Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
5c7e300b by Salvatore Bonaccorso at 2026-09-26T10:05:01+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -15,7 +15,7 @@ CVE-2026-96876 (Improper neutralization of input during web
page generation ('cr
CVE-2026-96875 (Improper neutralization of input during web page generation
('cross-si ...)
TODO: check
CVE-2026-96795 (Horilla is an HR and CRM software. Prior to 2.0.0,
HorillaListView.exp ...)
- TODO: check
+ NOT-FOR-US: Horilla
CVE-2026-96533 (The Testimonials Widget WordPress plugin through 4.0.4 does
not valida ...)
NOT-FOR-US: WordPress plugin
CVE-2026-96532 (The Testimonials Widget WordPress plugin through 4.0.4 does
not perfor ...)
@@ -33,9 +33,9 @@ CVE-2026-92411 (The WP Delicious WordPress plugin before
1.10.8 does not valida
CVE-2026-89237 (The Bluff Post WordPress plugin through 1.1.1 does not
sanitise and es ...)
NOT-FOR-US: WordPress plugin
CVE-2026-88003 (InvoicePlane is a self-hosted open source application for
managing inv ...)
- TODO: check
+ NOT-FOR-US: InvoicePlane
CVE-2026-86066 (Horilla is an HR and CRM software. Prior to 2.0.0,
approve_validate_at ...)
- TODO: check
+ NOT-FOR-US: Horilla
CVE-2026-85081 (The File Manager WordPress plugin before 8.0.5, FileOrganizer
WordPre ...)
NOT-FOR-US: WordPress plugin
CVE-2026-84097 (The wp-review-slider-pro WordPress plugin before 12.7.12 does
not sani ...)
@@ -49,11 +49,11 @@ CVE-2026-7800
CVE-2026-7799
REJECTED
CVE-2026-71483 (Horilla is an HR and CRM software. Prior to 1.6.0, the search
paramete ...)
- TODO: check
+ NOT-FOR-US: Horilla
CVE-2026-63432 (Horilla is an HR and CRM software. From 1.0.0 until 1.6.0 and
2.0.0, t ...)
- TODO: check
+ NOT-FOR-US: Horilla
CVE-2026-63431 (Horilla is an HR and CRM software. In 1.5.0-85 and earlier,
payroll/vi ...)
- TODO: check
+ NOT-FOR-US: Horilla
CVE-2026-5267 (Ciena Navigator Network Control Suite (NCS) contains an
information ex ...)
TODO: check
CVE-2026-57864
@@ -61,7 +61,7 @@ CVE-2026-57864
CVE-2026-57861
REJECTED
CVE-2026-57449 (Actual is a local-first personal finance tool. Prior to
26.7.0, Actual ...)
- TODO: check
+ NOT-FOR-US: Actual
CVE-2026-57443 (SCBE-AETHERMOORE is a geometric AI governance and evaluation
framework ...)
TODO: check
CVE-2026-53990
@@ -463,7 +463,7 @@ CVE-2026-95699 (Prior to 9/18/2026, the iSteamX mobile
application's AWS policy
CVE-2026-94573 (The Repeater Fields for Elementor Forms plugin for WordPress
is vulner ...)
NOT-FOR-US: WordPress plugin
CVE-2026-94445 (A malicious txtar could escape the intended execution context
and forc ...)
- TODO: check
+ NOT-FOR-US: golang.org/x/playground
CVE-2026-94376 (The Better Messages \u2013 Chat Rooms, Group Chat, Private
Messages & ...)
NOT-FOR-US: WordPress plugin
CVE-2026-93901 (The Optima Express IDX plugin for WordPress is vulnerable to
Privilege ...)
@@ -512,7 +512,7 @@ CVE-2026-93306 (IBM Server Firmware FW1120.00 through
FW1120.01, FW1110.00 throu
CVE-2026-93303 (The HT Contact Form \u2013 Drag & Drop Form Builder for
WordPress plug ...)
NOT-FOR-US: WordPress plugin
CVE-2026-93291 (Omni C20 lacks proper certificate validation which could allow
an atta ...)
- TODO: check
+ NOT-FOR-US: Omni C20
CVE-2026-93290 (Omni C20 uses hard-coded credentials that could allow an
attacker to m ...)
NOT-FOR-US: Omni C20
CVE-2026-93289 (The affected products are vulnerable to command injection
attack that ...)
@@ -573,7 +573,7 @@ CVE-2026-87721 (Uncontrolled Resource Consumption (CWE-400
/ CWE-407) in the ANT
CVE-2026-87720 (Incorrect Authorization (CWE-863) in project name
normalization (Proje ...)
TODO: check
CVE-2026-87118 (The Botslab G980H dash camera firmware contains an out of
bounds write ...)
- TODO: check
+ NOT-FOR-US: Botslab G980H dash camera firmware
CVE-2026-86837 (The Bookly WordPress plugin before 28.3 does not properly
verify a cus ...)
NOT-FOR-US: WordPress plugin
CVE-2026-85750 (Piwigo before v16.4.0 is vulnerable to arbitrary file read and
remote ...)
@@ -585,19 +585,19 @@ CVE-2026-85496 (The Botslab G980H dash camera firmware
generates session identif
CVE-2026-85417 (Incomplete property masking in the SANnav logging subsystem
permits SN ...)
NOT-FOR-US: Brocade
CVE-2026-85293 (InvoicePlane is a self-hosted open source application for
managing inv ...)
- TODO: check
+ NOT-FOR-US: Botslab G980H dash camera firmware
CVE-2026-85292 (InvoicePlane is a self-hosted open source application for
managing inv ...)
- TODO: check
+ NOT-FOR-US: InvoicePlane
CVE-2026-85291 (InvoicePlane is a self-hosted open source application for
managing inv ...)
- TODO: check
+ NOT-FOR-US: InvoicePlane
CVE-2026-85290 (InvoicePlane is a self-hosted open source application for
managing inv ...)
- TODO: check
+ NOT-FOR-US: InvoicePlane
CVE-2026-85289 (InvoicePlane is a self-hosted open source application for
managing inv ...)
- TODO: check
+ NOT-FOR-US: InvoicePlane
CVE-2026-85274 (InvoicePlane is a self-hosted open source application for
managing inv ...)
- TODO: check
+ NOT-FOR-US: InvoicePlane
CVE-2026-85082 (Root Browser Classic 3.3.0 passes the path of a selected
SQLite databa ...)
- TODO: check
+ NOT-FOR-US: Root Browser Classic
CVE-2026-85029 (IBM Guardium Data Protection 12.2 could allow a remote
attacker to obt ...)
NOT-FOR-US: IBM
CVE-2026-84893 (IBM Guardium Data Protection 12.2 is vulnerable to SQL
injection in th ...)
@@ -623,11 +623,11 @@ CVE-2026-84460 (Zammad is a web based open source
helpdesk/customer support syst
CVE-2026-84458 (Zammad is a web based open source helpdesk/customer support
system. Pr ...)
- zammad <itp> (bug #841355)
CVE-2026-84403 (The Botslab G980H dash camera firmware does not require
authenticated ...)
- TODO: check
+ NOT-FOR-US: Botslab G980H dash camera firmware
CVE-2026-84399 (The Botslab G980H dash camera firmware contains an
authorization vulne ...)
- TODO: check
+ NOT-FOR-US: Botslab G980H dash camera firmware
CVE-2026-84283 (Secure Folder 1.2 stores files selected for its
password-protected vau ...)
- TODO: check
+ NOT-FOR-US: Secure Folder
CVE-2026-84281 (The Fancy Product Designer plugin for WordPress is vulnerable
to Store ...)
NOT-FOR-US: WordPress plugin
CVE-2026-84280 (The Fancy Product Designer plugin for WordPress is vulnerable
to Store ...)
@@ -637,19 +637,19 @@ CVE-2026-84279 (The Fancy Product Designer plugin for
WordPress is vulnerable to
CVE-2026-83591 (The AMP for WP \u2013 Accelerated Mobile Pages plugin for
WordPress is ...)
NOT-FOR-US: WordPress plugin
CVE-2026-82716 (The Botslab G980H dash camera firmware includes sensitive
configuratio ...)
- TODO: check
+ NOT-FOR-US: Botslab G980H dash camera firmware
CVE-2026-82708 (The Botslab G980H dash camera firmware contains a path
traversal vulne ...)
- TODO: check
+ NOT-FOR-US: Botslab G980H dash camera firmware
CVE-2026-82585 (The Botslab G980H dash camera firmware transmits sensitive
information ...)
- TODO: check
+ NOT-FOR-US: Botslab G980H dash camera firmware
CVE-2026-82566 (The Botslab G980H dash camera firmware contains a session
management v ...)
- TODO: check
+ NOT-FOR-US: Botslab G980H dash camera firmware
CVE-2026-82372 (Improper handling of sensitive data during IPsec policy
creation and m ...)
NOT-FOR-US: Brocade
CVE-2026-82164 (Dell Trusted Device Client, versions prior to 8.1.359.0,
contain an In ...)
NOT-FOR-US: Dell / EMC
CVE-2026-81630 (The Botslab G980H dash camera firmware does not adequately
verify the ...)
- TODO: check
+ NOT-FOR-US: Botslab G980H dash camera firmware
CVE-2026-80514 (The wpForo Forum WordPress plugin from 3.0.0 before 3.1.6 does
not ver ...)
NOT-FOR-US: WordPress plugin
CVE-2026-80432 (Missing Authorization in the drop handling path of the drag
and drop p ...)
@@ -659,11 +659,11 @@ CVE-2026-80431 (Out-of-bounds Write in the natural width
branch of the text sizi
CVE-2026-80430 (Improper Link Resolution Before File Access in the drag source
staging ...)
TODO: check
CVE-2026-79959 (The Botslab G980H dash camera firmware contains a hard-coded
root acco ...)
- TODO: check
+ NOT-FOR-US: Botslab G980H dash camera firmware
CVE-2026-79153 (Seclore FileSecure Desktop Client before 3.25.1.0 contains
improper ac ...)
- TODO: check
+ NOT-FOR-US: Seclore FileSecure Desktop Client
CVE-2026-78902 (Cross Site Scripting vulnerability in Netgate pfSense
26.03.1-RELEASE ...)
- TODO: check
+ NOT-FOR-US: Netgate pfSense
CVE-2026-78397 (The Link Library WordPress plugin before 7.9.6 does not
validate the d ...)
NOT-FOR-US: WordPress plugin
CVE-2026-78394 (The Link Library WordPress plugin before 7.9.6 does not
sanitize a use ...)
@@ -671,25 +671,25 @@ CVE-2026-78394 (The Link Library WordPress plugin before
7.9.6 does not sanitize
CVE-2026-78393 (The Link Library WordPress plugin before 7.9.6 does not
properly escap ...)
NOT-FOR-US: WordPress plugin
CVE-2026-77967 (The Botslab G980H dash camera firmware accepts a reusable
authenticati ...)
- TODO: check
+ NOT-FOR-US: Botslab G980H dash camera firmware
CVE-2026-75558 (The Botslab G980H dash camera firmware uses a hard-coded
cryptographic ...)
- TODO: check
+ NOT-FOR-US: Botslab G980H dash camera firmware
CVE-2026-75553 (Smartphone application Tohoku Electric Power "Yorisou e Net"
uses a ha ...)
- TODO: check
+ NOT-FOR-US: Smartphone application Tohoku Electric Power "Yorisou e Net"
CVE-2026-6088 (Stored Cross-Site Scripting (XSS) vulnerability in StockAgile
API and ...)
- TODO: check
+ NOT-FOR-US: StockAgile
CVE-2026-6087 (Stored Cross-Site Scripting (XSS) vulnerability in StockAgile
API and ...)
- TODO: check
+ NOT-FOR-US: StockAgile
CVE-2026-6086 (Stored Cross-Site Scripting (XSS) vulnerability in StockAgile
API and ...)
- TODO: check
+ NOT-FOR-US: StockAgile
CVE-2026-6085 (Stored Cross-Site Scripting (XSS) vulnerability in StockAgile
API and ...)
- TODO: check
+ NOT-FOR-US: StockAgile
CVE-2026-6084 (Stored Cross-Site Scripting (XSS) vulnerability in StockAgile
API and ...)
- TODO: check
+ NOT-FOR-US: StockAgile
CVE-2026-6083 (Stored Cross-Site Scripting (XSS) vulnerability in StockAgile
API and ...)
- TODO: check
+ NOT-FOR-US: StockAgile
CVE-2026-6082 (Stored Cross-Site Scripting (XSS) vulnerability in StockAgile
API and ...)
- TODO: check
+ NOT-FOR-US: StockAgile
CVE-2026-67421 (RabbitMQ is a messaging and streaming broker. From 3.13.0
until 3.13.1 ...)
- rabbitmq-server <unfixed>
NOTE:
https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-6256-27fm-4rgr
@@ -2776,7 +2776,7 @@ CVE-2026-6544 (IBM Concert 1.0.0 through 3.0.0 allows
recursive copying of direc
CVE-2026-67233 (RabbitMQ is a messaging and streaming broker. Prior to
versions 3.13.1 ...)
TODO: check
CVE-2026-65827 (Docmost is open-source collaborative wiki and documentation
software. ...)
- TODO: check
+ NOT-FOR-US: Docmost
CVE-2026-65422 (A flaw in the authorization mechanism for Media Gateway API in
Genetec ...)
NOT-FOR-US: Genetec
CVE-2026-63645 (OpenObserve is a cloud-native observability platform. Prior to
0.90.3, ...)
@@ -2788,35 +2788,35 @@ CVE-2026-63498 (Snipe-IT is an IT asset/license
management system. Prior to 8.7.
CVE-2026-63493 (Snipe-IT is an IT asset/license management system. Prior to
8.7.0, a p ...)
- snipe-it <itp> (bug #1005172)
CVE-2026-63203 (Logto is the modern, open-source auth infrastructure for SaaS
and AI a ...)
- TODO: check
+ NOT-FOR-US: Logto
CVE-2026-62368 (Snipe-IT is an IT asset/license management system. Prior to
8.7.0, a u ...)
- snipe-it <itp> (bug #1005172)
CVE-2026-62286 (Dozzle is a realtime log viewer for docker containers. Prior
to 10.6.7 ...)
- TODO: check
+ NOT-FOR-US: Dozzle
CVE-2026-61825 (code16 Sharp is a Laravel-based framework for building
content-managem ...)
- TODO: check
+ NOT-FOR-US: code16 Sharp
CVE-2026-61823 (code16 Sharp is a Laravel-based framework for building
content-managem ...)
- TODO: check
+ NOT-FOR-US: code16 Sharp
CVE-2026-61816 (zbateson/mail-mime-parser is a mail mime parser alternative to
PHP's i ...)
- TODO: check
+ NOT-FOR-US: zbateson/mail-mime-parser
CVE-2026-61815 (zbateson/mail-mime-parser is a mail mime parser alternative to
PHP's i ...)
- TODO: check
+ NOT-FOR-US: zbateson/mail-mime-parser
CVE-2026-61811 (Wazuh is an open-source security platform providing unified
XDR and SI ...)
NOT-FOR-US: Wazuh
CVE-2026-61788 (DBHub is a database MCP server for Postgres, MySQL, SQL
Server, Oracle ...)
- TODO: check
+ NOT-FOR-US: DBHub
CVE-2026-61784 (xhtml-purifier is a Node.js library to take in
raw/unknown/untrusted H ...)
- TODO: check
+ NOT-FOR-US: xhtml-purifier Node.js module
CVE-2026-61782 (Rsdoctor is a build analyzer tailored for projects built with
Rspack. ...)
- TODO: check
+ NOT-FOR-US: Rsdoctor
CVE-2026-61742 (DBHub is a database MCP server for Postgres, MySQL, SQL
Server, Oracle ...)
- TODO: check
+ NOT-FOR-US: DBHub
CVE-2026-61741 (http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]`
instances ...)
- TODO: check
+ NOT-FOR-US: http4s-scala-xml
CVE-2026-61732 (Decepticon is an autonomous hacking agent for red teams.
Versions prio ...)
- TODO: check
+ NOT-FOR-US: Decepticon
CVE-2026-61604 (The ixo Blockchain is a Layer 1 blockchain that runs on both
Testnet a ...)
- TODO: check
+ NOT-FOR-US: ixo Blockchain
CVE-2026-58008 (Stack-based buffer overflow vulnerability in Altera Trusted
Firmware o ...)
NOT-FOR-US: Altera
CVE-2026-58007 (Untrusted pointer dereference vulnerability in Altera Trusted
Firmware ...)
@@ -2830,7 +2830,7 @@ CVE-2026-58004 (Out-of-bounds read vulnerability in
Altera Trusted Firmware on H
CVE-2026-57590 (A missing authorization vulnerability exists in the Task Group
APIs of ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-57440 (The EmbedVideo Extension is a MediaWiki extension which adds a
parser ...)
- TODO: check
+ NOT-FOR-US: SCBE-AETHERMOORE
CVE-2026-57179 (Python Social Auth is a social authentication/registration
mechanism. ...)
TODO: check
CVE-2026-57178 (Python Social Auth is a social authentication/registration
mechanism. ...)
@@ -4629,25 +4629,32 @@ CVE-2026-63000 (REDAXO is a PHP-based content
management system. Prior to 5.21.2
CVE-2026-62998 (REDAXO is a PHP-based content management system. Prior to
5.21.2, rex_ ...)
NOT-FOR-US: REDAXO
CVE-2026-61834 (scim-patch is a library for applying SCIM patch operations.
Prior to 0 ...)
- TODO: check
+ NOT-FOR-US: scim-patch
CVE-2026-61814 (Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's
AsyncParser ...)
- TODO: check
+ - jawn <unfixed>
+ NOTE:
https://github.com/typelevel/jawn/security/advisories/GHSA-w4cm-gvhj-cgw6
+ NOTE: Fixed by:
https://github.com/typelevel/jawn/commit/cddcd5e3387c356b05953f7b2af103d309687e4b
(v1.7.0)
CVE-2026-61695 (Wire provides gRPC and protocol buffers for Android, Kotlin,
Swift, an ...)
- TODO: check
+ NOT-FOR-US: Wire
CVE-2026-61413 (Dell Secure Connect Gateway (SCG) Policy Manager, versions
prior to 5. ...)
NOT-FOR-US: Dell / EMC
CVE-2026-5696 (Reflected Cross-Site Scripting (XSS) in Microweber. The
vulnerability ...)
- TODO: check
+ NOT-FOR-US: Microweber. CMS
CVE-2026-5695 (Arbitrary file upload vulnerability due to a lack of proper
validation ...)
- TODO: check
+ NOT-FOR-US: Microweber. CMS
CVE-2026-59990 (Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse
methods ...)
- TODO: check
+ - jawn <unfixed>
+ NOTE:
https://github.com/typelevel/jawn/security/advisories/GHSA-cc4v-rvgp-2pf3
+ NOTE: Fixed by:
https://github.com/typelevel/jawn/commit/191cb3a44e77f1afab439ee636bf66bdf3c54a04
(v1.7.0)
+ NOTE: Fixed by:
https://github.com/typelevel/jawn/commit/6219666641f9408498f85868f835e17bd8a72fed
(v1.7.0)
+ NOTE: Fxied by:
https://github.com/typelevel/jawn/commit/93ac93e9c992c11b4c03d5455d8551f9fb24da1b
(v1.7.0)
+ NOTE: Fixed by:
https://github.com/typelevel/jawn/commit/f6ace7e0db715de1a8c4618bed9378333a5c2214
(v1.7.0)
CVE-2026-59980 (hpack is an HTTP/2 Header Encoding for Python. Prior to
version 4.2.0, ...)
- python-hpack <unfixed> (bug #1148944)
NOTE:
https://github.com/python-hyper/hpack/security/advisories/GHSA-8v8h-hg4w-mvq2
NOTE:
https://github.com/python-hyper/hpack/commit/8cfb02c547740e16dbfe7aba77bad84b297cec2c
(v4.2.0)
CVE-2026-59167 (SunEditor is a lightweight and powerful WYSIWYG editor in
vanilla Java ...)
- TODO: check
+ NOT-FOR-US: SunEditor
CVE-2026-57854
REJECTED
CVE-2026-57168
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5c7e300b150a3b2c04c69500aaed91a59209565f
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5c7e300b150a3b2c04c69500aaed91a59209565f
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits