Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
ca447bb5 by Salvatore Bonaccorso at 2026-09-26T21:58:59+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -58,15 +58,15 @@ CVE-2026-100709 (Froxlor through 2.3.10 stores only a 
numeric user ID in remembe
 CVE-2026-100708 (Froxlor before 2.3.13 returns the ssl_key_file column \u2014 
which sto ...)
        - froxlor <itp> (bug #581792)
 CVE-2026-100707 (Kyverno before 1.19.1 contains a namespace isolation bypass 
in the api ...)
-       TODO: check
+       NOT-FOR-US: Kyverno
 CVE-2026-100706 (kyverno before 1.19.1 fails to properly validate URL-encoded 
path segm ...)
-       TODO: check
+       NOT-FOR-US: Kyverno
 CVE-2026-100705 (Kyverno before 1.19.1 is vulnerable to server-side request 
forgery. Th ...)
-       TODO: check
+       NOT-FOR-US: Kyverno
 CVE-2026-100704 (Kyverno is a policy engine for Kubernetes. In versions 1.14.0 
through  ...)
-       TODO: check
+       NOT-FOR-US: Kyverno
 CVE-2026-100703 (Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib 
CEL libr ...)
-       TODO: check
+       NOT-FOR-US: Kyverno
 CVE-2026-100702 (Nodemailer before 10.0.2 fails to properly flatten deeply 
nested array ...)
        TODO: check
 CVE-2026-100701 (Nodemailer versions 5.0.0 through 10.0.1 use a process-global 
DNS cach ...)
@@ -96,49 +96,49 @@ CVE-2026-100690 (Hugo versions from v0.161.0 through 
v0.165.0 run Node.js tools
 CVE-2026-100689 (GitPython before 3.1.62 does not validate the `path` field 
read from a ...)
        TODO: check
 CVE-2026-100688 (Budibase server before 3.45.0 contains a cross-tenant 
information disc ...)
-       TODO: check
+       NOT-FOR-US: Budibase
 CVE-2026-100687 (Budibase Server before 3.45.0 fails to redact plaintext 
datasource cre ...)
-       TODO: check
+       NOT-FOR-US: Budibase
 CVE-2026-100686 (Budibase versions before 3.45.0 fail to validate per-app 
authorization ...)
-       TODO: check
+       NOT-FOR-US: Budibase
 CVE-2026-100685 (Budibase before 3.45.0 fails to properly scope the GET 
/api/chat-links ...)
-       TODO: check
+       NOT-FOR-US: Budibase
 CVE-2026-100684 (Budibase versions 3.41.0 before 3.45.0 contain an 
authentication bypas ...)
-       TODO: check
+       NOT-FOR-US: Budibase
 CVE-2026-100683 (Budibase (@budibase/server) before 3.45.0 builds MySQL and 
MSSQL colum ...)
-       TODO: check
+       NOT-FOR-US: Budibase
 CVE-2026-100682 (Budibase Server before 3.45.0 contains an arbitrary file 
write vulnera ...)
-       TODO: check
+       NOT-FOR-US: Budibase
 CVE-2026-100681 (Budibase before 3.45.0 contains an unauthenticated 
server-side request ...)
-       TODO: check
+       NOT-FOR-US: Budibase
 CVE-2026-100680 (Budibase versions before 3.45.0 fail to disable external JSON 
referenc ...)
-       TODO: check
+       NOT-FOR-US: Budibase
 CVE-2026-100679 (stoatchat before 0.15.5 fails to validate that MFA tickets 
belong to t ...)
-       TODO: check
+       NOT-FOR-US: stoatchat
 CVE-2026-100678 (stoatchat before 0.15.5 fails to enforce account-level 
attempt limits  ...)
-       TODO: check
+       NOT-FOR-US: stoatchat
 CVE-2026-100677 (stoatchat before 0.15.5 contains an account enumeration 
vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: stoatchat
 CVE-2026-100676 (January, the media proxy/embed service of stoatchat 
(stoatchat/stoatch ...)
-       TODO: check
+       NOT-FOR-US: stoatchat
 CVE-2026-100675 (stoatchat versions before 0.15.5 contain a denial of service 
vulnerabi ...)
-       TODO: check
+       NOT-FOR-US: stoatchat
 CVE-2026-100674 (stoatchat before 0.15.5 fails to revalidate usernames after 
Unicode sa ...)
-       TODO: check
+       NOT-FOR-US: stoatchat
 CVE-2026-100673 (The Grav Data Manager plugin 
(getgrav/grav-plugin-datamanager) version ...)
