0.44.0: CVEs from MikroTik's release notes (discussion #85)
NVD can take weeks to list the versions a new CVE affects, so a device one
release behind a security fix showed "No known CVEs" (6.49.22 vs
CVE-2026-84411, fixed in 6.49.23).
- The daily vulnerability refresh also reads the release notes of each
release between a fleet version and the newest known one (each read once)
and stores the CVEs they name - A CVE a release fixes counts against earlier versions of the same major,
"Fixed in" that release, with MikroTik's line quoted; confirms NVD's
"may not apply" guesses and fills gaps in NVD's ranges - CVEs NVD's RouterOS list lacks are looked up by id for a description and
rating (rate-limited), so the CVE alert can fire for them - Respects the vulnerability list and RouterOS changelogs Dark Site switches
- Docs: security (MikroTik's release notes)
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
Container images (published once CI passes):
ghcr.io/2gt-media-group-llc/mikrotik-manager-backend:0.44.0-betaghcr.io/2gt-media-group-llc/mikrotik-manager-nginx:0.44.0-beta
Documentation: https://2gt-media-group-llc.github.io/mikrotik-manager/