Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
9946565b by Salvatore Bonaccorso at 2026-07-12T08:40:24+02:00
Simplify overlong note, the advisory contains enough information

- - - - -
2e894241 by Salvatore Bonaccorso at 2026-07-12T08:54:11+02:00
Process some NFUs

- - - - -
b44f15ef by Salvatore Bonaccorso at 2026-07-12T08:54:37+02:00
Add CVE-2026-55213/h2o

- - - - -
951fca40 by Salvatore Bonaccorso at 2026-07-12T08:54:54+02:00
Add CVE-2026-54329/snipe-it

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -98,7 +98,7 @@ CVE-2026-6801 (The Context Blog theme for WordPress is 
vulnerable to Sensitive I
 CVE-2026-5743 (The SimpLy Gallery Block & Lightbox plugin for WordPress is 
vulnerable ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-59155 (Nezha Monitoring is a self-hostable, lightweight, servers and 
websites ...)
-       TODO: check
+       NOT-FOR-US: Nezha Monitoring
 CVE-2026-58591 (Improper Neutralization of Input During Web Page Generation 
("Cross-si ...)
        NOT-FOR-US: Drupal core and addons
 CVE-2026-58590 (Missing Authorization vulnerability in Drupal FlowDrop allows 
Forceful ...)
@@ -110,21 +110,21 @@ CVE-2026-58588 (Improper Neutralization of Input During 
Web Page Generation ("Cr
 CVE-2026-58587 (Improper Neutralization of Input During Web Page Generation 
("Cross-si ...)
        NOT-FOR-US: Drupal core and addons
 CVE-2026-58503 (Frappe is a full-stack web application framework. Prior to 
16.16.0 and ...)
-       TODO: check
+       NOT-FOR-US: Frappe
 CVE-2026-58499 (EverOS is a memory runtime for agents. Prior to 1.0.1, EverOS 
is vulne ...)
-       TODO: check
+       NOT-FOR-US: EverOS
 CVE-2026-57850 (RustDesk before 1.4.9 does not enforce a session's authorized 
connecti ...)
-       TODO: check
+       NOT-FOR-US: RustDesk
 CVE-2026-57807 (Authentication Bypass Using an Alternate Path or Channel 
vulnerability ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57584 (Phalcon is a high-performance, full-stack PHP framework. Prior 
to 5.15 ...)
-       TODO: check
+       NOT-FOR-US: RustDesk
 CVE-2026-57575 (Misskey is an open source, federated social media platform. 
Prior to 2 ...)
-       TODO: check
+       NOT-FOR-US: Misskey
 CVE-2026-57574 (Misskey is an open source, federated social media platform. 
Prior to 2 ...)
-       TODO: check
+       NOT-FOR-US: Misskey
 CVE-2026-57230 (OpenReplay is a self-hosted session replay suite. Prior to 
1.27.0, the ...)
-       TODO: check
+       NOT-FOR-US: OpenReplay
 CVE-2026-57221 (RabbitMQ is a messaging and streaming broker. Prior to 
3.13.15, 4.0.20 ...)
        TODO: check
 CVE-2026-57220 (RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, 
the Rabb ...)
@@ -148,19 +148,19 @@ CVE-2026-57212 (RabbitMQ is a messaging and streaming 
broker. Prior to 3.13.14,
 CVE-2026-57211 (RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 
and 4.2. ...)
        TODO: check
 CVE-2026-55884 (Tilt defines dev environments as code for microservice apps on 
Kuberne ...)
-       TODO: check
+       NOT-FOR-US: Tilt
 CVE-2026-55883 (Tilt defines dev environments as code for microservice apps on 
Kuberne ...)
-       TODO: check
+       NOT-FOR-US: Tilt
 CVE-2026-55882 (Tilt defines dev environments as code for microservice apps on 
Kuberne ...)
-       TODO: check
+       NOT-FOR-US: Tilt
 CVE-2026-55881 (OpenReplay is a self-hosted session replay suite. From 1.22.0 
before 1 ...)
-       TODO: check
+       NOT-FOR-US: OpenReplay
 CVE-2026-55880 (OpenReplay is a self-hosted session replay suite. In 1.27.0 
and earlie ...)
-       TODO: check
+       NOT-FOR-US: OpenReplay
 CVE-2026-55879 (OpenReplay is a self-hosted session replay suite. From 1.24.0 
before 1 ...)
-       TODO: check
+       NOT-FOR-US: OpenReplay
 CVE-2026-55852 (Frappe is a full-stack web application framework. Prior to 
16.23.0 and ...)
-       TODO: check
+       NOT-FOR-US: Frappe
 CVE-2026-55810 (Improperly Controlled Modification of Dynamically-Determined 
Object At ...)
        NOT-FOR-US: Drupal core and addons
 CVE-2026-55809 (Improperly Controlled Modification of Dynamically-Determined 
Object At ...)
@@ -176,13 +176,13 @@ CVE-2026-55804 (Improperly Controlled Modification of 
Dynamically-Determined Obj
 CVE-2026-55803 (Improperly Controlled Modification of Dynamically-Determined 
Object At ...)
        NOT-FOR-US: Drupal core and addons
 CVE-2026-55789 (Logto is the modern, open-source auth infrastructure for SaaS 
and AI a ...)
-       TODO: check
+       NOT-FOR-US: Logto
 CVE-2026-55665 (Grist is spreadsheet software using Python as its formula 
language. Pr ...)
-       TODO: check
+       NOT-FOR-US: Grist
 CVE-2026-55664 (Grist is spreadsheet software using Python as its formula 
language. Pr ...)
-       TODO: check
+       NOT-FOR-US: Grist
 CVE-2026-55659 (Grist is spreadsheet software using Python as its formula 
language. Pr ...)
-       TODO: check
+       NOT-FOR-US: Grist
 CVE-2026-55515 (Snipe-IT is an IT asset/license management system. Prior to 
8.6.2, the ...)
        - snipe-it <itp> (bug #1005172)
 CVE-2026-55481 (Snipe-IT is an IT asset/license management system. Prior to 
8.6.2, def ...)
@@ -202,25 +202,26 @@ CVE-2026-55461 (Snipe-IT is an IT asset/license 
management system. Prior to 8.6.
 CVE-2026-55452 (Snipe-IT is an IT asset/license management system. Prior to 
8.5.0, Act ...)
        - snipe-it <itp> (bug #1005172)
 CVE-2026-55405 (LangChain4j is a Java library for building LLM-powered 
applications on ...)
-       TODO: check
+       NOT-FOR-US: LangChain4j
 CVE-2026-55377 (Logto is the modern, open-source auth infrastructure for SaaS 
and AI a ...)
-       TODO: check
+       NOT-FOR-US: Logto
 CVE-2026-55370 (Logto is the modern, open-source auth infrastructure for SaaS 
and AI a ...)
-       TODO: check
+       NOT-FOR-US: Logto
 CVE-2026-55233 (OpenResty is a high performance web platform. From 1.29.2.1 to 
before  ...)
        TODO: check
 CVE-2026-55229 (Gotenberg is a Docker-powered stateless API for PDF files. 
Prior to 8. ...)
-       TODO: check
+       NOT-FOR-US: Gotenberg
 CVE-2026-55213 (h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and 
HTTP/3. Pr ...)
-       TODO: check
+       - h2o <removed>
+       NOTE: https://github.com/h2o/h2o/security/advisories/GHSA-432c-8xmj-frmq
 CVE-2026-55187 (Mailpit is an email testing tool and API for developers. Prior 
to 1.30 ...)
        TODO: check
 CVE-2026-55175 (Spinnaker is an open source, multi-cloud continuous delivery 
platform. ...)
-       TODO: check
+       NOT-FOR-US: Spinnaker
 CVE-2026-54736 (Phalcon is a high-performance, full-stack PHP framework. Prior 
to 5.14 ...)
-       TODO: check
+       NOT-FOR-US: Phalcon
 CVE-2026-54714 (Logto is the modern, open-source auth infrastructure for SaaS 
and AI a ...)
-       TODO: check
+       NOT-FOR-US: Logto
 CVE-2026-52761 (ModSecurity is an open source, cross platform web application 
firewall ...)
        TODO: check
 CVE-2026-52747 (ModSecurity is an open source, cross platform web application 
firewall ...)
@@ -485,9 +486,9 @@ CVE-2026-59180 (Apprise is an open source library which 
allows you to send a not
        NOTE: https://github.com/caronc/apprise/pull/1610
        NOTE: Fixed by: 
https://github.com/caronc/apprise/commit/68c0aef218055e4586cf4605fd6b56358f5f462d
 (v1.11.0)
 CVE-2026-59162 (Excelize is a Go language library for reading and writing 
Microsoft Ex ...)
-       TODO: check
+       NOT-FOR-US: Excelize
 CVE-2026-59161 (Excelize is a Go language library for reading and writing 
Microsoft Ex ...)
-       TODO: check
+       NOT-FOR-US: Excelize
 CVE-2026-59154 (Wekan is open source kanban built with Meteor. Prior to 9.64, 
Wekan ha ...)
        - wekan <itp> (bug #819238)
 CVE-2026-59151 (Prowler is a cloud security platform. Prior to 5.30.3, 
Prowler's SAML  ...)
@@ -499,7 +500,7 @@ CVE-2026-58493 (grav-plugin-database is the database plugin 
for Grav CMS. Prior
 CVE-2026-58492 (grav-plugin-database is the database plugin for Grav CMS. 
Prior to 1.2 ...)
        NOT-FOR-US: grav-plugin-database
 CVE-2026-58225 (SQL Injection vulnerability in elixir-ecto postgrex allows an 
attacker ...)
-       TODO: check
+       NOT-FOR-US: elixir-ecto postgrex
 CVE-2026-57994 (phpMyFAQ before 4.1.5 applies inconsistent active=yes and 
publication- ...)
        NOT-FOR-US: phpMyFAQ
 CVE-2026-57961 (phpMyFAQ before 4.1.5 contains a potential authenticated path 
traversa ...)
@@ -581,7 +582,7 @@ CVE-2026-55781 (NanaZip is the 7-Zip derivative intended 
for the modern Windows
 CVE-2026-55780 (NanaZip is the 7-Zip derivative intended for the modern 
Windows experi ...)
        NOT-FOR-US: NanaZip
 CVE-2026-55687 (ESF-IDF is the Espressif Internet of Things (IOT) Development 
Framewor ...)
-       TODO: check
+       NOT-FOR-US: ESF-IDF
 CVE-2026-55672 (ZITADEL is an open source identity management platform. Prior 
to 3.4.1 ...)
        NOT-FOR-US: Zitadel
 CVE-2026-55671 (ZITADEL is an open source identity management platform. From 
4.0.0-rc. ...)
@@ -621,11 +622,11 @@ CVE-2026-54469 (Dell Unisphere for PowerMax, version(s) 
10.3.0.5 and prior, cont
 CVE-2026-54468 (Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, 
contain(s) ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-54329 (Snipe-IT is an IT asset/license management system. Prior to 
8.6.2, the ...)
-       TODO: check
+       - snipe-it <itp> (bug #1005172)
 CVE-2026-54149 (MaxKB is an open-source AI assistant for enterprise. Prior to 
2.10.0-l ...)
-       TODO: check
+       NOT-FOR-US: MaxKB
 CVE-2026-54063 (Excelize is a Go language library for reading and writing 
Microsoft Ex ...)
-       TODO: check
+       NOT-FOR-US: Excelize
 CVE-2026-54001 (osquery is a SQL powered operating system instrumentation, 
monitoring, ...)
        TODO: check
 CVE-2026-54000 (osquery is a SQL powered operating system instrumentation, 
monitoring, ...)
@@ -633,9 +634,9 @@ CVE-2026-54000 (osquery is a SQL powered operating system 
instrumentation, monit
 CVE-2026-53780
        REJECTED
 CVE-2026-53657 (Lima launches Linux virtual machines, typically on macOS, for 
running  ...)
-       TODO: check
+       NOT-FOR-US: Lima
 CVE-2026-53653 (Grav is a file-based Web platform. Prior to 1.7.53 and 
2.0.0-rc.8, Gra ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS
 CVE-2026-53450 (Coturn is a free open source implementation of TURN and STUN 
Server. P ...)
        TODO: check
 CVE-2026-53449 (Coturn is a free open source implementation of TURN and STUN 
Server. P ...)
@@ -643,7 +644,7 @@ CVE-2026-53449 (Coturn is a free open source implementation 
of TURN and STUN Ser
 CVE-2026-53448 (Coturn is a free open source implementation of TURN and STUN 
Server. P ...)
        TODO: check
 CVE-2026-51119 (An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to 
escalat ...)
-       TODO: check
+       NOT-FOR-US: Invixium IXM WEB
 CVE-2026-46388 (osquery is a SQL powered operating system instrumentation, 
monitoring, ...)
        TODO: check
 CVE-2026-41880 (R-SOFT DMS is vulnerable toOS Command Injection in the Optical 
Charact ...)
@@ -2186,7 +2187,7 @@ CVE-2026-49145 (App::Ack versions through 3.10.0 for Perl 
read arbitrary files v
        [bullseye] - ack <postponed> (Minor issue; local-only, needs untrusted 
project .ackrc; --files-from still unfixed upstream)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/41643327/
        NOTE: Fixed by: 
https://github.com/beyondgrep/ack3/commit/45ff5fe77dbd96f7332f31943102291f878f30b8
 (v3.10.0)
-       NOTE: 45ff5fe (v3.10.0) is only a partial fix: it adds --follow to the 
project .ackrc blocklist but --files-from remains accepted, so arbitrary file 
read via --files-from is still unfixed upstream.
+       NOTE: v3.10.0 only released with a partial fix for the --follow-option.
 CVE-2026-44840 (Dgraph is an open source distributed GraphQL database. Prior 
to versio ...)
        TODO: check
 CVE-2026-41122 (Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, 
LTS2026 r ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/b8641cc96f8f8797f11d05a985e95fd6b248af3f...951fca40b0b0efb61a9237c79143ec2c712f4ee1

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/b8641cc96f8f8797f11d05a985e95fd6b248af3f...951fca40b0b0efb61a9237c79143ec2c712f4ee1
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to