Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
5d4f5b65 by Moritz Muehlenhoff at 2026-08-20T14:05:20+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -4392,7 +4392,7 @@ CVE-2026-63328 (Trivy is a security scanner. Prior to
0.72.0, plugin manifest me
CVE-2026-62684 (File Browser is a file managing interface for uploading,
deleting, pre ...)
NOT-FOR-US: File Browser
CVE-2026-62357 (Dragonfly is an in-memory data store built for modern
application work ...)
- NOT-FOR-US: Dragonfly
+ NOT-FOR-US: DragonflyDB Dragonfly
CVE-2026-61696 (Forem is open source software for building communities. In
versions be ...)
NOT-FOR-US: Forem
CVE-2026-61634 (The RabbitMQ Java client library allows Java and JVM-based
application ...)
@@ -4440,33 +4440,33 @@ CVE-2026-55163 (Lemur manages TLS certificate creation.
Prior to 1.9.2, PUT /api
CVE-2026-55162 (Lemur manages TLS certificate creation. Prior to 1.9.2,
lemur/certific ...)
- lemur <itp> (bug #809533)
CVE-2026-55106 (authentik is an open-source identity provider. Prior to
2026.2.6 and 2 ...)
- TODO: check
+ NOT-FOR-US: authentik
CVE-2026-54730 (authentik is an open-source identity provider. Prior to
2026.2.6 and 2 ...)
- TODO: check
+ NOT-FOR-US: authentik
CVE-2026-54570 (AngleSharp is a .NET library for parsing angle bracket based
hyper-tex ...)
- TODO: check
+ NOT-FOR-US: AngleSharp
CVE-2026-54552 (sh provides Python process launching. Prior to 2.2.4, the _uid
option ...)
TODO: check
CVE-2026-53533 (aiosmtplib is an asynchronous SMTP client for use with
asyncio. Prior ...)
TODO: check
CVE-2026-52723 (ePA 3.x Integration implements the authorization workflow and
writes M ...)
- TODO: check
+ NOT-FOR-US: ePA3-Service-OpenSource
CVE-2026-52610 (An arbitrary file write/directory traversal vulnerability in
reportico ...)
- TODO: check
+ NOT-FOR-US: reportico-web
CVE-2026-52609 (A reflected cross-site scripting (XSS) vulnerability in
reportico-web ...)
- TODO: check
+ NOT-FOR-US: reportico-web
CVE-2026-52608 (An incorrect access control vulnerability in reportico-web <=
8.1.0 al ...)
- TODO: check
+ NOT-FOR-US: reportico-web
CVE-2026-52607 (A directory traversal vulnerability in reportico-web <= 8.1.0
allows r ...)
- TODO: check
+ NOT-FOR-US: reportico-web
CVE-2026-52606 (A reflected cross-site scripting (XSS) vulnerability in
reportico-web ...)
- TODO: check
+ NOT-FOR-US: reportico-web
CVE-2026-50578 (ePA 3.x Integration implements the authorization workflow and
writes M ...)
- TODO: check
+ NOT-FOR-US: ePA3-Service-OpenSource
CVE-2026-50577 (ePA 3.x Integration implements the authorization workflow and
writes M ...)
- TODO: check
+ NOT-FOR-US: ePA3-Service-OpenSource
CVE-2026-50576 (ePA 3.x Integration implements the authorization workflow and
writes M ...)
- TODO: check
+ NOT-FOR-US: ePA3-Service-OpenSource
CVE-2026-50575 (BetterDesk is a remote desktop management solution. BetterDesk
version ...)
TODO: check
CVE-2026-50187 (Oh My Zsh is a community-driven framework for managing Zsh
configurati ...)
@@ -4476,33 +4476,33 @@ CVE-2026-50167 (Kurrier is a modern, self-hosted
workspace for email, calendar,
CVE-2026-50161 (libre is a generic library for real-time communications with
asynchron ...)
TODO: check
CVE-2026-50143 (The Apify MCP server enables AI agents to extract data from
websites u ...)
- TODO: check
+ NOT-FOR-US: Apify MCP server
CVE-2026-50139 (goshs is a SimpleHTTPServer written in Go. Prior to version
2.1.0, `Sh ...)
TODO: check
CVE-2026-50138 (goshs is a SimpleHTTPServer written in Go. Prior to version
2.1.0, whe ...)
TODO: check
CVE-2026-50126 (Adaguc-server is an open source geographical information
system to vis ...)
- TODO: check
+ NOT-FOR-US: Vvveb
CVE-2026-49228 (Vvveb is a powerful and easy to use CMS with page builder to
build web ...)
- TODO: check
+ NOT-FOR-US: Vvveb
CVE-2026-49227 (Vvveb is a powerful and easy to use CMS with page builder to
build web ...)
- TODO: check
+ NOT-FOR-US: Vvveb
CVE-2026-49226 (Vvveb is a powerful and easy to use CMS with page builder to
build web ...)
- TODO: check
+ NOT-FOR-US: Vvveb
CVE-2026-49225 (Vvveb is a powerful and easy to use CMS with page builder to
build web ...)
- TODO: check
+ NOT-FOR-US: Vvveb
CVE-2026-49224 (Vvveb is a powerful and easy to use CMS with page builder to
build web ...)
- TODO: check
+ NOT-FOR-US: Vvveb
CVE-2026-49223 (Vvveb is a powerful and easy to use CMS with page builder to
build web ...)
- TODO: check
+ NOT-FOR-US: Vvveb
CVE-2026-49222 (Vvveb is a powerful and easy to use CMS with page builder to
build web ...)
- TODO: check
+ NOT-FOR-US: Vvveb
CVE-2026-49221 (Vvveb is a powerful and easy to use CMS with page builder to
build web ...)
- TODO: check
+ NOT-FOR-US: Vvveb
CVE-2026-48798 (SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0
and earl ...)
- TODO: check
+ NOT-FOR-US: SSH.NET
CVE-2026-48744 (Saleor is an e-commerce platform. From 3.14.67 until 3.21.67,
3.22.63, ...)
- TODO: check
+ NOT-FOR-US: Saleor
CVE-2026-48508 (Lemur manages TLS certificate creation. Prior to 1.9.1,
StrictRolePerm ...)
- lemur <itp> (bug #809533)
CVE-2026-47630 (NVIDIA Triton Inference Server for Linux contains a
vulnerability wher ...)
@@ -4522,7 +4522,7 @@ CVE-2026-46482 (### Impact The registration component
does not validate the text
CVE-2026-45734 (MyBB is free and open source forum software. Prior to 1.8.40,
the buil ...)
NOT-FOR-US: MyBB
CVE-2026-45733 (Trilium Notes is a cross-platform, hierarchical note taking
applicatio ...)
- TODO: check
+ NOT-FOR-US: Trilium Notes
CVE-2026-45532 (DataEase is an open source data visualization and analysis
tool. Versi ...)
NOT-FOR-US: DataEase
CVE-2026-45129 (MyBB is free and open source forum software. Prior to 1.8.40,
the Admi ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5d4f5b655636a623def927d32921be992a494cd2
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5d4f5b655636a623def927d32921be992a494cd2
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits