Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
08ddcdcd by Salvatore Bonaccorso at 2026-07-17T22:19:01+02:00
Process some NFUs
- - - - -
6a696b5e by Salvatore Bonaccorso at 2026-07-17T22:19:01+02:00
Add CVE-2026-63308/Helm
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3,17 +3,17 @@ CVE-2026-9762 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0
through 12.1.4 is vulne
CVE-2026-9656 (The HubSpot All-In-One Marketing \u2013 Forms, Popups, Live
Chat plugi ...)
NOT-FOR-US: WordPress plugin
CVE-2026-9602 (Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to
validate ...)
- TODO: check
+ NOT-FOR-US: Mattermost Desktop App
CVE-2026-9592 (SEPPmail Secure Email Gateway & SEPPmail Cloud before version
15.0.4.2 ...)
- TODO: check
+ NOT-FOR-US: SEPPmail
CVE-2026-9588 (A stored cross-site scripting (XSS) vulnerability exists in
Sangoma Sw ...)
- TODO: check
+ NOT-FOR-US: Sangoma Switchvox SMB Edition
CVE-2026-9587 (An authenticated local file inclusion vulnerability exists in
Sangoma ...)
- TODO: check
+ NOT-FOR-US: Sangoma Switchvox SMB Edition
CVE-2026-9586 (An unauthenticated SQL injection vulnerability exists in
Sangoma Switc ...)
- TODO: check
+ NOT-FOR-US: Sangoma Switchvox SMB Edition
CVE-2026-9585 (An unauthenticated reflected cross-site scripting (XSS)
vulnerability ...)
- TODO: check
+ NOT-FOR-US: Sangoma Switchvox SMB Edition
CVE-2026-9537 (Mojo::JWT versions before 1.02 for Perl verify HMAC signatures
with a ...)
- libmojo-jwt-perl 1.02-1
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41907805/
@@ -29,39 +29,39 @@ CVE-2026-9135 (IBM Langflow OSS 1.0.0 through 1.10.0
Langflow versions up to 1.9
CVE-2026-9103 (IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote
attacker to ...)
NOT-FOR-US: IBM
CVE-2026-8396 (Improper restriction of XML external entity reference
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: NetGIS
CVE-2026-8297 (Improper neutralization of special elements used in an SQL
command ('S ...)
- TODO: check
+ NOT-FOR-US: GisLab Laboratory Management System
CVE-2026-8075 (Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to
properly ...)
- TODO: check
+ NOT-FOR-US: Mattermost Desktop App
CVE-2026-7488 (Insertion of sensitive information into sent data vulnerability
in IKA ...)
- TODO: check
+ NOT-FOR-US: IKAS Technology Inc. E-Commerce
CVE-2026-7189 (Insertion of sensitive information into sent data vulnerability
in Pro ...)
- TODO: check
+ NOT-FOR-US: Proliz
CVE-2026-63309 (SurrealDB before 3.1.5 fail to apply field-level SELECT
permissions to ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63308 (Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial
of serv ...)
- TODO: check
+ - helm-kubernetes <itp> (bug #910799)
CVE-2026-63307 (Chat2DB before 5.3.0 contains an insecure direct object
reference vuln ...)
- TODO: check
+ NOT-FOR-US: Chat2DB
CVE-2026-63101 (Open Event Server through 1.19.1 contains a missing
authentication vul ...)
- TODO: check
+ NOT-FOR-US: Open Event Server
CVE-2026-63100 (Maybe through 0.6.0 contains a missing authorization
vulnerability tha ...)
- TODO: check
+ NOT-FOR-US: Maybe
CVE-2026-63099 (TheHive through 4.1.24 contains a broken object-level
authorization vu ...)
- TODO: check
+ NOT-FOR-US: TheHive
CVE-2026-63098 (TheHive through 4.1.24 contains an unauthenticated information
disclos ...)
- TODO: check
+ NOT-FOR-US: TheHive
CVE-2026-63097 (Dendrite through 0.13.8 contains an improper access control
vulnerabil ...)
- TODO: check
+ NOT-FOR-US: Dendrite
CVE-2026-63096 (Dendrite through 0.13.8 contains a server-side request forgery
vulnera ...)
- TODO: check
+ NOT-FOR-US: Dendrite
CVE-2026-63095 (Dendrite through 0.13.8 contains an improper authorization
vulnerabili ...)
- TODO: check
+ NOT-FOR-US: Dendrite
CVE-2026-63094 (SigNoz through 0.133.0 contains an open redirect vulnerability
in the ...)
- TODO: check
+ NOT-FOR-US: SigNoz
CVE-2026-63093 (Cursor for Windows version 3.2.16 contains a binary planting
vulnerabi ...)
- TODO: check
+ NOT-FOR-US: Cursor
CVE-2026-62764 (Improper Handling of Insufficient Privileges vulnerability in
Apache A ...)
TODO: check
CVE-2026-60025 (The Joomla extension Events Booking prior version 5.8.0 had an
fronten ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/cb7d77916bf1dc9ca3f563b3e06972ea3edd2484...6a696b5eddd846cf4d56eda2f0ae5ddf6aafb419
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/cb7d77916bf1dc9ca3f563b3e06972ea3edd2484...6a696b5eddd846cf4d56eda2f0ae5ddf6aafb419
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits