Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
ca447bb5 by Salvatore Bonaccorso at 2026-09-26T21:58:59+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -58,15 +58,15 @@ CVE-2026-100709 (Froxlor through 2.3.10 stores only a
numeric user ID in remembe
CVE-2026-100708 (Froxlor before 2.3.13 returns the ssl_key_file column \u2014
which sto ...)
- froxlor <itp> (bug #581792)
CVE-2026-100707 (Kyverno before 1.19.1 contains a namespace isolation bypass
in the api ...)
- TODO: check
+ NOT-FOR-US: Kyverno
CVE-2026-100706 (kyverno before 1.19.1 fails to properly validate URL-encoded
path segm ...)
- TODO: check
+ NOT-FOR-US: Kyverno
CVE-2026-100705 (Kyverno before 1.19.1 is vulnerable to server-side request
forgery. Th ...)
- TODO: check
+ NOT-FOR-US: Kyverno
CVE-2026-100704 (Kyverno is a policy engine for Kubernetes. In versions 1.14.0
through ...)
- TODO: check
+ NOT-FOR-US: Kyverno
CVE-2026-100703 (Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib
CEL libr ...)
- TODO: check
+ NOT-FOR-US: Kyverno
CVE-2026-100702 (Nodemailer before 10.0.2 fails to properly flatten deeply
nested array ...)
TODO: check
CVE-2026-100701 (Nodemailer versions 5.0.0 through 10.0.1 use a process-global
DNS cach ...)
@@ -96,49 +96,49 @@ CVE-2026-100690 (Hugo versions from v0.161.0 through
v0.165.0 run Node.js tools
CVE-2026-100689 (GitPython before 3.1.62 does not validate the `path` field
read from a ...)
TODO: check
CVE-2026-100688 (Budibase server before 3.45.0 contains a cross-tenant
information disc ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-100687 (Budibase Server before 3.45.0 fails to redact plaintext
datasource cre ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-100686 (Budibase versions before 3.45.0 fail to validate per-app
authorization ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-100685 (Budibase before 3.45.0 fails to properly scope the GET
/api/chat-links ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-100684 (Budibase versions 3.41.0 before 3.45.0 contain an
authentication bypas ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-100683 (Budibase (@budibase/server) before 3.45.0 builds MySQL and
MSSQL colum ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-100682 (Budibase Server before 3.45.0 contains an arbitrary file
write vulnera ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-100681 (Budibase before 3.45.0 contains an unauthenticated
server-side request ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-100680 (Budibase versions before 3.45.0 fail to disable external JSON
referenc ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-100679 (stoatchat before 0.15.5 fails to validate that MFA tickets
belong to t ...)
- TODO: check
+ NOT-FOR-US: stoatchat
CVE-2026-100678 (stoatchat before 0.15.5 fails to enforce account-level
attempt limits ...)
- TODO: check
+ NOT-FOR-US: stoatchat
CVE-2026-100677 (stoatchat before 0.15.5 contains an account enumeration
vulnerability ...)
- TODO: check
+ NOT-FOR-US: stoatchat
CVE-2026-100676 (January, the media proxy/embed service of stoatchat
(stoatchat/stoatch ...)
- TODO: check
+ NOT-FOR-US: stoatchat
CVE-2026-100675 (stoatchat versions before 0.15.5 contain a denial of service
vulnerabi ...)
- TODO: check
+ NOT-FOR-US: stoatchat
CVE-2026-100674 (stoatchat before 0.15.5 fails to revalidate usernames after
Unicode sa ...)
- TODO: check
+ NOT-FOR-US: stoatchat
CVE-2026-100673 (The Grav Data Manager plugin
(getgrav/grav-plugin-datamanager) version ...)
- TODO: check
+ NOT-FOR-US: Grav Data Manager plugin
CVE-2026-100672 (The Comments plugin (getgrav/grav-plugin-comments) for Grav
CMS throug ...)
- TODO: check
+ NOT-FOR-US: Grav CMS plugin
CVE-2026-100671 (Grav is a flat-file CMS. In versions 2.0.19 through 2.0.24
\u2014 and ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-100670 (Grav CMS 2.0.14 through 2.0.24 contains a privilege
escalation vulnera ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-100669 (Grav before 2.0.25 ships web server configuration samples
whose access ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-100668 (Grav 2.0.0 through 2.0.24 contain a Twig content sandbox
escape. The ` ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-100667 (grav-plugin-login (the Grav CMS Login plugin) versions >=
3.8.7 and < ...)
- TODO: check
+ NOT-FOR-US: Grav CMS plugin
CVE-2026-100666 (Netty's HttpServerCodec (io.netty:netty-codec-http) in
versions 4.2.0. ...)
TODO: check
CVE-2026-100665 (Netty versions from 4.2.11.Final before 4.2.18.Final contain
an incomp ...)