-       TODO: check
+       NOT-FOR-US: Grav Data Manager plugin
 CVE-2026-100672 (The Comments plugin (getgrav/grav-plugin-comments) for Grav 
CMS throug ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS plugin
 CVE-2026-100671 (Grav is a flat-file CMS. In versions 2.0.19 through 2.0.24 
\u2014 and  ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS
 CVE-2026-100670 (Grav CMS 2.0.14 through 2.0.24 contains a privilege 
escalation vulnera ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS
 CVE-2026-100669 (Grav before 2.0.25 ships web server configuration samples 
whose access ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS
 CVE-2026-100668 (Grav 2.0.0 through 2.0.24 contain a Twig content sandbox 
escape. The ` ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS
 CVE-2026-100667 (grav-plugin-login (the Grav CMS Login plugin) versions >= 
3.8.7 and <  ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS plugin
 CVE-2026-100666 (Netty's HttpServerCodec (io.netty:netty-codec-http) in 
versions 4.2.0. ...)
        TODO: check
 CVE-2026-100665 (Netty versions from 4.2.11.Final before 4.2.18.Final contain 
an incomp ...)
@@ -351,7 +351,7 @@ CVE-2026-63432 (Horilla is an HR and CRM software. From 
1.0.0 until 1.6.0 and 2.
 CVE-2026-63431 (Horilla is an HR and CRM software. In 1.5.0-85 and earlier, 
payroll/vi ...)
        NOT-FOR-US: Horilla
 CVE-2026-5267 (Ciena Navigator Network Control Suite (NCS) contains an 
information ex ...)
-       TODO: check
+       NOT-FOR-US: Ciena Navigator Network Control Suite (NCS)
 CVE-2026-57864
        REJECTED
 CVE-2026-57861
@@ -359,7 +359,7 @@ CVE-2026-57861
 CVE-2026-57449 (Actual is a local-first personal finance tool. Prior to 
26.7.0, Actual ...)
        NOT-FOR-US: Actual
 CVE-2026-57443 (SCBE-AETHERMOORE is a geometric AI governance and evaluation 
framework ...)
-       TODO: check
+       NOT-FOR-US: SCBE-AETHERMOORE
 CVE-2026-53990
        REJECTED
 CVE-2026-53973
@@ -399,7 +399,7 @@ CVE-2026-15273 (The Automatic.css plugin for WordPress is 
vulnerable to Stored C
 CVE-2026-11871 (The Team Members  WordPress plugin through 9.2 does not 
perform any au ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-10758 (Esri LERC is an open-source image or raster format which 
supports rapi ...)
-       TODO: check
+       NOT-FOR-US: Esri LERC
 CVE-2026-100599 (OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the 
configur ...)
        NOT-FOR-US: OpenClaw
 CVE-2026-100598 (OpenClaw (npm package openclaw) before 2026.7.1 incorrectly 
binds Sign ...)
@@ -880,7 +880,7 @@ CVE-2026-85750 (Piwigo before v16.4.0 is vulnerable to 
arbitrary file read and r
 CVE-2026-85542 (IBM Guardium Data Protection 12.2 is affected by a command 
injection v ...)
        NOT-FOR-US: IBM
 CVE-2026-85496 (The Botslab G980H dash camera firmware generates session 
identifiers u ...)
-       TODO: check
+       NOT-FOR-US: Botslab G980H dash camera firmware
 CVE-2026-85417 (Incomplete property masking in the SANnav logging subsystem 
permits SN ...)
        NOT-FOR-US: Brocade
 CVE-2026-85293 (InvoicePlane is a self-hosted open source application for 
managing inv ...)
@@ -1165,7 +1165,7 @@ CVE-2026-55217 (GLPI is a free asset and IT management 
software package. From 0.
 CVE-2026-55214 (GLPI is a free asset and IT management software package. From 
11.0.6 u ...)
        - glpi <removed>
 CVE-2026-54790 (InvoicePlane is a self-hosted open source application for 
managing inv ...)
-       TODO: check
+       NOT-FOR-US: InvoicePlane
 CVE-2026-53629 (GLPI is a free asset and IT management software package. From 
9.4.0 un ...)
        - glpi <removed>
 CVE-2026-53628 (GLPI is a free asset and IT management software package. From 
0.84 unt ...)
@@ -1181,27 +1181,27 @@ CVE-2026-53610 (GLPI is a free asset and IT management 
software package. From 11
 CVE-2026-53493 (containerd is an open-source container runtime. Prior to 
versions 1.7. ...)
        TODO: check
 CVE-2026-52622 (An issue in Wellav Technologies Co., Ltd Wellav WES Emergency 
Broadcas ...)
-       TODO: check
+       NOT-FOR-US: Wellav
 CVE-2026-51773 (An issue in the VMware datastore driver of OpenStack 
glance_store. Whe ...)
        TODO: check
 CVE-2026-51772 (A Server-Side Request Forgery (SSRF) vulnerability exists in 
the Image ...)
        TODO: check
 CVE-2026-50547 (InvoicePlane is a self-hosted open source application for 
managing inv ...)
-       TODO: check
+       NOT-FOR-US: InvoicePlane
 CVE-2026-49850 (InvoicePlane is a self-hosted open source application for 
managing inv ...)
-       TODO: check
+       NOT-FOR-US: InvoicePlane
 CVE-2026-49470 (GLPI is a free asset and IT management software package. From 
11.0.0 u ...)
        - glpi <removed>
 CVE-2026-49469 (GLPI is a free asset and IT management software package. From 
0.70 unt ...)
        - glpi <removed>
 CVE-2026-48543 (Krayin CRM through 2.2.6 contains a stored client-side 
template inject ...)
-       TODO: check
+       NOT-FOR-US: Krayin CRM
 CVE-2026-48542 (Krayin CRM through 2.2.6 contains a stored client-side 
template inject ...)
-       TODO: check
+       NOT-FOR-US: Krayin CRM
 CVE-2026-48541 (Krayin CRM through 2.2.6 contains a stored client-side 
template inject ...)
-       TODO: check
+       NOT-FOR-US: Krayin CRM
 CVE-2026-48540 (Krayin CRM through 2.2.6 contains a stored client-side 
template inject ...)
-       TODO: check
+       NOT-FOR-US: Krayin CRM
 CVE-2026-48482 (GLPI is a free asset and IT management software package. From 
11.0.0 u ...)
        - glpi <removed>
 CVE-2026-47679 (GLPI is a free asset and IT management software package. From 
10.0.0 u ...)
@@ -1217,23 +1217,23 @@ CVE-2026-42323 (Piwigo is a full featured open source 
photo gallery application
 CVE-2026-42322 (Piwigo is a full featured open source photo gallery 
application for th ...)
        - piwigo <removed>
 CVE-2026-39372 (InvoicePlane is a self-hosted open source application for 
managing inv ...)
-       TODO: check
+       NOT-FOR-US: InvoicePlane
 CVE-2026-39353 (InvoicePlane is a self-hosted open source application for 
managing inv ...)
-       TODO: check
+       NOT-FOR-US: InvoicePlane
 CVE-2026-33639 (InvoicePlane is a self-hosted open source application for 
managing inv ...)
-       TODO: check
+       NOT-FOR-US: InvoicePlane
 CVE-2026-27867 (An attacker with access via network to the Regesta Smart 
HD-PLC of the ...)
-       TODO: check
+       NOT-FOR-US: Regesta Smart HD-PLC TLDPH16D2
 CVE-2026-19804 (The s2Member \u2013 Excellent for All Kinds of Memberships, 
Content Re ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-19775 (The OpenStation \u2014 Desktop Windows, Dock & Virtual 
Desktops for WP ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-18320 (Readwise Reader for Android uses a sanitize-html configuration 
that pe ...)
-       TODO: check
+       NOT-FOR-US: Readwise Reader for Android
 CVE-2026-18312 (Readwise Reader for Android constructs URLs in its WebView 
using attac ...)
-       TODO: check
+       NOT-FOR-US: Readwise Reader for Android
 CVE-2026-18311 (Readwise Reader for Android contains a cross-site scripting 
vulnerabil ...)
-       TODO: check
+       NOT-FOR-US: Readwise Reader for Android
 CVE-2026-17602 (The SSL Zen \u2014 SSL Certificate Installer & HTTPS Redirects 
plugin  ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-17577 (The SSL Zen plugin for WordPress is vulnerable to Reflected 
Cross-Site ...)
@@ -3181,9 +3181,9 @@ CVE-2026-57175 (Python Social Auth is a social 
authentication/registration mecha
 CVE-2026-56792 (Dell Rugged Control Center (RCC), versions prior to 5.2.206, 
contain a ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-56744 (`@bsv/wallet-toolbox` provides BRC-100 wallet signing and 
storage comp ...)
-       TODO: check
+       NOT-FOR-US: bsv-blockchain/wallet-toolbox
 CVE-2026-56739 (Logto is the modern, open-source auth infrastructure for SaaS 
and AI a ...)
-       TODO: check
+       NOT-FOR-US: Logto
 CVE-2026-56738 (phpMyFAQ is an open source FAQ web application. The 
`StopWords::add()` ...)
        NOT-FOR-US: phpMyFAQ
 CVE-2026-56737 (phpMyFAQ is an open source FAQ web application. Versions 3.2.0 
through ...)
@@ -4999,9 +4999,9 @@ CVE-2026-57854
 CVE-2026-57168
        REJECTED
 CVE-2026-55632 (GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, 
the int ...)
-       TODO: check
+       NOT-FOR-US: GoCD
 CVE-2026-55610 (InvoiceShelf is an open-source web & mobile app that helps 
track expen ...)
-       TODO: check
+       NOT-FOR-US: InvoiceShelf
 CVE-2026-55456
        REJECTED
 CVE-2026-53979
@@ -5013,7 +5013,7 @@ CVE-2026-53969
 CVE-2026-53968
        REJECTED
 CVE-2026-52744 (GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, 
the int ...)
-       TODO: check
+       NOT-FOR-US: GoCD
 CVE-2026-50228 (An unauthenticated local attacker can connect to the Electron 
DevTools ...)
        NOT-FOR-US: Acer
 CVE-2026-50227 (An unauthenticated local attacker can connect to the MQTT 
broker over  ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ca447bb5e9f840c2cd81e681e3e3b99f49131f6d

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ca447bb5e9f840c2cd81e681e3e3b99f49131f6d
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to