross-site 
scripting (X ...)
-       TODO: check
+       NOT-FOR-US: madpsy ka9q_ubersdr
 CVE-2026-97721 (A weakness has been identified in Sanluan PublicCMS up to 
6.202506.e.  ...)
-       TODO: check
+       NOT-FOR-US: Sanluan PublicCMS
 CVE-2026-97650 (A vulnerability has been found in ningzichun 
student-management-system ...)
-       TODO: check
+       NOT-FOR-US: ningzichun student-management-system
 CVE-2026-97649 (A flaw has been found in ningzichun student-management-system 
up to 98 ...)
-       TODO: check
+       NOT-FOR-US: ningzichun student-management-system
 CVE-2026-97648 (A vulnerability was detected in ningzichun 
student-management-system u ...)
-       TODO: check
+       NOT-FOR-US: ningzichun student-management-system
 CVE-2026-97647 (A security vulnerability has been detected in ningzichun 
student-manag ...)
-       TODO: check
+       NOT-FOR-US: ningzichun student-management-system
 CVE-2026-97646 (A weakness has been identified in ningzichun 
student-management-system ...)
-       TODO: check
+       NOT-FOR-US: ningzichun student-management-system
 CVE-2026-97636 (Apache Airflow HashiCorp provider: the HashiCorp Vault secrets 
backend ...)
-       TODO: check
+       NOT-FOR-US: Apache Airflow HashiCorp provider
 CVE-2026-97622
        REJECTED
 CVE-2026-97469 (PostgreSQL Anonymizer contains a vulnerability that allows 
unprivilege ...)
-       TODO: check
+       NOT-FOR-US: PostgreSQL Anonymizer
 CVE-2026-97387
        REJECTED
 CVE-2026-97368 (A weakness has been identified in chillzhuang SpringBlade up 
to 5.0.2. ...)
-       TODO: check
+       NOT-FOR-US: chillzhuang SpringBlade
 CVE-2026-97366 (A security flaw has been discovered in jhen0409 
react-native-debugger  ...)
-       TODO: check
+       NOT-FOR-US: jhen0409 react-native-debugger
 CVE-2026-97365 (A vulnerability was determined in chonkie-inc littrs 
0.6.1/0.6.2. Impa ...)
-       TODO: check
+       NOT-FOR-US: chonkie-inc littrs
 CVE-2026-97326 (A weakness has been identified in songxinjianqwe Chat up to 
ac63d25297 ...)
-       TODO: check
+       NOT-FOR-US: songxinjianqwe Chat
 CVE-2026-97325 (A security flaw has been discovered in YunaiV/zhijiantianya 
ruoyi-vue- ...)
-       TODO: check
+       NOT-FOR-US: YunaiV/zhijiantianya ruoyi-vue-pro
 CVE-2026-97324 (A vulnerability was identified in YunaiV/zhijiantianya 
ruoyi-vue-pro u ...)
-       TODO: check
+       NOT-FOR-US: YunaiV/zhijiantianya ruoyi-vue-pro
 CVE-2026-97228 (Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer 
from a Grap ...)
-       TODO: check
+       NOT-FOR-US: Rapid7 Bulk Export MCP
 CVE-2026-97222 (A heap use-after-free flaw was found in Gnumeric. When a user 
opens a  ...)
        TODO: check
 CVE-2026-97064 (X-SpringBoot through 6.0 ships with a hardcoded static master 
login ve ...)
-       TODO: check
+       NOT-FOR-US: X-SpringBoot
 CVE-2026-97063 (X-SpringBoot through 6.0 returns login verification codes in 
HTTP resp ...)
-       TODO: check
+       NOT-FOR-US: X-SpringBoot
 CVE-2026-97060 (X-SpringBoot through 6.0 lacks object-level authorization in 
user mana ...)
-       TODO: check
+       NOT-FOR-US: X-SpringBoot
 CVE-2026-96883 (pgcollection is an open source extension to PostgreSQL. A type 
confusi ...)
        NOT-FOR-US: Amazon
 CVE-2026-96874 (Improper neutralization of input during web page generation 
('cross-si ...)
-       TODO: check
+       NOT-FOR-US: X-SpringBoot
 CVE-2026-96812 (Improper Exposure of Resource to Wrong Sphere in the host file 
helper  ...)
-       TODO: check
+       NOT-FOR-US: Google gVisor
 CVE-2026-96766 (The GeoDirectory \u2013 WP Business Directory Plugin and 
Classified Li ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-96752 (The Zero Spam for WordPress plugin for WordPress is vulnerable 
to Stor ...)
@@ -131,7 +131,7 @@ CVE-2026-95834 (Use After Free in the drag source path of 
the drag and drop prot
 CVE-2026-95832 (Improper Neutralization of Special Elements in Output Used by 
a Downst ...)
        TODO: check
 CVE-2026-95699 (Prior to 9/18/2026, the iSteamX mobile application's AWS 
policy could  ...)
-       TODO: check
+       NOT-FOR-US: iSteamX mobile application
 CVE-2026-94573 (The Repeater Fields for Elementor Forms plugin for WordPress 
is vulner ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-94445 (A malicious txtar could escape the intended execution context 
and forc ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb8c765c91d27e0d45ae8dc40f36131feaa020c1

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb8c765c91d27e0d45ae8dc40f36131feaa020c1
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to