Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
08ddcdcd by Salvatore Bonaccorso at 2026-07-17T22:19:01+02:00
Process some NFUs

- - - - -
6a696b5e by Salvatore Bonaccorso at 2026-07-17T22:19:01+02:00
Add CVE-2026-63308/Helm

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3,17 +3,17 @@ CVE-2026-9762 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 
through 12.1.4 is vulne
 CVE-2026-9656 (The HubSpot All-In-One Marketing \u2013 Forms, Popups, Live 
Chat plugi ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-9602 (Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to 
validate  ...)
-       TODO: check
+       NOT-FOR-US: Mattermost Desktop App
 CVE-2026-9592 (SEPPmail Secure Email Gateway & SEPPmail Cloud before version 
15.0.4.2 ...)
-       TODO: check
+       NOT-FOR-US: SEPPmail
 CVE-2026-9588 (A stored cross-site scripting (XSS) vulnerability exists in 
Sangoma Sw ...)
-       TODO: check
+       NOT-FOR-US: Sangoma Switchvox SMB Edition
 CVE-2026-9587 (An authenticated local file inclusion vulnerability exists in 
Sangoma  ...)
-       TODO: check
+       NOT-FOR-US: Sangoma Switchvox SMB Edition
 CVE-2026-9586 (An unauthenticated SQL injection vulnerability exists in 
Sangoma Switc ...)
-       TODO: check
+       NOT-FOR-US: Sangoma Switchvox SMB Edition
 CVE-2026-9585 (An unauthenticated reflected cross-site scripting (XSS) 
vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: Sangoma Switchvox SMB Edition
 CVE-2026-9537 (Mojo::JWT versions before 1.02 for Perl verify HMAC signatures 
with a  ...)
        - libmojo-jwt-perl 1.02-1
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/41907805/
@@ -29,39 +29,39 @@ CVE-2026-9135 (IBM Langflow OSS 1.0.0 through 1.10.0 
Langflow versions up to 1.9
 CVE-2026-9103 (IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote 
attacker to ...)
        NOT-FOR-US: IBM
 CVE-2026-8396 (Improper restriction of XML external entity reference 
vulnerability in ...)
-       TODO: check
+       NOT-FOR-US: NetGIS
 CVE-2026-8297 (Improper neutralization of special elements used in an SQL 
command ('S ...)
-       TODO: check
+       NOT-FOR-US: GisLab Laboratory Management System
 CVE-2026-8075 (Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to 
properly  ...)
-       TODO: check
+       NOT-FOR-US: Mattermost Desktop App
 CVE-2026-7488 (Insertion of sensitive information into sent data vulnerability 
in IKA ...)
-       TODO: check
+       NOT-FOR-US: IKAS Technology Inc. E-Commerce
 CVE-2026-7189 (Insertion of sensitive information into sent data vulnerability 
in Pro ...)
-       TODO: check
+       NOT-FOR-US: Proliz
 CVE-2026-63309 (SurrealDB before 3.1.5 fail to apply field-level SELECT 
permissions to ...)
-       TODO: check
+       NOT-FOR-US: SurrealDB
 CVE-2026-63308 (Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial 
of serv ...)
-       TODO: check
+       - helm-kubernetes <itp> (bug #910799)
 CVE-2026-63307 (Chat2DB before 5.3.0 contains an insecure direct object 
reference vuln ...)
-       TODO: check
+       NOT-FOR-US: Chat2DB
 CVE-2026-63101 (Open Event Server through 1.19.1 contains a missing 
authentication vul ...)
-       TODO: check
+       NOT-FOR-US: Open Event Server
 CVE-2026-63100 (Maybe through 0.6.0 contains a missing authorization 
vulnerability tha ...)
-       TODO: check
+       NOT-FOR-US: Maybe
 CVE-2026-63099 (TheHive through 4.1.24 contains a broken object-level 
authorization vu ...)
-       TODO: check
+       NOT-FOR-US: TheHive
 CVE-2026-63098 (TheHive through 4.1.24 contains an unauthenticated information 
disclos ...)
-       TODO: check
+       NOT-FOR-US: TheHive
 CVE-2026-63097 (Dendrite through 0.13.8 contains an improper access control 
vulnerabil ...)
-       TODO: check
+       NOT-FOR-US: Dendrite
 CVE-2026-63096 (Dendrite through 0.13.8 contains a server-side request forgery 
vulnera ...)
-       TODO: check
+       NOT-FOR-US: Dendrite
 CVE-2026-63095 (Dendrite through 0.13.8 contains an improper authorization 
vulnerabili ...)
-       TODO: check
+       NOT-FOR-US: Dendrite
 CVE-2026-63094 (SigNoz through 0.133.0 contains an open redirect vulnerability 
in the  ...)
-       TODO: check
+       NOT-FOR-US: SigNoz
 CVE-2026-63093 (Cursor for Windows version 3.2.16 contains a binary planting 
vulnerabi ...)
-       TODO: check
+       NOT-FOR-US: Cursor
 CVE-2026-62764 (Improper Handling of Insufficient Privileges vulnerability in 
Apache A ...)
        TODO: check
 CVE-2026-60025 (The Joomla extension Events Booking prior version 5.8.0 had an 
fronten ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/cb7d77916bf1dc9ca3f563b3e06972ea3edd2484...6a696b5eddd846cf4d56eda2f0ae5ddf6aafb419

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/cb7d77916bf1dc9ca3f563b3e06972ea3edd2484...6a696b5eddd846cf4d56eda2f0ae5ddf6aafb419
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to