@@ -351,7 +351,7 @@ CVE-2026-63432 (Horilla is an HR and CRM software. From
1.0.0 until 1.6.0 and 2.
CVE-2026-63431 (Horilla is an HR and CRM software. In 1.5.0-85 and earlier,
payroll/vi ...)
NOT-FOR-US: Horilla
CVE-2026-5267 (Ciena Navigator Network Control Suite (NCS) contains an
information ex ...)
- TODO: check
+ NOT-FOR-US: Ciena Navigator Network Control Suite (NCS)
CVE-2026-57864
REJECTED
CVE-2026-57861
@@ -359,7 +359,7 @@ CVE-2026-57861
CVE-2026-57449 (Actual is a local-first personal finance tool. Prior to
26.7.0, Actual ...)
NOT-FOR-US: Actual
CVE-2026-57443 (SCBE-AETHERMOORE is a geometric AI governance and evaluation
framework ...)
- TODO: check
+ NOT-FOR-US: SCBE-AETHERMOORE
CVE-2026-53990
REJECTED
CVE-2026-53973
@@ -399,7 +399,7 @@ CVE-2026-15273 (The Automatic.css plugin for WordPress is
vulnerable to Stored C
CVE-2026-11871 (The Team Members WordPress plugin through 9.2 does not
perform any au ...)
NOT-FOR-US: WordPress plugin
CVE-2026-10758 (Esri LERC is an open-source image or raster format which
supports rapi ...)
- TODO: check
+ NOT-FOR-US: Esri LERC
CVE-2026-100599 (OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the
configur ...)
NOT-FOR-US: OpenClaw
CVE-2026-100598 (OpenClaw (npm package openclaw) before 2026.7.1 incorrectly
binds Sign ...)
@@ -880,7 +880,7 @@ CVE-2026-85750 (Piwigo before v16.4.0 is vulnerable to
arbitrary file read and r
CVE-2026-85542 (IBM Guardium Data Protection 12.2 is affected by a command
injection v ...)
NOT-FOR-US: IBM
CVE-2026-85496 (The Botslab G980H dash camera firmware generates session
identifiers u ...)
- TODO: check
+ NOT-FOR-US: Botslab G980H dash camera firmware
CVE-2026-85417 (Incomplete property masking in the SANnav logging subsystem
permits SN ...)
NOT-FOR-US: Brocade
CVE-2026-85293 (InvoicePlane is a self-hosted open source application for
managing inv ...)
@@ -1165,7 +1165,7 @@ CVE-2026-55217 (GLPI is a free asset and IT management
software package. From 0.
CVE-2026-55214 (GLPI is a free asset and IT management software package. From
11.0.6 u ...)
- glpi <removed>
CVE-2026-54790 (InvoicePlane is a self-hosted open source application for
managing inv ...)
- TODO: check
+ NOT-FOR-US: InvoicePlane
CVE-2026-53629 (GLPI is a free asset and IT management software package. From
9.4.0 un ...)
- glpi <removed>
CVE-2026-53628 (GLPI is a free asset and IT management software package. From
0.84 unt ...)
@@ -1181,27 +1181,27 @@ CVE-2026-53610 (GLPI is a free asset and IT management
software package. From 11
CVE-2026-53493 (containerd is an open-source container runtime. Prior to
versions 1.7. ...)
TODO: check
CVE-2026-52622 (An issue in Wellav Technologies Co., Ltd Wellav WES Emergency
Broadcas ...)
- TODO: check
+ NOT-FOR-US: Wellav
CVE-2026-51773 (An issue in the VMware datastore driver of OpenStack
glance_store. Whe ...)
TODO: check
CVE-2026-51772 (A Server-Side Request Forgery (SSRF) vulnerability exists in
the Image ...)
TODO: check
CVE-2026-50547 (InvoicePlane is a self-hosted open source application for
managing inv ...)
- TODO: check
+ NOT-FOR-US: InvoicePlane
CVE-2026-49850 (InvoicePlane is a self-hosted open source application for
managing inv ...)
- TODO: check
+ NOT-FOR-US: InvoicePlane
CVE-2026-49470 (GLPI is a free asset and IT management software package. From
11.0.0 u ...)
- glpi <removed>
CVE-2026-49469 (GLPI is a free asset and IT management software package. From
0.70 unt ...)
- glpi <removed>
CVE-2026-48543 (Krayin CRM through 2.2.6 contains a stored client-side
template inject ...)
- TODO: check
+ NOT-FOR-US: Krayin CRM
CVE-2026-48542 (Krayin CRM through 2.2.6 contains a stored client-side
template inject ...)
- TODO: check
+ NOT-FOR-US: Krayin CRM
CVE-2026-48541 (Krayin CRM through 2.2.6 contains a stored client-side
template inject ...)
- TODO: check
+ NOT-FOR-US: Krayin CRM
CVE-2026-48540 (Krayin CRM through 2.2.6 contains a stored client-side
template inject ...)
- TODO: check
+ NOT-FOR-US: Krayin CRM
CVE-2026-48482 (GLPI is a free asset and IT management software package. From
11.0.0 u ...)
- glpi <removed>
CVE-2026-47679 (GLPI is a free asset and IT management software package. From
10.0.0 u ...)
@@ -1217,23 +1217,23 @@ CVE-2026-42323 (Piwigo is a full featured open source
photo gallery application
CVE-2026-42322 (Piwigo is a full featured open source photo gallery
application for th ...)
- piwigo <removed>
CVE-2026-39372 (InvoicePlane is a self-hosted open source application for
managing inv ...)
- TODO: check
+ NOT-FOR-US: InvoicePlane
CVE-2026-39353 (InvoicePlane is a self-hosted open source application for
managing inv ...)
- TODO: check
+ NOT-FOR-US: InvoicePlane
CVE-2026-33639 (InvoicePlane is a self-hosted open source application for
managing inv ...)
- TODO: check
+ NOT-FOR-US: InvoicePlane
CVE-2026-27867 (An attacker with access via network to the Regesta Smart
HD-PLC of the ...)
- TODO: check
+ NOT-FOR-US: Regesta Smart HD-PLC TLDPH16D2
CVE-2026-19804 (The s2Member \u2013 Excellent for All Kinds of Memberships,
Content Re ...)
NOT-FOR-US: WordPress plugin
CVE-2026-19775 (The OpenStation \u2014 Desktop Windows, Dock & Virtual
Desktops for WP ...)
NOT-FOR-US: WordPress plugin
CVE-2026-18320 (Readwise Reader for Android uses a sanitize-html configuration
that pe ...)
- TODO: check
+ NOT-FOR-US: Readwise Reader for Android
CVE-2026-18312 (Readwise Reader for Android constructs URLs in its WebView
using attac ...)
- TODO: check
+ NOT-FOR-US: Readwise Reader for Android
CVE-2026-18311 (Readwise Reader for Android contains a cross-site scripting
vulnerabil ...)
- TODO: check
+ NOT-FOR-US: Readwise Reader for Android
CVE-2026-17602 (The SSL Zen \u2014 SSL Certificate Installer & HTTPS Redirects
plugin ...)
NOT-FOR-US: WordPress plugin
CVE-2026-17577 (The SSL Zen plugin for WordPress is vulnerable to Reflected
Cross-Site ...)
@@ -3181,9 +3181,9 @@ CVE-2026-57175 (Python Social Auth is a social
authentication/registration mecha
CVE-2026-56792 (Dell Rugged Control Center (RCC), versions prior to 5.2.206,
contain a ...)
NOT-FOR-US: Dell / EMC
CVE-2026-56744 (`@bsv/wallet-toolbox` provides BRC-100 wallet signing and
storage comp ...)
- TODO: check
+ NOT-FOR-US: bsv-blockchain/wallet-toolbox
CVE-2026-56739 (Logto is the modern, open-source auth infrastructure for SaaS
and AI a ...)
- TODO: check
+ NOT-FOR-US: Logto
CVE-2026-56738 (phpMyFAQ is an open source FAQ web application. The
`StopWords::add()` ...)
NOT-FOR-US: phpMyFAQ
CVE-2026-56737 (phpMyFAQ is an open source FAQ web application. Versions 3.2.0
through ...)
@@ -4999,9 +4999,9 @@ CVE-2026-57854
CVE-2026-57168
REJECTED
CVE-2026-55632 (GoCD is a continuous deliver server. From 20.2.0 until 26.1.0,
the int ...)
- TODO: check
+ NOT-FOR-US: GoCD
CVE-2026-55610 (InvoiceShelf is an open-source web & mobile app that helps
track expen ...)
- TODO: check
+ NOT-FOR-US: InvoiceShelf
CVE-2026-55456
REJECTED
CVE-2026-53979
@@ -5013,7 +5013,7 @@ CVE-2026-53969
CVE-2026-53968
REJECTED
CVE-2026-52744 (GoCD is a continuous deliver server. From 20.2.0 until 26.1.0,
the int ...)
- TODO: check
+ NOT-FOR-US: GoCD
CVE-2026-50228 (An unauthenticated local attacker can connect to the Electron
DevTools ...)
NOT-FOR-US: Acer
CVE-2026-50227 (An unauthenticated local attacker can connect to the MQTT
broker over ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ca447bb5e9f840c2cd81e681e3e3b99f49131f6d
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ca447bb5e9f840c2cd81e681e3e3b99f49131f6d
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits