{"grype_matches":[{"artifact":{"id":"813a521db4fc3e60","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Common.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Common.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5f2m-466j-3848","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-5f2m-466j-3848","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-08","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0981","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0981","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"risk":3.70725,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0981","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0981","https://github.com/dotnet/announcements/issues/113","https://github.com/github/advisory-database/issues/302"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5f2m-466j-3848","description":"Denial of service in ASP.NET Core"},"relatedVulnerabilities":[{"id":"CVE-2019-0981","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0981","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0981","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"urls":["https://access.redhat.com/errata/RHSA-2019:1259","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0981"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0981","description":"A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980."}]},{"artifact":{"id":"ab0a95adac035edf","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Http.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Http.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5f2m-466j-3848","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-5f2m-466j-3848","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-08","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0981","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0981","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"risk":3.70725,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0981","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0981","https://github.com/dotnet/announcements/issues/113","https://github.com/github/advisory-database/issues/302"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5f2m-466j-3848","description":"Denial of service in ASP.NET Core"},"relatedVulnerabilities":[{"id":"CVE-2019-0981","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0981","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0981","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"urls":["https://access.redhat.com/errata/RHSA-2019:1259","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0981"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0981","description":"A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980."}]},{"artifact":{"id":"ef362d5a7ec58ac7","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Api.V1.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Api.V1.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5f2m-466j-3848","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-5f2m-466j-3848","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-08","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0981","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0981","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"risk":3.70725,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0981","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0981","https://github.com/dotnet/announcements/issues/113","https://github.com/github/advisory-database/issues/302"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5f2m-466j-3848","description":"Denial of service in ASP.NET Core"},"relatedVulnerabilities":[{"id":"CVE-2019-0981","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0981","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0981","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"urls":["https://access.redhat.com/errata/RHSA-2019:1259","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0981"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0981","description":"A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980."}]},{"artifact":{"id":"d19caa8a77759251","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.SignalR.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.SignalR.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5f2m-466j-3848","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-5f2m-466j-3848","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-08","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0981","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0981","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"risk":3.70725,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0981","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0981","https://github.com/dotnet/announcements/issues/113","https://github.com/github/advisory-database/issues/302"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5f2m-466j-3848","description":"Denial of service in ASP.NET Core"},"relatedVulnerabilities":[{"id":"CVE-2019-0981","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0981","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0981","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"urls":["https://access.redhat.com/errata/RHSA-2019:1259","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0981"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0981","description":"A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980."}]},{"artifact":{"id":"9a7aa0bb8939199c","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Host.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Host.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5f2m-466j-3848","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-5f2m-466j-3848","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-08","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0981","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0981","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"risk":3.70725,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0981","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0981","https://github.com/dotnet/announcements/issues/113","https://github.com/github/advisory-database/issues/302"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5f2m-466j-3848","description":"Denial of service in ASP.NET Core"},"relatedVulnerabilities":[{"id":"CVE-2019-0981","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0981","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0981","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"urls":["https://access.redhat.com/errata/RHSA-2019:1259","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0981"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0981","description":"A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980."}]},{"artifact":{"id":"9bcafce77bfc30eb","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Core.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Core.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5f2m-466j-3848","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-5f2m-466j-3848","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-08","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0981","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0981","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"risk":3.70725,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0981","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0981","https://github.com/dotnet/announcements/issues/113","https://github.com/github/advisory-database/issues/302"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5f2m-466j-3848","description":"Denial of service in ASP.NET Core"},"relatedVulnerabilities":[{"id":"CVE-2019-0981","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0981","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0981","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"urls":["https://access.redhat.com/errata/RHSA-2019:1259","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0981"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0981","description":"A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980."}]},{"artifact":{"id":"d19caa8a77759251","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.SignalR.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.SignalR.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-xhfc-gr8f-ffwc","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-xhfc-gr8f-ffwc","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-08","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0980","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0980","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"risk":3.70725,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0980","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0980","https://github.com/dotnet/announcements/issues/112","https://github.com/github/advisory-database/issues/302"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-xhfc-gr8f-ffwc","description":"Denial of service in ASP.NET Core"},"relatedVulnerabilities":[{"id":"CVE-2019-0980","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0980","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0980","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"urls":["https://access.redhat.com/errata/RHSA-2019:1259","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0980"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0980","description":"A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0981."}]},{"artifact":{"id":"ab0a95adac035edf","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Http.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Http.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-xhfc-gr8f-ffwc","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-xhfc-gr8f-ffwc","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-08","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0980","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0980","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"risk":3.70725,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0980","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0980","https://github.com/dotnet/announcements/issues/112","https://github.com/github/advisory-database/issues/302"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-xhfc-gr8f-ffwc","description":"Denial of service in ASP.NET Core"},"relatedVulnerabilities":[{"id":"CVE-2019-0980","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0980","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0980","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"urls":["https://access.redhat.com/errata/RHSA-2019:1259","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0980"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0980","description":"A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0981."}]},{"artifact":{"id":"9a7aa0bb8939199c","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Host.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Host.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-xhfc-gr8f-ffwc","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-xhfc-gr8f-ffwc","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-08","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0980","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0980","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"risk":3.70725,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0980","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0980","https://github.com/dotnet/announcements/issues/112","https://github.com/github/advisory-database/issues/302"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-xhfc-gr8f-ffwc","description":"Denial of service in ASP.NET Core"},"relatedVulnerabilities":[{"id":"CVE-2019-0980","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0980","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0980","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"urls":["https://access.redhat.com/errata/RHSA-2019:1259","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0980"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0980","description":"A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0981."}]},{"artifact":{"id":"9bcafce77bfc30eb","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Core.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Core.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-xhfc-gr8f-ffwc","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-xhfc-gr8f-ffwc","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-08","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0980","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0980","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"risk":3.70725,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0980","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0980","https://github.com/dotnet/announcements/issues/112","https://github.com/github/advisory-database/issues/302"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-xhfc-gr8f-ffwc","description":"Denial of service in ASP.NET Core"},"relatedVulnerabilities":[{"id":"CVE-2019-0980","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0980","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0980","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"urls":["https://access.redhat.com/errata/RHSA-2019:1259","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0980"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0980","description":"A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0981."}]},{"artifact":{"id":"813a521db4fc3e60","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Common.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Common.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-xhfc-gr8f-ffwc","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-xhfc-gr8f-ffwc","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-08","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0980","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0980","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"risk":3.70725,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0980","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0980","https://github.com/dotnet/announcements/issues/112","https://github.com/github/advisory-database/issues/302"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-xhfc-gr8f-ffwc","description":"Denial of service in ASP.NET Core"},"relatedVulnerabilities":[{"id":"CVE-2019-0980","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0980","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0980","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"urls":["https://access.redhat.com/errata/RHSA-2019:1259","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0980"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0980","description":"A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0981."}]},{"artifact":{"id":"ef362d5a7ec58ac7","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Api.V1.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Api.V1.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-xhfc-gr8f-ffwc","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-xhfc-gr8f-ffwc","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-08","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0980","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0980","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"risk":3.70725,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0980","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0980","https://github.com/dotnet/announcements/issues/112","https://github.com/github/advisory-database/issues/302"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-xhfc-gr8f-ffwc","description":"Denial of service in ASP.NET Core"},"relatedVulnerabilities":[{"id":"CVE-2019-0980","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0980","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0980","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"urls":["https://access.redhat.com/errata/RHSA-2019:1259","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0980"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0980","description":"A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0981."}]},{"artifact":{"id":"ab0a95adac035edf","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Http.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Http.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-x5qj-9vmx-7g6g","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-x5qj-9vmx-7g6g","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-09","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0657","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0657","date":"2026-10-08","epss":0.04518,"percentile":0.91284}],"risk":2.46231,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0657","https://access.redhat.com/errata/RHSA-2019:0349","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657","http://www.securityfocus.com/bid/106890","https://github.com/dotnet/announcements/issues/97","https://github.com/github/advisory-database/issues/302"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-x5qj-9vmx-7g6g","description":"Improper Input Validation in .Net Framework API's"},"relatedVulnerabilities":[{"id":"CVE-2019-0657","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0657","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0657","date":"2026-10-08","epss":0.04518,"percentile":0.91284}],"urls":["http://www.securityfocus.com/bid/106890","https://access.redhat.com/errata/RHSA-2019:0349","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0657","description":"A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'."}]},{"artifact":{"id":"ef362d5a7ec58ac7","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Api.V1.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Api.V1.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-x5qj-9vmx-7g6g","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-x5qj-9vmx-7g6g","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-09","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0657","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0657","date":"2026-10-08","epss":0.04518,"percentile":0.91284}],"risk":2.46231,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0657","https://access.redhat.com/errata/RHSA-2019:0349","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657","http://www.securityfocus.com/bid/106890","https://github.com/dotnet/announcements/issues/97","https://github.com/github/advisory-database/issues/302"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-x5qj-9vmx-7g6g","description":"Improper Input Validation in .Net Framework API's"},"relatedVulnerabilities":[{"id":"CVE-2019-0657","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0657","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0657","date":"2026-10-08","epss":0.04518,"percentile":0.91284}],"urls":["http://www.securityfocus.com/bid/106890","https://access.redhat.com/errata/RHSA-2019:0349","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0657","description":"A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'."}]},{"artifact":{"id":"813a521db4fc3e60","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Common.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Common.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-x5qj-9vmx-7g6g","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-x5qj-9vmx-7g6g","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-09","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0657","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0657","date":"2026-10-08","epss":0.04518,"percentile":0.91284}],"risk":2.46231,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0657","https://access.redhat.com/errata/RHSA-2019:0349","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657","http://www.securityfocus.com/bid/106890","https://github.com/dotnet/announcements/issues/97","https://github.com/github/advisory-database/issues/302"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-x5qj-9vmx-7g6g","description":"Improper Input Validation in .Net Framework API's"},"relatedVulnerabilities":[{"id":"CVE-2019-0657","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0657","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0657","date":"2026-10-08","epss":0.04518,"percentile":0.91284}],"urls":["http://www.securityfocus.com/bid/106890","https://access.redhat.com/errata/RHSA-2019:0349","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0657","description":"A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'."}]},{"artifact":{"id":"9bcafce77bfc30eb","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Core.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Core.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-x5qj-9vmx-7g6g","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-x5qj-9vmx-7g6g","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-09","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0657","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0657","date":"2026-10-08","epss":0.04518,"percentile":0.91284}],"risk":2.46231,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0657","https://access.redhat.com/errata/RHSA-2019:0349","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657","http://www.securityfocus.com/bid/106890","https://github.com/dotnet/announcements/issues/97","https://github.com/github/advisory-database/issues/302"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-x5qj-9vmx-7g6g","description":"Improper Input Validation in .Net Framework API's"},"relatedVulnerabilities":[{"id":"CVE-2019-0657","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0657","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0657","date":"2026-10-08","epss":0.04518,"percentile":0.91284}],"urls":["http://www.securityfocus.com/bid/106890","https://access.redhat.com/errata/RHSA-2019:0349","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0657","description":"A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'."}]},{"artifact":{"id":"9a7aa0bb8939199c","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Host.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Host.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-x5qj-9vmx-7g6g","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-x5qj-9vmx-7g6g","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-09","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0657","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0657","date":"2026-10-08","epss":0.04518,"percentile":0.91284}],"risk":2.46231,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0657","https://access.redhat.com/errata/RHSA-2019:0349","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657","http://www.securityfocus.com/bid/106890","https://github.com/dotnet/announcements/issues/97","https://github.com/github/advisory-database/issues/302"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-x5qj-9vmx-7g6g","description":"Improper Input Validation in .Net Framework API's"},"relatedVulnerabilities":[{"id":"CVE-2019-0657","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0657","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0657","date":"2026-10-08","epss":0.04518,"percentile":0.91284}],"urls":["http://www.securityfocus.com/bid/106890","https://access.redhat.com/errata/RHSA-2019:0349","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0657","description":"A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'."}]},{"artifact":{"id":"d19caa8a77759251","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.SignalR.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.SignalR.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-x5qj-9vmx-7g6g","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-x5qj-9vmx-7g6g","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-09","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0657","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0657","date":"2026-10-08","epss":0.04518,"percentile":0.91284}],"risk":2.46231,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0657","https://access.redhat.com/errata/RHSA-2019:0349","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657","http://www.securityfocus.com/bid/106890","https://github.com/dotnet/announcements/issues/97","https://github.com/github/advisory-database/issues/302"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-x5qj-9vmx-7g6g","description":"Improper Input Validation in .Net Framework API's"},"relatedVulnerabilities":[{"id":"CVE-2019-0657","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0657","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0657","date":"2026-10-08","epss":0.04518,"percentile":0.91284}],"urls":["http://www.securityfocus.com/bid/106890","https://access.redhat.com/errata/RHSA-2019:0349","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0657","description":"A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'."}]},{"artifact":{"id":"03a87ab2abe700e3","cpes":["cpe:2.3:a:_net_foundation:mimekit_.net:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:_net_foundation:mimekit:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:mimekit:mimekit_.net:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:mimekit:mimekit:4.14.0:*:*:*:*:*:*:*"],"name":"MimeKit","purl":"pkg:nuget/MimeKit@4.14.0","type":"dotnet","version":"4.14.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/MimeKit.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/MimeKit.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.15.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-g7hc-96xr-gvvx","versionConstraint":"<=4.15.0 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"MimeKit","version":"4.14.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-g7hc-96xr-gvvx","fix":{"state":"fixed","versions":["4.15.1"],"available":[{"date":"2026-03-06","kind":"first-observed","version":"4.15.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30227","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-30227","date":"2026-10-08","epss":0.0121,"percentile":0.67542}],"risk":0.71995,"urls":["https://github.com/jstedfast/MimeKit/security/advisories/GHSA-g7hc-96xr-gvvx","https://nvd.nist.gov/vuln/detail/CVE-2026-30227"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-g7hc-96xr-gvvx","description":"MimeKit has CRLF Injection in Quoted Local-Part that Enables SMTP Command Injection and Email Forgery"},"relatedVulnerabilities":[{"id":"CVE-2026-30227","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30227","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-30227","date":"2026-10-08","epss":0.0121,"percentile":0.67542}],"urls":["https://github.com/jstedfast/MimeKit/security/advisories/GHSA-g7hc-96xr-gvvx"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30227","description":"MimeKit is a C# library which may be used for the creation and parsing of messages using the Multipurpose Internet Mail Extension (MIME), as defined by numerous IETF specifications. Prior to version 4.15.1, a CRLF injection vulnerability in MimeKit allows an attacker to embed \\r\\n into the SMTP envelope address local-part (when the local-part is a quoted-string). This is non-compliant with RFC 5321 and can result in SMTP command injection (e.g., injecting additional RCPT TO / DATA / RSET commands) and/or mail header injection, depending on how the application uses MailKit/MimeKit to construct and send messages. The issue becomes exploitable when the attacker can influence a MailboxAddress (MAIL FROM / RCPT TO) value that is later serialized to an SMTP session. RFC 5321 explicitly defines the SMTP mailbox local-part grammar and does not permit CR (13) or LF (10) inside Quoted-string (qtextSMTP and quoted-pairSMTP ranges exclude control characters). SMTP commands are terminated by <CRLF>, making CRLF injection in command arguments particularly dangerous. This issue has been patched in version 4.15.1."}]},{"artifact":{"id":"b0f5934e832b8de0","cpes":["cpe:2.3:a:_net_foundation:mimekit_.net:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:_net_foundation:mimekit:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:mimekit:mimekit_.net:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:mimekit:mimekit:4.14.0:*:*:*:*:*:*:*"],"name":"MimeKit","purl":"pkg:nuget/MimeKit@4.14.0","type":"dotnet","version":"4.14.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.SignalR.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.SignalR.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/MimeKit.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/MimeKit.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.15.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-g7hc-96xr-gvvx","versionConstraint":"<=4.15.0 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"MimeKit","version":"4.14.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-g7hc-96xr-gvvx","fix":{"state":"fixed","versions":["4.15.1"],"available":[{"date":"2026-03-06","kind":"first-observed","version":"4.15.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30227","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-30227","date":"2026-10-08","epss":0.0121,"percentile":0.67542}],"risk":0.71995,"urls":["https://github.com/jstedfast/MimeKit/security/advisories/GHSA-g7hc-96xr-gvvx","https://nvd.nist.gov/vuln/detail/CVE-2026-30227"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-g7hc-96xr-gvvx","description":"MimeKit has CRLF Injection in Quoted Local-Part that Enables SMTP Command Injection and Email Forgery"},"relatedVulnerabilities":[{"id":"CVE-2026-30227","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30227","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-30227","date":"2026-10-08","epss":0.0121,"percentile":0.67542}],"urls":["https://github.com/jstedfast/MimeKit/security/advisories/GHSA-g7hc-96xr-gvvx"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30227","description":"MimeKit is a C# library which may be used for the creation and parsing of messages using the Multipurpose Internet Mail Extension (MIME), as defined by numerous IETF specifications. Prior to version 4.15.1, a CRLF injection vulnerability in MimeKit allows an attacker to embed \\r\\n into the SMTP envelope address local-part (when the local-part is a quoted-string). This is non-compliant with RFC 5321 and can result in SMTP command injection (e.g., injecting additional RCPT TO / DATA / RSET commands) and/or mail header injection, depending on how the application uses MailKit/MimeKit to construct and send messages. The issue becomes exploitable when the attacker can influence a MailboxAddress (MAIL FROM / RCPT TO) value that is later serialized to an SMTP session. RFC 5321 explicitly defines the SMTP mailbox local-part grammar and does not permit CR (13) or LF (10) inside Quoted-string (qtextSMTP and quoted-pairSMTP ranges exclude control characters). SMTP commands are terminated by <CRLF>, making CRLF injection in command arguments particularly dangerous. This issue has been patched in version 4.15.1."}]},{"artifact":{"id":"3b4fd56e2a431e65","cpes":["cpe:2.3:a:_net_foundation:mimekit_.net:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:_net_foundation:mimekit:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:mimekit:mimekit_.net:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:mimekit:mimekit:4.14.0:*:*:*:*:*:*:*"],"name":"MimeKit","purl":"pkg:nuget/MimeKit@4.14.0","type":"dotnet","version":"4.14.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Core.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Core.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/MimeKit.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/MimeKit.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.15.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-g7hc-96xr-gvvx","versionConstraint":"<=4.15.0 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"MimeKit","version":"4.14.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-g7hc-96xr-gvvx","fix":{"state":"fixed","versions":["4.15.1"],"available":[{"date":"2026-03-06","kind":"first-observed","version":"4.15.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30227","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-30227","date":"2026-10-08","epss":0.0121,"percentile":0.67542}],"risk":0.71995,"urls":["https://github.com/jstedfast/MimeKit/security/advisories/GHSA-g7hc-96xr-gvvx","https://nvd.nist.gov/vuln/detail/CVE-2026-30227"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-g7hc-96xr-gvvx","description":"MimeKit has CRLF Injection in Quoted Local-Part that Enables SMTP Command Injection and Email Forgery"},"relatedVulnerabilities":[{"id":"CVE-2026-30227","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30227","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-30227","date":"2026-10-08","epss":0.0121,"percentile":0.67542}],"urls":["https://github.com/jstedfast/MimeKit/security/advisories/GHSA-g7hc-96xr-gvvx"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30227","description":"MimeKit is a C# library which may be used for the creation and parsing of messages using the Multipurpose Internet Mail Extension (MIME), as defined by numerous IETF specifications. Prior to version 4.15.1, a CRLF injection vulnerability in MimeKit allows an attacker to embed \\r\\n into the SMTP envelope address local-part (when the local-part is a quoted-string). This is non-compliant with RFC 5321 and can result in SMTP command injection (e.g., injecting additional RCPT TO / DATA / RSET commands) and/or mail header injection, depending on how the application uses MailKit/MimeKit to construct and send messages. The issue becomes exploitable when the attacker can influence a MailboxAddress (MAIL FROM / RCPT TO) value that is later serialized to an SMTP session. RFC 5321 explicitly defines the SMTP mailbox local-part grammar and does not permit CR (13) or LF (10) inside Quoted-string (qtextSMTP and quoted-pairSMTP ranges exclude control characters). SMTP commands are terminated by <CRLF>, making CRLF injection in command arguments particularly dangerous. This issue has been patched in version 4.15.1."}]},{"artifact":{"id":"21e9ec315d9aac89","cpes":["cpe:2.3:a:_net_foundation:mimekit_.net:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:_net_foundation:mimekit:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:mimekit:mimekit_.net:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:mimekit:mimekit:4.14.0:*:*:*:*:*:*:*"],"name":"MimeKit","purl":"pkg:nuget/MimeKit@4.14.0","type":"dotnet","version":"4.14.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Api.V1.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Api.V1.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/MimeKit.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/MimeKit.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.15.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-g7hc-96xr-gvvx","versionConstraint":"<=4.15.0 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"MimeKit","version":"4.14.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-g7hc-96xr-gvvx","fix":{"state":"fixed","versions":["4.15.1"],"available":[{"date":"2026-03-06","kind":"first-observed","version":"4.15.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30227","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-30227","date":"2026-10-08","epss":0.0121,"percentile":0.67542}],"risk":0.71995,"urls":["https://github.com/jstedfast/MimeKit/security/advisories/GHSA-g7hc-96xr-gvvx","https://nvd.nist.gov/vuln/detail/CVE-2026-30227"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-g7hc-96xr-gvvx","description":"MimeKit has CRLF Injection in Quoted Local-Part that Enables SMTP Command Injection and Email Forgery"},"relatedVulnerabilities":[{"id":"CVE-2026-30227","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30227","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-30227","date":"2026-10-08","epss":0.0121,"percentile":0.67542}],"urls":["https://github.com/jstedfast/MimeKit/security/advisories/GHSA-g7hc-96xr-gvvx"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30227","description":"MimeKit is a C# library which may be used for the creation and parsing of messages using the Multipurpose Internet Mail Extension (MIME), as defined by numerous IETF specifications. Prior to version 4.15.1, a CRLF injection vulnerability in MimeKit allows an attacker to embed \\r\\n into the SMTP envelope address local-part (when the local-part is a quoted-string). This is non-compliant with RFC 5321 and can result in SMTP command injection (e.g., injecting additional RCPT TO / DATA / RSET commands) and/or mail header injection, depending on how the application uses MailKit/MimeKit to construct and send messages. The issue becomes exploitable when the attacker can influence a MailboxAddress (MAIL FROM / RCPT TO) value that is later serialized to an SMTP session. RFC 5321 explicitly defines the SMTP mailbox local-part grammar and does not permit CR (13) or LF (10) inside Quoted-string (qtextSMTP and quoted-pairSMTP ranges exclude control characters). SMTP commands are terminated by <CRLF>, making CRLF injection in command arguments particularly dangerous. This issue has been patched in version 4.15.1."}]},{"artifact":{"id":"62e4fb8557f3510b","cpes":["cpe:2.3:a:_net_foundation:mimekit_.net:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:_net_foundation:mimekit:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:mimekit:mimekit_.net:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:mimekit:mimekit:4.14.0:*:*:*:*:*:*:*"],"name":"MimeKit","purl":"pkg:nuget/MimeKit@4.14.0","type":"dotnet","version":"4.14.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Host.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Host.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/MimeKit.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/MimeKit.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.15.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-g7hc-96xr-gvvx","versionConstraint":"<=4.15.0 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"MimeKit","version":"4.14.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-g7hc-96xr-gvvx","fix":{"state":"fixed","versions":["4.15.1"],"available":[{"date":"2026-03-06","kind":"first-observed","version":"4.15.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30227","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-30227","date":"2026-10-08","epss":0.0121,"percentile":0.67542}],"risk":0.71995,"urls":["https://github.com/jstedfast/MimeKit/security/advisories/GHSA-g7hc-96xr-gvvx","https://nvd.nist.gov/vuln/detail/CVE-2026-30227"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-g7hc-96xr-gvvx","description":"MimeKit has CRLF Injection in Quoted Local-Part that Enables SMTP Command Injection and Email Forgery"},"relatedVulnerabilities":[{"id":"CVE-2026-30227","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30227","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-30227","date":"2026-10-08","epss":0.0121,"percentile":0.67542}],"urls":["https://github.com/jstedfast/MimeKit/security/advisories/GHSA-g7hc-96xr-gvvx"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30227","description":"MimeKit is a C# library which may be used for the creation and parsing of messages using the Multipurpose Internet Mail Extension (MIME), as defined by numerous IETF specifications. Prior to version 4.15.1, a CRLF injection vulnerability in MimeKit allows an attacker to embed \\r\\n into the SMTP envelope address local-part (when the local-part is a quoted-string). This is non-compliant with RFC 5321 and can result in SMTP command injection (e.g., injecting additional RCPT TO / DATA / RSET commands) and/or mail header injection, depending on how the application uses MailKit/MimeKit to construct and send messages. The issue becomes exploitable when the attacker can influence a MailboxAddress (MAIL FROM / RCPT TO) value that is later serialized to an SMTP session. RFC 5321 explicitly defines the SMTP mailbox local-part grammar and does not permit CR (13) or LF (10) inside Quoted-string (qtextSMTP and quoted-pairSMTP ranges exclude control characters). SMTP commands are terminated by <CRLF>, making CRLF injection in command arguments particularly dangerous. This issue has been patched in version 4.15.1."}]},{"artifact":{"id":"5d8d38e13d92c0c1","cpes":["cpe:2.3:a:_net_foundation:mimekit_.net:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:_net_foundation:mimekit:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:mimekit:mimekit_.net:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:mimekit:mimekit:4.14.0:*:*:*:*:*:*:*"],"name":"MimeKit","purl":"pkg:nuget/MimeKit@4.14.0","type":"dotnet","version":"4.14.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Http.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Http.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/MimeKit.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/MimeKit.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.15.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-g7hc-96xr-gvvx","versionConstraint":"<=4.15.0 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"MimeKit","version":"4.14.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-g7hc-96xr-gvvx","fix":{"state":"fixed","versions":["4.15.1"],"available":[{"date":"2026-03-06","kind":"first-observed","version":"4.15.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30227","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-30227","date":"2026-10-08","epss":0.0121,"percentile":0.67542}],"risk":0.71995,"urls":["https://github.com/jstedfast/MimeKit/security/advisories/GHSA-g7hc-96xr-gvvx","https://nvd.nist.gov/vuln/detail/CVE-2026-30227"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-g7hc-96xr-gvvx","description":"MimeKit has CRLF Injection in Quoted Local-Part that Enables SMTP Command Injection and Email Forgery"},"relatedVulnerabilities":[{"id":"CVE-2026-30227","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30227","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-30227","date":"2026-10-08","epss":0.0121,"percentile":0.67542}],"urls":["https://github.com/jstedfast/MimeKit/security/advisories/GHSA-g7hc-96xr-gvvx"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30227","description":"MimeKit is a C# library which may be used for the creation and parsing of messages using the Multipurpose Internet Mail Extension (MIME), as defined by numerous IETF specifications. Prior to version 4.15.1, a CRLF injection vulnerability in MimeKit allows an attacker to embed \\r\\n into the SMTP envelope address local-part (when the local-part is a quoted-string). This is non-compliant with RFC 5321 and can result in SMTP command injection (e.g., injecting additional RCPT TO / DATA / RSET commands) and/or mail header injection, depending on how the application uses MailKit/MimeKit to construct and send messages. The issue becomes exploitable when the attacker can influence a MailboxAddress (MAIL FROM / RCPT TO) value that is later serialized to an SMTP session. RFC 5321 explicitly defines the SMTP mailbox local-part grammar and does not permit CR (13) or LF (10) inside Quoted-string (qtextSMTP and quoted-pairSMTP ranges exclude control characters). SMTP commands are terminated by <CRLF>, making CRLF injection in command arguments particularly dangerous. This issue has been patched in version 4.15.1."}]},{"artifact":{"id":"cd1d29bf30c1bae9","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.28.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64831","versionConstraint":">= 8.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64831","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64831","cwe":"CWE-121","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64831","date":"2026-10-08","epss":0.00851,"percentile":0.56929}],"risk":0.6914375,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/92737390dc133daadce47dd7d2ec8ef3d9ebcbed","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23665","https://www.vulncheck.com/advisories/ffmpeg-stack-buffer-overflow-in-vulkan-hevc-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64831","description":"FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"4173cf2fc659ac9d","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.12.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64831","versionConstraint":">= 8.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64831","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64831","cwe":"CWE-121","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64831","date":"2026-10-08","epss":0.00851,"percentile":0.56929}],"risk":0.6914375,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/92737390dc133daadce47dd7d2ec8ef3d9ebcbed","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23665","https://www.vulncheck.com/advisories/ffmpeg-stack-buffer-overflow-in-vulkan-hevc-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64831","description":"FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c11220a4fbbc883","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.26.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64831","versionConstraint":">= 8.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64831","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64831","cwe":"CWE-121","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64831","date":"2026-10-08","epss":0.00851,"percentile":0.56929}],"risk":0.6914375,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/92737390dc133daadce47dd7d2ec8ef3d9ebcbed","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23665","https://www.vulncheck.com/advisories/ffmpeg-stack-buffer-overflow-in-vulkan-hevc-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64831","description":"FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"a3d12aa6031708d4","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.3.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64831","versionConstraint":">= 8.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64831","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64831","cwe":"CWE-121","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64831","date":"2026-10-08","epss":0.00851,"percentile":0.56929}],"risk":0.6914375,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/92737390dc133daadce47dd7d2ec8ef3d9ebcbed","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23665","https://www.vulncheck.com/advisories/ffmpeg-stack-buffer-overflow-in-vulkan-hevc-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64831","description":"FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"cd1d29bf30c1bae9","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.28.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66040","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66040","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66040","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66040","date":"2026-10-08","epss":0.00776,"percentile":0.54427}],"risk":0.6311466666666667,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23786","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-png-apng-exif-encoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66040","description":"FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"4173cf2fc659ac9d","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.12.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66040","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66040","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66040","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66040","date":"2026-10-08","epss":0.00776,"percentile":0.54427}],"risk":0.6311466666666667,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23786","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-png-apng-exif-encoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66040","description":"FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c11220a4fbbc883","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.26.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66040","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66040","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66040","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66040","date":"2026-10-08","epss":0.00776,"percentile":0.54427}],"risk":0.6311466666666667,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23786","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-png-apng-exif-encoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66040","description":"FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"a3d12aa6031708d4","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.3.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66040","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66040","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66040","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66040","date":"2026-10-08","epss":0.00776,"percentile":0.54427}],"risk":0.6311466666666667,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23786","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-png-apng-exif-encoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66040","description":"FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"cd1d29bf30c1bae9","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.28.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64834","versionConstraint":">= 0.6.3, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64834","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64834","cwe":"CWE-835","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64834","date":"2026-10-08","epss":0.00727,"percentile":0.52717}],"risk":0.56706,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23663","https://www.vulncheck.com/advisories/ffmpeg-infinite-loop-dos-via-rtp-asf-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64834","description":"FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that denies service to legitimate users."},"relatedVulnerabilities":[]},{"artifact":{"id":"4173cf2fc659ac9d","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.12.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64834","versionConstraint":">= 0.6.3, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64834","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64834","cwe":"CWE-835","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64834","date":"2026-10-08","epss":0.00727,"percentile":0.52717}],"risk":0.56706,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23663","https://www.vulncheck.com/advisories/ffmpeg-infinite-loop-dos-via-rtp-asf-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64834","description":"FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that denies service to legitimate users."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c11220a4fbbc883","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.26.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64834","versionConstraint":">= 0.6.3, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64834","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64834","cwe":"CWE-835","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64834","date":"2026-10-08","epss":0.00727,"percentile":0.52717}],"risk":0.56706,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23663","https://www.vulncheck.com/advisories/ffmpeg-infinite-loop-dos-via-rtp-asf-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64834","description":"FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that denies service to legitimate users."},"relatedVulnerabilities":[]},{"artifact":{"id":"a3d12aa6031708d4","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.3.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64834","versionConstraint":">= 0.6.3, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64834","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64834","cwe":"CWE-835","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64834","date":"2026-10-08","epss":0.00727,"percentile":0.52717}],"risk":0.56706,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23663","https://www.vulncheck.com/advisories/ffmpeg-infinite-loop-dos-via-rtp-asf-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64834","description":"FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that denies service to legitimate users."},"relatedVulnerabilities":[]},{"artifact":{"id":"5072120da1bad992","cpes":["cpe:2.3:a:DaveGamble:cjson:1.7.19-r1:*:*:*:*:*:*:*","cpe:2.3:a:cjson:cjson:1.7.19-r1:*:*:*:*:*:*:*"],"name":"cjson","purl":"pkg:apk/alpine/cjson@1.7.19-r1?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"1.7.19-r1","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcjson.so.1"},{"path":"/usr/lib/libcjson.so.1.7.19"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"cjson"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-67215","versionConstraint":"<= 1.7.19 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:DaveGamble:cjson:1.7.19:*:*:*:*:*:*:*"],"package":{"name":"cjson","version":"1.7.19-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-67215","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-67215","cwe":"CWE-674","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-67215","date":"2026-10-08","epss":0.007,"percentile":0.51693}],"risk":0.546,"urls":["https://github.com/DaveGamble/cJSON/blob/v1.7.19/cJSON.c#L253-L261","https://github.com/DaveGamble/cJSON/blob/v1.7.19/cJSON_Utils.c#L906-L940","https://joshua.hu/cjson-json-parser-cve-vulnerabilities","https://www.vulncheck.com/advisories/cjson-json-patch-copy-add-uncontrolled-recursion-stack-exhaustion"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-67215","description":"cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operations grafts duplicated subtrees to amplify document depth beyond the parser's nesting limit: cJSON_Delete() recurses with no depth bound, and the cJSON_Duplicate() guard CJSON_CIRCULAR_LIMIT is set to 10000, ten times the parser's 1000-level nesting limit and high enough to overflow a default thread stack. An attacker who can supply the patch document can crash the process, resulting in denial of service."},"relatedVulnerabilities":[]},{"artifact":{"id":"cd1d29bf30c1bae9","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.28.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64830","versionConstraint":">= 2.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64830","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64830","cwe":"CWE-122","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64830","date":"2026-10-08","epss":0.00646,"percentile":0.49366}],"risk":0.524875,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23657","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-via-vobsub-subtitle-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64830","description":"FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer."},"relatedVulnerabilities":[]},{"artifact":{"id":"4173cf2fc659ac9d","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.12.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64830","versionConstraint":">= 2.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64830","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64830","cwe":"CWE-122","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64830","date":"2026-10-08","epss":0.00646,"percentile":0.49366}],"risk":0.524875,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23657","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-via-vobsub-subtitle-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64830","description":"FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c11220a4fbbc883","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.26.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64830","versionConstraint":">= 2.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64830","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64830","cwe":"CWE-122","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64830","date":"2026-10-08","epss":0.00646,"percentile":0.49366}],"risk":0.524875,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23657","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-via-vobsub-subtitle-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64830","description":"FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer."},"relatedVulnerabilities":[]},{"artifact":{"id":"a3d12aa6031708d4","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.3.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64830","versionConstraint":">= 2.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64830","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64830","cwe":"CWE-122","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64830","date":"2026-10-08","epss":0.00646,"percentile":0.49366}],"risk":0.524875,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23657","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-via-vobsub-subtitle-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64830","description":"FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer."},"relatedVulnerabilities":[]},{"artifact":{"id":"5072120da1bad992","cpes":["cpe:2.3:a:DaveGamble:cjson:1.7.19-r1:*:*:*:*:*:*:*","cpe:2.3:a:cjson:cjson:1.7.19-r1:*:*:*:*:*:*:*"],"name":"cjson","purl":"pkg:apk/alpine/cjson@1.7.19-r1?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"1.7.19-r1","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcjson.so.1"},{"path":"/usr/lib/libcjson.so.1.7.19"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"cjson"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-67216","versionConstraint":"<= 1.7.19 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:DaveGamble:cjson:1.7.19:*:*:*:*:*:*:*"],"package":{"name":"cjson","version":"1.7.19-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-67216","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-67216","cwe":"CWE-407","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-67216","date":"2026-10-08","epss":0.00645,"percentile":0.49346}],"risk":0.474075,"urls":["https://github.com/DaveGamble/cJSON/blob/v1.7.19/cJSON.c#L3057-L3180","https://joshua.hu/cjson-json-parser-cve-vulnerabilities","https://www.vulncheck.com/advisories/cjson-cjson-compare-exponential-complexity-denial-of-service"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-67216","description":"cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each shared subtree twice, once in each direction, with no depth guard, making the running time exponential in nesting depth. A small, deeply nested document of a few hundred bytes (depth around 40) compared for equality consumes hours of CPU, and the cost roughly doubles with each additional level of nesting. An application that calls cJSON_Compare() on attacker-influenced JSON that is structurally equal to a reference document is exposed to a denial-of-service condition."},"relatedVulnerabilities":[]},{"artifact":{"id":"cd1d29bf30c1bae9","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.28.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64835","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64835","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64835","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64835","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.40299999999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23659","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-memory-access-in-adx-audio-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64835","description":"FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count."},"relatedVulnerabilities":[]},{"artifact":{"id":"4173cf2fc659ac9d","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.12.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64835","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64835","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64835","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64835","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.40299999999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23659","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-memory-access-in-adx-audio-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64835","description":"FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c11220a4fbbc883","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.26.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64835","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64835","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64835","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64835","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.40299999999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23659","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-memory-access-in-adx-audio-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64835","description":"FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count."},"relatedVulnerabilities":[]},{"artifact":{"id":"a3d12aa6031708d4","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.3.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64835","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64835","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64835","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64835","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.40299999999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23659","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-memory-access-in-adx-audio-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64835","description":"FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count."},"relatedVulnerabilities":[]},{"artifact":{"id":"cd1d29bf30c1bae9","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.28.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66036","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66036","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66036","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66036","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.3951466666666666,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-vf-hqdn3d-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66036","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption."},"relatedVulnerabilities":[]},{"artifact":{"id":"4173cf2fc659ac9d","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.12.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66036","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66036","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66036","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66036","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.3951466666666666,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-vf-hqdn3d-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66036","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c11220a4fbbc883","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.26.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66036","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66036","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66036","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66036","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.3951466666666666,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-vf-hqdn3d-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66036","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption."},"relatedVulnerabilities":[]},{"artifact":{"id":"a3d12aa6031708d4","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.3.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66036","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66036","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66036","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66036","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.3951466666666666,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-vf-hqdn3d-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66036","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption."},"relatedVulnerabilities":[]},{"artifact":{"id":"cd1d29bf30c1bae9","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.28.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66041","versionConstraint":">= 7.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66041","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66041","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66041","date":"2026-10-08","epss":0.00487,"percentile":0.40005}],"risk":0.37986000000000003,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4da9812e25894fb51d62a8875cfa8eb39b5e20f5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23625","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-vf-quirc-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66041","description":"FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a subtitle file whose second presentation has larger dimensions than its first, causing av_image_copy_plane() to copy data exceeding the initial allocation size into the undersized libquirc grayscale image buffer, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"4173cf2fc659ac9d","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.12.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66041","versionConstraint":">= 7.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66041","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66041","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66041","date":"2026-10-08","epss":0.00487,"percentile":0.40005}],"risk":0.37986000000000003,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4da9812e25894fb51d62a8875cfa8eb39b5e20f5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23625","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-vf-quirc-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66041","description":"FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a subtitle file whose second presentation has larger dimensions than its first, causing av_image_copy_plane() to copy data exceeding the initial allocation size into the undersized libquirc grayscale image buffer, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c11220a4fbbc883","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.26.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66041","versionConstraint":">= 7.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66041","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66041","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66041","date":"2026-10-08","epss":0.00487,"percentile":0.40005}],"risk":0.37986000000000003,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4da9812e25894fb51d62a8875cfa8eb39b5e20f5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23625","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-vf-quirc-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66041","description":"FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a subtitle file whose second presentation has larger dimensions than its first, causing av_image_copy_plane() to copy data exceeding the initial allocation size into the undersized libquirc grayscale image buffer, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"a3d12aa6031708d4","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.3.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66041","versionConstraint":">= 7.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66041","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66041","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66041","date":"2026-10-08","epss":0.00487,"percentile":0.40005}],"risk":0.37986000000000003,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4da9812e25894fb51d62a8875cfa8eb39b5e20f5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23625","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-vf-quirc-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66041","description":"FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a subtitle file whose second presentation has larger dimensions than its first, causing av_image_copy_plane() to copy data exceeding the initial allocation size into the undersized libquirc grayscale image buffer, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"cd1d29bf30c1bae9","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.28.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66039","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66039","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66039","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-66039","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66039","date":"2026-10-08","epss":0.0044,"percentile":0.362}],"risk":0.35053333333333336,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23631","https://www.vulncheck.com/advisories/ffmpeg-mace6-audio-decoder-heap-out-of-bounds-write-via-caf-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66039","description":"FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"4173cf2fc659ac9d","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.12.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66039","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66039","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66039","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-66039","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66039","date":"2026-10-08","epss":0.0044,"percentile":0.362}],"risk":0.35053333333333336,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23631","https://www.vulncheck.com/advisories/ffmpeg-mace6-audio-decoder-heap-out-of-bounds-write-via-caf-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66039","description":"FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c11220a4fbbc883","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.26.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66039","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66039","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66039","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-66039","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66039","date":"2026-10-08","epss":0.0044,"percentile":0.362}],"risk":0.35053333333333336,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23631","https://www.vulncheck.com/advisories/ffmpeg-mace6-audio-decoder-heap-out-of-bounds-write-via-caf-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66039","description":"FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"a3d12aa6031708d4","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.3.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66039","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66039","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66039","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-66039","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66039","date":"2026-10-08","epss":0.0044,"percentile":0.362}],"risk":0.35053333333333336,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23631","https://www.vulncheck.com/advisories/ffmpeg-mace6-audio-decoder-heap-out-of-bounds-write-via-caf-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66039","description":"FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"cd1d29bf30c1bae9","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.28.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64833","versionConstraint":">= 0.7.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64833","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64833","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64833","date":"2026-10-08","epss":0.00396,"percentile":0.31662}],"risk":0.28908,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23661","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-via-s-pdif-muxer-spdifenc-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64833","description":"FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"4173cf2fc659ac9d","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.12.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64833","versionConstraint":">= 0.7.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64833","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64833","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64833","date":"2026-10-08","epss":0.00396,"percentile":0.31662}],"risk":0.28908,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23661","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-via-s-pdif-muxer-spdifenc-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64833","description":"FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c11220a4fbbc883","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.26.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64833","versionConstraint":">= 0.7.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64833","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64833","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64833","date":"2026-10-08","epss":0.00396,"percentile":0.31662}],"risk":0.28908,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23661","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-via-s-pdif-muxer-spdifenc-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64833","description":"FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"a3d12aa6031708d4","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.3.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64833","versionConstraint":">= 0.7.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64833","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64833","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64833","date":"2026-10-08","epss":0.00396,"percentile":0.31662}],"risk":0.28908,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23661","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-via-s-pdif-muxer-spdifenc-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64833","description":"FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"cd1d29bf30c1bae9","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.28.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64832","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64832","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64832","cwe":"CWE-415","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64832","date":"2026-10-08","epss":0.00335,"percentile":0.24797}],"risk":0.27218749999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23664","https://www.vulncheck.com/advisories/ffmpeg-double-free-in-nvdec-hardware-decoder-via-nvdec-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64832","description":"FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding."},"relatedVulnerabilities":[]},{"artifact":{"id":"4173cf2fc659ac9d","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.12.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64832","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64832","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64832","cwe":"CWE-415","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64832","date":"2026-10-08","epss":0.00335,"percentile":0.24797}],"risk":0.27218749999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23664","https://www.vulncheck.com/advisories/ffmpeg-double-free-in-nvdec-hardware-decoder-via-nvdec-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64832","description":"FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c11220a4fbbc883","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.26.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64832","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64832","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64832","cwe":"CWE-415","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64832","date":"2026-10-08","epss":0.00335,"percentile":0.24797}],"risk":0.27218749999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23664","https://www.vulncheck.com/advisories/ffmpeg-double-free-in-nvdec-hardware-decoder-via-nvdec-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64832","description":"FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding."},"relatedVulnerabilities":[]},{"artifact":{"id":"a3d12aa6031708d4","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.3.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64832","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64832","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64832","cwe":"CWE-415","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64832","date":"2026-10-08","epss":0.00335,"percentile":0.24797}],"risk":0.27218749999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23664","https://www.vulncheck.com/advisories/ffmpeg-double-free-in-nvdec-hardware-decoder-via-nvdec-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64832","description":"FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding."},"relatedVulnerabilities":[]},{"artifact":{"id":"75b9753b56f635f4","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.SignalR.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.SignalR.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j3p4-wp97-rph4","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-j3p4-wp97-rph4","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106113","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106113","date":"2026-10-08","epss":0.0035,"percentile":0.266}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j3p4-wp97-rph4","https://nvd.nist.gov/vuln/detail/CVE-2026-106113","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/c4c4bf292298c026df470db1a17ff826515fd95d","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j3p4-wp97-rph4","description":"ImageSharp: HistogramEqualization uses an unvalidated luminance as an unchecked histogram index"},"relatedVulnerabilities":[{"id":"CVE-2026-106113","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106113","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106113","date":"2026-10-08","epss":0.0035,"percentile":0.266}],"urls":["https://github.com/SixLabors/ImageSharp/commit/c4c4bf292298c026df470db1a17ff826515fd95d","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j3p4-wp97-rph4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106113","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, decoding an attacker-supplied 32-bit floating-point TIFF as Image<HalfVector4> and applying HistogramEqualization can produce a non-finite or out-of-range luminance in ColorNumerics.GetBT709Luminance. GrayscaleLevelsRowOperation.Invoke uses the resulting value as an unchecked histogram offset, causing an unsafe out-of-range access and process termination. Adaptive Histogram Equalization and AutoLevel are not affected by this report. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"ebfa5695b11b7ea8","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j3p4-wp97-rph4","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-j3p4-wp97-rph4","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106113","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106113","date":"2026-10-08","epss":0.0035,"percentile":0.266}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j3p4-wp97-rph4","https://nvd.nist.gov/vuln/detail/CVE-2026-106113","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/c4c4bf292298c026df470db1a17ff826515fd95d","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j3p4-wp97-rph4","description":"ImageSharp: HistogramEqualization uses an unvalidated luminance as an unchecked histogram index"},"relatedVulnerabilities":[{"id":"CVE-2026-106113","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106113","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106113","date":"2026-10-08","epss":0.0035,"percentile":0.266}],"urls":["https://github.com/SixLabors/ImageSharp/commit/c4c4bf292298c026df470db1a17ff826515fd95d","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j3p4-wp97-rph4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106113","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, decoding an attacker-supplied 32-bit floating-point TIFF as Image<HalfVector4> and applying HistogramEqualization can produce a non-finite or out-of-range luminance in ColorNumerics.GetBT709Luminance. GrayscaleLevelsRowOperation.Invoke uses the resulting value as an unchecked histogram offset, causing an unsafe out-of-range access and process termination. Adaptive Histogram Equalization and AutoLevel are not affected by this report. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"7d1ad195f96bf365","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Api.V1.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Api.V1.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j3p4-wp97-rph4","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-j3p4-wp97-rph4","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106113","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106113","date":"2026-10-08","epss":0.0035,"percentile":0.266}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j3p4-wp97-rph4","https://nvd.nist.gov/vuln/detail/CVE-2026-106113","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/c4c4bf292298c026df470db1a17ff826515fd95d","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j3p4-wp97-rph4","description":"ImageSharp: HistogramEqualization uses an unvalidated luminance as an unchecked histogram index"},"relatedVulnerabilities":[{"id":"CVE-2026-106113","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106113","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106113","date":"2026-10-08","epss":0.0035,"percentile":0.266}],"urls":["https://github.com/SixLabors/ImageSharp/commit/c4c4bf292298c026df470db1a17ff826515fd95d","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j3p4-wp97-rph4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106113","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, decoding an attacker-supplied 32-bit floating-point TIFF as Image<HalfVector4> and applying HistogramEqualization can produce a non-finite or out-of-range luminance in ColorNumerics.GetBT709Luminance. GrayscaleLevelsRowOperation.Invoke uses the resulting value as an unchecked histogram offset, causing an unsafe out-of-range access and process termination. Adaptive Histogram Equalization and AutoLevel are not affected by this report. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"3e3b14319bc01e58","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Core.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Core.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j3p4-wp97-rph4","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-j3p4-wp97-rph4","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106113","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106113","date":"2026-10-08","epss":0.0035,"percentile":0.266}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j3p4-wp97-rph4","https://nvd.nist.gov/vuln/detail/CVE-2026-106113","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/c4c4bf292298c026df470db1a17ff826515fd95d","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j3p4-wp97-rph4","description":"ImageSharp: HistogramEqualization uses an unvalidated luminance as an unchecked histogram index"},"relatedVulnerabilities":[{"id":"CVE-2026-106113","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106113","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106113","date":"2026-10-08","epss":0.0035,"percentile":0.266}],"urls":["https://github.com/SixLabors/ImageSharp/commit/c4c4bf292298c026df470db1a17ff826515fd95d","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j3p4-wp97-rph4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106113","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, decoding an attacker-supplied 32-bit floating-point TIFF as Image<HalfVector4> and applying HistogramEqualization can produce a non-finite or out-of-range luminance in ColorNumerics.GetBT709Luminance. GrayscaleLevelsRowOperation.Invoke uses the resulting value as an unchecked histogram offset, causing an unsafe out-of-range access and process termination. Adaptive Histogram Equalization and AutoLevel are not affected by this report. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"27074e88c8facc24","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Host.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Host.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j3p4-wp97-rph4","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-j3p4-wp97-rph4","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106113","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106113","date":"2026-10-08","epss":0.0035,"percentile":0.266}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j3p4-wp97-rph4","https://nvd.nist.gov/vuln/detail/CVE-2026-106113","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/c4c4bf292298c026df470db1a17ff826515fd95d","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j3p4-wp97-rph4","description":"ImageSharp: HistogramEqualization uses an unvalidated luminance as an unchecked histogram index"},"relatedVulnerabilities":[{"id":"CVE-2026-106113","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106113","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106113","date":"2026-10-08","epss":0.0035,"percentile":0.266}],"urls":["https://github.com/SixLabors/ImageSharp/commit/c4c4bf292298c026df470db1a17ff826515fd95d","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j3p4-wp97-rph4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106113","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, decoding an attacker-supplied 32-bit floating-point TIFF as Image<HalfVector4> and applying HistogramEqualization can produce a non-finite or out-of-range luminance in ColorNumerics.GetBT709Luminance. GrayscaleLevelsRowOperation.Invoke uses the resulting value as an unchecked histogram offset, causing an unsafe out-of-range access and process termination. Adaptive Histogram Equalization and AutoLevel are not affected by this report. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"17272c7abf1a8571","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Http.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Http.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j3p4-wp97-rph4","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-j3p4-wp97-rph4","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106113","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106113","date":"2026-10-08","epss":0.0035,"percentile":0.266}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j3p4-wp97-rph4","https://nvd.nist.gov/vuln/detail/CVE-2026-106113","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/c4c4bf292298c026df470db1a17ff826515fd95d","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j3p4-wp97-rph4","description":"ImageSharp: HistogramEqualization uses an unvalidated luminance as an unchecked histogram index"},"relatedVulnerabilities":[{"id":"CVE-2026-106113","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106113","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106113","date":"2026-10-08","epss":0.0035,"percentile":0.266}],"urls":["https://github.com/SixLabors/ImageSharp/commit/c4c4bf292298c026df470db1a17ff826515fd95d","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j3p4-wp97-rph4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106113","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, decoding an attacker-supplied 32-bit floating-point TIFF as Image<HalfVector4> and applying HistogramEqualization can produce a non-finite or out-of-range luminance in ColorNumerics.GetBT709Luminance. GrayscaleLevelsRowOperation.Invoke uses the resulting value as an unchecked histogram offset, causing an unsafe out-of-range access and process termination. Adaptive Histogram Equalization and AutoLevel are not affected by this report. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"75b9753b56f635f4","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.SignalR.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.SignalR.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j9gm-c75j-xc9q","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-j9gm-c75j-xc9q","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106110","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106110","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j9gm-c75j-xc9q","https://nvd.nist.gov/vuln/detail/CVE-2026-106110","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j9gm-c75j-xc9q","description":"ImageSharp: TIFF CCITT T4 encoder can write past its compressed output buffer"},"relatedVulnerabilities":[{"id":"CVE-2026-106110","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106110","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106110","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"urls":["https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j9gm-c75j-xc9q"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106110","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Group 3 encoder allocates an undersized compressed-data buffer for narrow 1-bit images. TiffCcittCompressor.Initialize does not reserve enough space for the row data and T4 end-of-line codes, and T4BitCompressor.CompressStrip reaches unchecked writes when TiffCompression.CcittGroup3Fax is selected directly or inherited from decoded TIFF metadata. An attacker-controlled encode or decode-and-re-encode flow can write beyond the logical output span, corrupt process memory, and terminate the process. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"ebfa5695b11b7ea8","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j9gm-c75j-xc9q","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-j9gm-c75j-xc9q","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106110","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106110","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j9gm-c75j-xc9q","https://nvd.nist.gov/vuln/detail/CVE-2026-106110","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j9gm-c75j-xc9q","description":"ImageSharp: TIFF CCITT T4 encoder can write past its compressed output buffer"},"relatedVulnerabilities":[{"id":"CVE-2026-106110","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106110","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106110","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"urls":["https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j9gm-c75j-xc9q"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106110","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Group 3 encoder allocates an undersized compressed-data buffer for narrow 1-bit images. TiffCcittCompressor.Initialize does not reserve enough space for the row data and T4 end-of-line codes, and T4BitCompressor.CompressStrip reaches unchecked writes when TiffCompression.CcittGroup3Fax is selected directly or inherited from decoded TIFF metadata. An attacker-controlled encode or decode-and-re-encode flow can write beyond the logical output span, corrupt process memory, and terminate the process. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"17272c7abf1a8571","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Http.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Http.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j9gm-c75j-xc9q","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-j9gm-c75j-xc9q","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106110","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106110","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j9gm-c75j-xc9q","https://nvd.nist.gov/vuln/detail/CVE-2026-106110","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j9gm-c75j-xc9q","description":"ImageSharp: TIFF CCITT T4 encoder can write past its compressed output buffer"},"relatedVulnerabilities":[{"id":"CVE-2026-106110","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106110","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106110","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"urls":["https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j9gm-c75j-xc9q"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106110","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Group 3 encoder allocates an undersized compressed-data buffer for narrow 1-bit images. TiffCcittCompressor.Initialize does not reserve enough space for the row data and T4 end-of-line codes, and T4BitCompressor.CompressStrip reaches unchecked writes when TiffCompression.CcittGroup3Fax is selected directly or inherited from decoded TIFF metadata. An attacker-controlled encode or decode-and-re-encode flow can write beyond the logical output span, corrupt process memory, and terminate the process. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"27074e88c8facc24","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Host.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Host.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j9gm-c75j-xc9q","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-j9gm-c75j-xc9q","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106110","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106110","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j9gm-c75j-xc9q","https://nvd.nist.gov/vuln/detail/CVE-2026-106110","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j9gm-c75j-xc9q","description":"ImageSharp: TIFF CCITT T4 encoder can write past its compressed output buffer"},"relatedVulnerabilities":[{"id":"CVE-2026-106110","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106110","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106110","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"urls":["https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j9gm-c75j-xc9q"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106110","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Group 3 encoder allocates an undersized compressed-data buffer for narrow 1-bit images. TiffCcittCompressor.Initialize does not reserve enough space for the row data and T4 end-of-line codes, and T4BitCompressor.CompressStrip reaches unchecked writes when TiffCompression.CcittGroup3Fax is selected directly or inherited from decoded TIFF metadata. An attacker-controlled encode or decode-and-re-encode flow can write beyond the logical output span, corrupt process memory, and terminate the process. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"3e3b14319bc01e58","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Core.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Core.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j9gm-c75j-xc9q","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-j9gm-c75j-xc9q","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106110","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106110","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j9gm-c75j-xc9q","https://nvd.nist.gov/vuln/detail/CVE-2026-106110","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j9gm-c75j-xc9q","description":"ImageSharp: TIFF CCITT T4 encoder can write past its compressed output buffer"},"relatedVulnerabilities":[{"id":"CVE-2026-106110","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106110","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106110","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"urls":["https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j9gm-c75j-xc9q"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106110","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Group 3 encoder allocates an undersized compressed-data buffer for narrow 1-bit images. TiffCcittCompressor.Initialize does not reserve enough space for the row data and T4 end-of-line codes, and T4BitCompressor.CompressStrip reaches unchecked writes when TiffCompression.CcittGroup3Fax is selected directly or inherited from decoded TIFF metadata. An attacker-controlled encode or decode-and-re-encode flow can write beyond the logical output span, corrupt process memory, and terminate the process. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"7d1ad195f96bf365","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Api.V1.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Api.V1.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j9gm-c75j-xc9q","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-j9gm-c75j-xc9q","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106110","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106110","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j9gm-c75j-xc9q","https://nvd.nist.gov/vuln/detail/CVE-2026-106110","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j9gm-c75j-xc9q","description":"ImageSharp: TIFF CCITT T4 encoder can write past its compressed output buffer"},"relatedVulnerabilities":[{"id":"CVE-2026-106110","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106110","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106110","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"urls":["https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j9gm-c75j-xc9q"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106110","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Group 3 encoder allocates an undersized compressed-data buffer for narrow 1-bit images. TiffCcittCompressor.Initialize does not reserve enough space for the row data and T4 end-of-line codes, and T4BitCompressor.CompressStrip reaches unchecked writes when TiffCompression.CcittGroup3Fax is selected directly or inherited from decoded TIFF metadata. An attacker-controlled encode or decode-and-re-encode flow can write beyond the logical output span, corrupt process memory, and terminate the process. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"7d1ad195f96bf365","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Api.V1.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Api.V1.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jjfr-hcj7-qf5w","versionConstraint":">=2.1.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-jjfr-hcj7-qf5w","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106115","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106115","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-jjfr-hcj7-qf5w","https://nvd.nist.gov/vuln/detail/CVE-2026-106115","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jjfr-hcj7-qf5w","description":"ImageSharp: TIFF CCITT T6 encoder writes beyond an undersized output buffer"},"relatedVulnerabilities":[{"id":"CVE-2026-106115","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106115","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106115","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"urls":["https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-jjfr-hcj7-qf5w"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106115","description":"ImageSharp is a 2D graphics library. From 2.1.0 until 4.1.2, the TIFF CCITT Group 4 encoder allocates Width times rowsPerStrip bytes even though T6BitCompressor.CompressStrip can emit encoded row data and two 12-bit end-of-facsimile-block codes beyond that capacity. TiffCcittCompressor.WriteCode performs unchecked writes, and a decode-and-re-encode flow can inherit TiffCompression.CcittGroup4Fax and one-bit metadata from attacker-supplied input. The resulting out-of-bounds writes can corrupt memory and terminate the process. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"3e3b14319bc01e58","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Core.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Core.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jjfr-hcj7-qf5w","versionConstraint":">=2.1.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-jjfr-hcj7-qf5w","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106115","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106115","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-jjfr-hcj7-qf5w","https://nvd.nist.gov/vuln/detail/CVE-2026-106115","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jjfr-hcj7-qf5w","description":"ImageSharp: TIFF CCITT T6 encoder writes beyond an undersized output buffer"},"relatedVulnerabilities":[{"id":"CVE-2026-106115","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106115","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106115","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"urls":["https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-jjfr-hcj7-qf5w"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106115","description":"ImageSharp is a 2D graphics library. From 2.1.0 until 4.1.2, the TIFF CCITT Group 4 encoder allocates Width times rowsPerStrip bytes even though T6BitCompressor.CompressStrip can emit encoded row data and two 12-bit end-of-facsimile-block codes beyond that capacity. TiffCcittCompressor.WriteCode performs unchecked writes, and a decode-and-re-encode flow can inherit TiffCompression.CcittGroup4Fax and one-bit metadata from attacker-supplied input. The resulting out-of-bounds writes can corrupt memory and terminate the process. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"27074e88c8facc24","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Host.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Host.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jjfr-hcj7-qf5w","versionConstraint":">=2.1.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-jjfr-hcj7-qf5w","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106115","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106115","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-jjfr-hcj7-qf5w","https://nvd.nist.gov/vuln/detail/CVE-2026-106115","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jjfr-hcj7-qf5w","description":"ImageSharp: TIFF CCITT T6 encoder writes beyond an undersized output buffer"},"relatedVulnerabilities":[{"id":"CVE-2026-106115","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106115","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106115","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"urls":["https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-jjfr-hcj7-qf5w"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106115","description":"ImageSharp is a 2D graphics library. From 2.1.0 until 4.1.2, the TIFF CCITT Group 4 encoder allocates Width times rowsPerStrip bytes even though T6BitCompressor.CompressStrip can emit encoded row data and two 12-bit end-of-facsimile-block codes beyond that capacity. TiffCcittCompressor.WriteCode performs unchecked writes, and a decode-and-re-encode flow can inherit TiffCompression.CcittGroup4Fax and one-bit metadata from attacker-supplied input. The resulting out-of-bounds writes can corrupt memory and terminate the process. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"17272c7abf1a8571","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Http.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Http.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jjfr-hcj7-qf5w","versionConstraint":">=2.1.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-jjfr-hcj7-qf5w","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106115","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106115","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-jjfr-hcj7-qf5w","https://nvd.nist.gov/vuln/detail/CVE-2026-106115","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jjfr-hcj7-qf5w","description":"ImageSharp: TIFF CCITT T6 encoder writes beyond an undersized output buffer"},"relatedVulnerabilities":[{"id":"CVE-2026-106115","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106115","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106115","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"urls":["https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-jjfr-hcj7-qf5w"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106115","description":"ImageSharp is a 2D graphics library. From 2.1.0 until 4.1.2, the TIFF CCITT Group 4 encoder allocates Width times rowsPerStrip bytes even though T6BitCompressor.CompressStrip can emit encoded row data and two 12-bit end-of-facsimile-block codes beyond that capacity. TiffCcittCompressor.WriteCode performs unchecked writes, and a decode-and-re-encode flow can inherit TiffCompression.CcittGroup4Fax and one-bit metadata from attacker-supplied input. The resulting out-of-bounds writes can corrupt memory and terminate the process. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"75b9753b56f635f4","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.SignalR.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.SignalR.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jjfr-hcj7-qf5w","versionConstraint":">=2.1.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-jjfr-hcj7-qf5w","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106115","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106115","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-jjfr-hcj7-qf5w","https://nvd.nist.gov/vuln/detail/CVE-2026-106115","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jjfr-hcj7-qf5w","description":"ImageSharp: TIFF CCITT T6 encoder writes beyond an undersized output buffer"},"relatedVulnerabilities":[{"id":"CVE-2026-106115","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106115","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106115","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"urls":["https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-jjfr-hcj7-qf5w"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106115","description":"ImageSharp is a 2D graphics library. From 2.1.0 until 4.1.2, the TIFF CCITT Group 4 encoder allocates Width times rowsPerStrip bytes even though T6BitCompressor.CompressStrip can emit encoded row data and two 12-bit end-of-facsimile-block codes beyond that capacity. TiffCcittCompressor.WriteCode performs unchecked writes, and a decode-and-re-encode flow can inherit TiffCompression.CcittGroup4Fax and one-bit metadata from attacker-supplied input. The resulting out-of-bounds writes can corrupt memory and terminate the process. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"ebfa5695b11b7ea8","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jjfr-hcj7-qf5w","versionConstraint":">=2.1.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-jjfr-hcj7-qf5w","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106115","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106115","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-jjfr-hcj7-qf5w","https://nvd.nist.gov/vuln/detail/CVE-2026-106115","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jjfr-hcj7-qf5w","description":"ImageSharp: TIFF CCITT T6 encoder writes beyond an undersized output buffer"},"relatedVulnerabilities":[{"id":"CVE-2026-106115","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106115","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106115","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"urls":["https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-jjfr-hcj7-qf5w"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106115","description":"ImageSharp is a 2D graphics library. From 2.1.0 until 4.1.2, the TIFF CCITT Group 4 encoder allocates Width times rowsPerStrip bytes even though T6BitCompressor.CompressStrip can emit encoded row data and two 12-bit end-of-facsimile-block codes beyond that capacity. TiffCcittCompressor.WriteCode performs unchecked writes, and a decode-and-re-encode flow can inherit TiffCompression.CcittGroup4Fax and one-bit metadata from attacker-supplied input. The resulting out-of-bounds writes can corrupt memory and terminate the process. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"cd1d29bf30c1bae9","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.28.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66038","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66038","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66038","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66038","date":"2026-10-08","epss":0.00439,"percentile":0.36186}],"risk":0.256815,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23626","https://www.vulncheck.com/advisories/ffmpeg-lcl-zlib-video-decoder-information-disclosure-via-lcldec-c"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66038","description":"FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services."},"relatedVulnerabilities":[]},{"artifact":{"id":"4173cf2fc659ac9d","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.12.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66038","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66038","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66038","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66038","date":"2026-10-08","epss":0.00439,"percentile":0.36186}],"risk":0.256815,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23626","https://www.vulncheck.com/advisories/ffmpeg-lcl-zlib-video-decoder-information-disclosure-via-lcldec-c"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66038","description":"FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c11220a4fbbc883","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.26.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66038","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66038","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66038","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66038","date":"2026-10-08","epss":0.00439,"percentile":0.36186}],"risk":0.256815,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23626","https://www.vulncheck.com/advisories/ffmpeg-lcl-zlib-video-decoder-information-disclosure-via-lcldec-c"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66038","description":"FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services."},"relatedVulnerabilities":[]},{"artifact":{"id":"a3d12aa6031708d4","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.3.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66038","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66038","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66038","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66038","date":"2026-10-08","epss":0.00439,"percentile":0.36186}],"risk":0.256815,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23626","https://www.vulncheck.com/advisories/ffmpeg-lcl-zlib-video-decoder-information-disclosure-via-lcldec-c"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66038","description":"FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services."},"relatedVulnerabilities":[]},{"artifact":{"id":"5072120da1bad992","cpes":["cpe:2.3:a:DaveGamble:cjson:1.7.19-r1:*:*:*:*:*:*:*","cpe:2.3:a:cjson:cjson:1.7.19-r1:*:*:*:*:*:*:*"],"name":"cjson","purl":"pkg:apk/alpine/cjson@1.7.19-r1?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"1.7.19-r1","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcjson.so.1"},{"path":"/usr/lib/libcjson.so.1.7.19"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"cjson"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-67217","versionConstraint":"<= 1.7.19 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:DaveGamble:cjson:1.7.19:*:*:*:*:*:*:*"],"package":{"name":"cjson","version":"1.7.19-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-67217","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-67217","cwe":"CWE-696","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-67217","date":"2026-10-08","epss":0.00433,"percentile":0.35564}],"risk":0.24031499999999997,"urls":["https://github.com/DaveGamble/cJSON/blob/v1.7.19/cJSON_Utils.c#L887-L948","https://joshua.hu/cjson-json-parser-cve-vulnerabilities","https://www.vulncheck.com/advisories/cjson-json-patch-non-atomic-application-destroys-data-before-validation"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-67217","description":"cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing its value member, or a move operation whose destination path cannot be resolved, the existing target member is detached and deleted before the operation is fully validated, so the target document is mutated while cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive() returns a failure status. An attacker who can supply the patch document can destroy addressable members of the target document even though the API reports that the patch failed, defeating the all-or-nothing behavior callers rely on to reject bad patches."},"relatedVulnerabilities":[]},{"artifact":{"id":"cd1d29bf30c1bae9","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.28.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65703","versionConstraint":">= 2.7, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65703","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65703","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65703","date":"2026-10-08","epss":0.00292,"percentile":0.19919}],"risk":0.22849,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-tdsc-video-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65703","description":"FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"4173cf2fc659ac9d","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.12.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65703","versionConstraint":">= 2.7, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65703","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65703","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65703","date":"2026-10-08","epss":0.00292,"percentile":0.19919}],"risk":0.22849,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-tdsc-video-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65703","description":"FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c11220a4fbbc883","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.26.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65703","versionConstraint":">= 2.7, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65703","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65703","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65703","date":"2026-10-08","epss":0.00292,"percentile":0.19919}],"risk":0.22849,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-tdsc-video-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65703","description":"FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"a3d12aa6031708d4","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.3.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65703","versionConstraint":">= 2.7, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65703","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65703","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65703","date":"2026-10-08","epss":0.00292,"percentile":0.19919}],"risk":0.22849,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-tdsc-video-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65703","description":"FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"5072120da1bad992","cpes":["cpe:2.3:a:DaveGamble:cjson:1.7.19-r1:*:*:*:*:*:*:*","cpe:2.3:a:cjson:cjson:1.7.19-r1:*:*:*:*:*:*:*"],"name":"cjson","purl":"pkg:apk/alpine/cjson@1.7.19-r1?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"1.7.19-r1","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcjson.so.1"},{"path":"/usr/lib/libcjson.so.1.7.19"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"cjson"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-16554","versionConstraint":"= 1.7.19 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:DaveGamble:cjson:1.7.19:*:*:*:*:*:*:*"],"package":{"name":"cjson","version":"1.7.19-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-16554","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16554","cwe":"CWE-190","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-16554","date":"2026-10-08","epss":0.00291,"percentile":0.19897}],"risk":0.2029725,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-16554","https://github.com/DaveGamble/cJSON","http://www.openwall.com/lists/oss-security/2026/07/30/26","http://www.openwall.com/lists/oss-security/2026/07/31/4"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16554","description":"cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms. The escape_characters counter, a 32-bit size_t, can wrap around when processing strings containing approximately 858,993,460 or more control characters, causing the output buffer to be allocated based on an underestimated length. When cJSON_PrintBuffered() is used with a pre-allocated buffer, the subsequent write loop overflows the heap allocation. An attacker supplying a crafted JSON string to an application using cJSON on a 32-bit platform can cause a heap buffer overflow, potentially leading to remote code execution, information disclosure, or denial of service.\n\n\n\n\nBecause project creator contact attempts were unsuccessful, the vulnerability has only been confirmed in version 1.7.19 but may also affect other versions."},"relatedVulnerabilities":[]},{"artifact":{"id":"6921667c3af65467","cpes":["cpe:2.3:a:coreutils:coreutils:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:apk/alpine/coreutils@9.11-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/base64"},{"path":"/bin/cat"},{"path":"/bin/chgrp"},{"path":"/bin/chmod"},{"path":"/bin/chown"},{"path":"/bin/coreutils"},{"path":"/bin/cp"},{"path":"/bin/date"},{"path":"/bin/dd"},{"path":"/bin/df"},{"path":"/bin/echo"},{"path":"/bin/false"},{"path":"/bin/link"},{"path":"/bin/ln"},{"path":"/bin/ls"},{"path":"/bin/mkdir"},{"path":"/bin/mknod"},{"path":"/bin/mktemp"},{"path":"/bin/mv"},{"path":"/bin/nice"},{"path":"/bin/printenv"},{"path":"/bin/pwd"},{"path":"/bin/rm"},{"path":"/bin/rmdir"},{"path":"/bin/sleep"},{"path":"/bin/stat"},{"path":"/bin/stty"},{"path":"/bin/sync"},{"path":"/bin/touch"},{"path":"/bin/true"},{"path":"/bin/uname"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/["},{"path":"/usr/bin/b2sum"},{"path":"/usr/bin/base32"},{"path":"/usr/bin/basename"},{"path":"/usr/bin/basenc"},{"path":"/usr/bin/cksum"},{"path":"/usr/bin/comm"},{"path":"/usr/bin/csplit"},{"path":"/usr/bin/cut"},{"path":"/usr/bin/dir"},{"path":"/usr/bin/dircolors"},{"path":"/usr/bin/dirname"},{"path":"/usr/bin/du"},{"path":"/usr/bin/expand"},{"path":"/usr/bin/expr"},{"path":"/usr/bin/factor"},{"path":"/usr/bin/fold"},{"path":"/usr/bin/head"},{"path":"/usr/bin/hostid"},{"path":"/usr/bin/id"},{"path":"/usr/bin/install"},{"path":"/usr/bin/join"},{"path":"/usr/bin/logname"},{"path":"/usr/bin/md5sum"},{"path":"/usr/bin/mkfifo"},{"path":"/usr/bin/nl"},{"path":"/usr/bin/nohup"},{"path":"/usr/bin/nproc"},{"path":"/usr/bin/numfmt"},{"path":"/usr/bin/od"},{"path":"/usr/bin/paste"},{"path":"/usr/bin/pathchk"},{"path":"/usr/bin/pinky"},{"path":"/usr/bin/pr"},{"path":"/usr/bin/printf"},{"path":"/usr/bin/ptx"},{"path":"/usr/bin/readlink"},{"path":"/usr/bin/realpath"},{"path":"/usr/bin/seq"},{"path":"/usr/bin/sha1sum"},{"path":"/usr/bin/sha224sum"},{"path":"/usr/bin/sha256sum"},{"path":"/usr/bin/sha384sum"},{"path":"/usr/bin/shred"},{"path":"/usr/bin/shuf"},{"path":"/usr/bin/sort"},{"path":"/usr/bin/split"},{"path":"/usr/bin/stdbuf"},{"path":"/usr/bin/sum"},{"path":"/usr/bin/tac"},{"path":"/usr/bin/tail"},{"path":"/usr/bin/tee"},{"path":"/usr/bin/test"},{"path":"/usr/bin/timeout"},{"path":"/usr/bin/tr"},{"path":"/usr/bin/truncate"},{"path":"/usr/bin/tsort"},{"path":"/usr/bin/tty"},{"path":"/usr/bin/unexpand"},{"path":"/usr/bin/uniq"},{"path":"/usr/bin/unlink"},{"path":"/usr/bin/users"},{"path":"/usr/bin/vdir"},{"path":"/usr/bin/wc"},{"path":"/usr/bin/who"},{"path":"/usr/bin/whoami"},{"path":"/usr/bin/yes"},{"path":"/usr/libexec"},{"path":"/usr/libexec/coreutils"},{"path":"/usr/libexec/coreutils/libstdbuf.so"},{"path":"/usr/sbin"},{"path":"/usr/sbin/chroot"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"16361c4de507bb4c","cpes":["cpe:2.3:a:coreutils-env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_env:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-env","purl":"pkg:apk/alpine/coreutils-env@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/env"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c43a637992609b6","cpes":["cpe:2.3:a:coreutils-fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-fmt","purl":"pkg:apk/alpine/coreutils-fmt@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/fmt"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"157238390cea3b89","cpes":["cpe:2.3:a:coreutils-sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-sha512sum","purl":"pkg:apk/alpine/coreutils-sha512sum@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/sha512sum"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"cd1d29bf30c1bae9","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.28.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66037","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66037","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66037","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66037","date":"2026-10-08","epss":0.00349,"percentile":0.26444}],"risk":0.19834833333333335,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23627","https://www.vulncheck.com/advisories/ffmpeg-iamf-demuxer-uncontrolled-resource-consumption-via-mix-presentation-obu"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66037","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing."},"relatedVulnerabilities":[]},{"artifact":{"id":"4173cf2fc659ac9d","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.12.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66037","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66037","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66037","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66037","date":"2026-10-08","epss":0.00349,"percentile":0.26444}],"risk":0.19834833333333335,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23627","https://www.vulncheck.com/advisories/ffmpeg-iamf-demuxer-uncontrolled-resource-consumption-via-mix-presentation-obu"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66037","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c11220a4fbbc883","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.26.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66037","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66037","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66037","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66037","date":"2026-10-08","epss":0.00349,"percentile":0.26444}],"risk":0.19834833333333335,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23627","https://www.vulncheck.com/advisories/ffmpeg-iamf-demuxer-uncontrolled-resource-consumption-via-mix-presentation-obu"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66037","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing."},"relatedVulnerabilities":[]},{"artifact":{"id":"a3d12aa6031708d4","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.3.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66037","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66037","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66037","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66037","date":"2026-10-08","epss":0.00349,"percentile":0.26444}],"risk":0.19834833333333335,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23627","https://www.vulncheck.com/advisories/ffmpeg-iamf-demuxer-uncontrolled-resource-consumption-via-mix-presentation-obu"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66037","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing."},"relatedVulnerabilities":[]},{"artifact":{"id":"5de1c0aba9a1e864","cpes":["cpe:2.3:a:_net_foundation:mailkit_.net:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:_net_foundation:mailkit:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:mailkit:mailkit_.net:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:mailkit:mailkit:4.14.0:*:*:*:*:*:*:*"],"name":"MailKit","purl":"pkg:nuget/MailKit@4.14.0","type":"dotnet","version":"4.14.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Api.V1.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Api.V1.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/MailKit.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/MailKit.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.16.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9j88-vvj5-vhgr","versionConstraint":"<4.16.0 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"MailKit","version":"4.14.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-9j88-vvj5-vhgr","fix":{"state":"fixed","versions":["4.16.0"],"available":[{"date":"2026-04-18","kind":"first-observed","version":"4.16.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41319","cwe":"CWE-74","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41319","date":"2026-10-08","epss":0.00331,"percentile":0.24243}],"risk":0.19032499999999997,"urls":["https://github.com/jstedfast/MailKit/security/advisories/GHSA-9j88-vvj5-vhgr","https://nvd.nist.gov/vuln/detail/CVE-2026-41319"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9j88-vvj5-vhgr","description":"MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade"},"relatedVulnerabilities":[{"id":"CVE-2026-41319","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41319","cwe":"CWE-74","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41319","date":"2026-10-08","epss":0.00331,"percentile":0.24243}],"urls":["https://github.com/jstedfast/MailKit/security/advisories/GHSA-9j88-vvj5-vhgr"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41319","description":"MailKit is a cross-platform mail client library built on top of MimeKit. A STARTTLS Response Injection vulnerability in versions prior to 4.16.0 allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in `SmtpStream`, `ImapStream`, and `Pop3Stream` is not flushed when the underlying stream is replaced with `SslStream` during STARTTLS upgrade, causing pre-TLS attacker-injected data to be processed as trusted post-TLS responses. Version 4.16.0 patches the issue."}]},{"artifact":{"id":"926beac9bfdf0401","cpes":["cpe:2.3:a:_net_foundation:mailkit_.net:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:_net_foundation:mailkit:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:mailkit:mailkit_.net:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:mailkit:mailkit:4.14.0:*:*:*:*:*:*:*"],"name":"MailKit","purl":"pkg:nuget/MailKit@4.14.0","type":"dotnet","version":"4.14.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/MailKit.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/MailKit.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.16.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9j88-vvj5-vhgr","versionConstraint":"<4.16.0 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"MailKit","version":"4.14.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-9j88-vvj5-vhgr","fix":{"state":"fixed","versions":["4.16.0"],"available":[{"date":"2026-04-18","kind":"first-observed","version":"4.16.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41319","cwe":"CWE-74","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41319","date":"2026-10-08","epss":0.00331,"percentile":0.24243}],"risk":0.19032499999999997,"urls":["https://github.com/jstedfast/MailKit/security/advisories/GHSA-9j88-vvj5-vhgr","https://nvd.nist.gov/vuln/detail/CVE-2026-41319"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9j88-vvj5-vhgr","description":"MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade"},"relatedVulnerabilities":[{"id":"CVE-2026-41319","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41319","cwe":"CWE-74","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41319","date":"2026-10-08","epss":0.00331,"percentile":0.24243}],"urls":["https://github.com/jstedfast/MailKit/security/advisories/GHSA-9j88-vvj5-vhgr"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41319","description":"MailKit is a cross-platform mail client library built on top of MimeKit. A STARTTLS Response Injection vulnerability in versions prior to 4.16.0 allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in `SmtpStream`, `ImapStream`, and `Pop3Stream` is not flushed when the underlying stream is replaced with `SslStream` during STARTTLS upgrade, causing pre-TLS attacker-injected data to be processed as trusted post-TLS responses. Version 4.16.0 patches the issue."}]},{"artifact":{"id":"7f8d836debe22d36","cpes":["cpe:2.3:a:_net_foundation:mailkit_.net:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:_net_foundation:mailkit:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:mailkit:mailkit_.net:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:mailkit:mailkit:4.14.0:*:*:*:*:*:*:*"],"name":"MailKit","purl":"pkg:nuget/MailKit@4.14.0","type":"dotnet","version":"4.14.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.SignalR.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.SignalR.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/MailKit.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/MailKit.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.16.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9j88-vvj5-vhgr","versionConstraint":"<4.16.0 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"MailKit","version":"4.14.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-9j88-vvj5-vhgr","fix":{"state":"fixed","versions":["4.16.0"],"available":[{"date":"2026-04-18","kind":"first-observed","version":"4.16.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41319","cwe":"CWE-74","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41319","date":"2026-10-08","epss":0.00331,"percentile":0.24243}],"risk":0.19032499999999997,"urls":["https://github.com/jstedfast/MailKit/security/advisories/GHSA-9j88-vvj5-vhgr","https://nvd.nist.gov/vuln/detail/CVE-2026-41319"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9j88-vvj5-vhgr","description":"MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade"},"relatedVulnerabilities":[{"id":"CVE-2026-41319","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41319","cwe":"CWE-74","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41319","date":"2026-10-08","epss":0.00331,"percentile":0.24243}],"urls":["https://github.com/jstedfast/MailKit/security/advisories/GHSA-9j88-vvj5-vhgr"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41319","description":"MailKit is a cross-platform mail client library built on top of MimeKit. A STARTTLS Response Injection vulnerability in versions prior to 4.16.0 allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in `SmtpStream`, `ImapStream`, and `Pop3Stream` is not flushed when the underlying stream is replaced with `SslStream` during STARTTLS upgrade, causing pre-TLS attacker-injected data to be processed as trusted post-TLS responses. Version 4.16.0 patches the issue."}]},{"artifact":{"id":"24e163ba8578059d","cpes":["cpe:2.3:a:_net_foundation:mailkit_.net:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:_net_foundation:mailkit:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:mailkit:mailkit_.net:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:mailkit:mailkit:4.14.0:*:*:*:*:*:*:*"],"name":"MailKit","purl":"pkg:nuget/MailKit@4.14.0","type":"dotnet","version":"4.14.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Http.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Http.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/MailKit.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/MailKit.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.16.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9j88-vvj5-vhgr","versionConstraint":"<4.16.0 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"MailKit","version":"4.14.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-9j88-vvj5-vhgr","fix":{"state":"fixed","versions":["4.16.0"],"available":[{"date":"2026-04-18","kind":"first-observed","version":"4.16.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41319","cwe":"CWE-74","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41319","date":"2026-10-08","epss":0.00331,"percentile":0.24243}],"risk":0.19032499999999997,"urls":["https://github.com/jstedfast/MailKit/security/advisories/GHSA-9j88-vvj5-vhgr","https://nvd.nist.gov/vuln/detail/CVE-2026-41319"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9j88-vvj5-vhgr","description":"MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade"},"relatedVulnerabilities":[{"id":"CVE-2026-41319","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41319","cwe":"CWE-74","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41319","date":"2026-10-08","epss":0.00331,"percentile":0.24243}],"urls":["https://github.com/jstedfast/MailKit/security/advisories/GHSA-9j88-vvj5-vhgr"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41319","description":"MailKit is a cross-platform mail client library built on top of MimeKit. A STARTTLS Response Injection vulnerability in versions prior to 4.16.0 allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in `SmtpStream`, `ImapStream`, and `Pop3Stream` is not flushed when the underlying stream is replaced with `SslStream` during STARTTLS upgrade, causing pre-TLS attacker-injected data to be processed as trusted post-TLS responses. Version 4.16.0 patches the issue."}]},{"artifact":{"id":"29091f662b484fd4","cpes":["cpe:2.3:a:_net_foundation:mailkit_.net:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:_net_foundation:mailkit:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:mailkit:mailkit_.net:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:mailkit:mailkit:4.14.0:*:*:*:*:*:*:*"],"name":"MailKit","purl":"pkg:nuget/MailKit@4.14.0","type":"dotnet","version":"4.14.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Host.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Host.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/MailKit.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/MailKit.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.16.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9j88-vvj5-vhgr","versionConstraint":"<4.16.0 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"MailKit","version":"4.14.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-9j88-vvj5-vhgr","fix":{"state":"fixed","versions":["4.16.0"],"available":[{"date":"2026-04-18","kind":"first-observed","version":"4.16.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41319","cwe":"CWE-74","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41319","date":"2026-10-08","epss":0.00331,"percentile":0.24243}],"risk":0.19032499999999997,"urls":["https://github.com/jstedfast/MailKit/security/advisories/GHSA-9j88-vvj5-vhgr","https://nvd.nist.gov/vuln/detail/CVE-2026-41319"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9j88-vvj5-vhgr","description":"MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade"},"relatedVulnerabilities":[{"id":"CVE-2026-41319","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41319","cwe":"CWE-74","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41319","date":"2026-10-08","epss":0.00331,"percentile":0.24243}],"urls":["https://github.com/jstedfast/MailKit/security/advisories/GHSA-9j88-vvj5-vhgr"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41319","description":"MailKit is a cross-platform mail client library built on top of MimeKit. A STARTTLS Response Injection vulnerability in versions prior to 4.16.0 allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in `SmtpStream`, `ImapStream`, and `Pop3Stream` is not flushed when the underlying stream is replaced with `SslStream` during STARTTLS upgrade, causing pre-TLS attacker-injected data to be processed as trusted post-TLS responses. Version 4.16.0 patches the issue."}]},{"artifact":{"id":"886e39cb5db47338","cpes":["cpe:2.3:a:_net_foundation:mailkit_.net:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:_net_foundation:mailkit:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:mailkit:mailkit_.net:4.14.0:*:*:*:*:*:*:*","cpe:2.3:a:mailkit:mailkit:4.14.0:*:*:*:*:*:*:*"],"name":"MailKit","purl":"pkg:nuget/MailKit@4.14.0","type":"dotnet","version":"4.14.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Core.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Core.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/MailKit.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/MailKit.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.16.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9j88-vvj5-vhgr","versionConstraint":"<4.16.0 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"MailKit","version":"4.14.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-9j88-vvj5-vhgr","fix":{"state":"fixed","versions":["4.16.0"],"available":[{"date":"2026-04-18","kind":"first-observed","version":"4.16.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41319","cwe":"CWE-74","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41319","date":"2026-10-08","epss":0.00331,"percentile":0.24243}],"risk":0.19032499999999997,"urls":["https://github.com/jstedfast/MailKit/security/advisories/GHSA-9j88-vvj5-vhgr","https://nvd.nist.gov/vuln/detail/CVE-2026-41319"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9j88-vvj5-vhgr","description":"MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade"},"relatedVulnerabilities":[{"id":"CVE-2026-41319","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41319","cwe":"CWE-74","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41319","date":"2026-10-08","epss":0.00331,"percentile":0.24243}],"urls":["https://github.com/jstedfast/MailKit/security/advisories/GHSA-9j88-vvj5-vhgr"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41319","description":"MailKit is a cross-platform mail client library built on top of MimeKit. A STARTTLS Response Injection vulnerability in versions prior to 4.16.0 allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in `SmtpStream`, `ImapStream`, and `Pop3Stream` is not flushed when the underlying stream is replaced with `SslStream` during STARTTLS upgrade, causing pre-TLS attacker-injected data to be processed as trusted post-TLS responses. Version 4.16.0 patches the issue."}]},{"artifact":{"id":"ebfa5695b11b7ea8","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gwg2-r3hj-4w44","versionConstraint":">=1.0.0-beta0001,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-gwg2-r3hj-4w44","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106114","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106114","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"risk":0.18849000000000002,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-gwg2-r3hj-4w44","https://nvd.nist.gov/vuln/detail/CVE-2026-106114","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/8de892a7623aa8a09ba2333b624c8d2eb98325df","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gwg2-r3hj-4w44","description":"ImageSharp: ICC CLUT parsing allocates from unvalidated channel and grid dimensions"},"relatedVulnerabilities":[{"id":"CVE-2026-106114","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106114","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106114","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"urls":["https://github.com/SixLabors/ImageSharp/commit/8de892a7623aa8a09ba2333b624c8d2eb98325df","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-gwg2-r3hj-4w44"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106114","description":"ImageSharp is a 2D graphics library. From 1.0.0-beta0001 until 4.1.2, ICC CLUT parsing calculates allocation sizes from attacker-declared channel and grid dimensions before confirming that the profile contains the declared values. IccDataReader.ReadClutF32 can request a large float array, and earlier public IccProfile.Entries parsing paths can allocate a large jagged representation, from a short truncated profile. In version 4, automatic image conversion reaches the parser when DecoderOptions.ColorProfileHandling is Convert; the default Preserve mode avoids that conversion path. The demonstrated impact is memory pressure and input-validation failure, not unhandled process termination. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"7d1ad195f96bf365","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Api.V1.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Api.V1.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gwg2-r3hj-4w44","versionConstraint":">=1.0.0-beta0001,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-gwg2-r3hj-4w44","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106114","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106114","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"risk":0.18849000000000002,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-gwg2-r3hj-4w44","https://nvd.nist.gov/vuln/detail/CVE-2026-106114","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/8de892a7623aa8a09ba2333b624c8d2eb98325df","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gwg2-r3hj-4w44","description":"ImageSharp: ICC CLUT parsing allocates from unvalidated channel and grid dimensions"},"relatedVulnerabilities":[{"id":"CVE-2026-106114","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106114","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106114","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"urls":["https://github.com/SixLabors/ImageSharp/commit/8de892a7623aa8a09ba2333b624c8d2eb98325df","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-gwg2-r3hj-4w44"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106114","description":"ImageSharp is a 2D graphics library. From 1.0.0-beta0001 until 4.1.2, ICC CLUT parsing calculates allocation sizes from attacker-declared channel and grid dimensions before confirming that the profile contains the declared values. IccDataReader.ReadClutF32 can request a large float array, and earlier public IccProfile.Entries parsing paths can allocate a large jagged representation, from a short truncated profile. In version 4, automatic image conversion reaches the parser when DecoderOptions.ColorProfileHandling is Convert; the default Preserve mode avoids that conversion path. The demonstrated impact is memory pressure and input-validation failure, not unhandled process termination. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"75b9753b56f635f4","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.SignalR.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.SignalR.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gwg2-r3hj-4w44","versionConstraint":">=1.0.0-beta0001,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-gwg2-r3hj-4w44","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106114","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106114","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"risk":0.18849000000000002,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-gwg2-r3hj-4w44","https://nvd.nist.gov/vuln/detail/CVE-2026-106114","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/8de892a7623aa8a09ba2333b624c8d2eb98325df","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gwg2-r3hj-4w44","description":"ImageSharp: ICC CLUT parsing allocates from unvalidated channel and grid dimensions"},"relatedVulnerabilities":[{"id":"CVE-2026-106114","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106114","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106114","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"urls":["https://github.com/SixLabors/ImageSharp/commit/8de892a7623aa8a09ba2333b624c8d2eb98325df","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-gwg2-r3hj-4w44"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106114","description":"ImageSharp is a 2D graphics library. From 1.0.0-beta0001 until 4.1.2, ICC CLUT parsing calculates allocation sizes from attacker-declared channel and grid dimensions before confirming that the profile contains the declared values. IccDataReader.ReadClutF32 can request a large float array, and earlier public IccProfile.Entries parsing paths can allocate a large jagged representation, from a short truncated profile. In version 4, automatic image conversion reaches the parser when DecoderOptions.ColorProfileHandling is Convert; the default Preserve mode avoids that conversion path. The demonstrated impact is memory pressure and input-validation failure, not unhandled process termination. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"17272c7abf1a8571","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Http.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Http.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gwg2-r3hj-4w44","versionConstraint":">=1.0.0-beta0001,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-gwg2-r3hj-4w44","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106114","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106114","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"risk":0.18849000000000002,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-gwg2-r3hj-4w44","https://nvd.nist.gov/vuln/detail/CVE-2026-106114","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/8de892a7623aa8a09ba2333b624c8d2eb98325df","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gwg2-r3hj-4w44","description":"ImageSharp: ICC CLUT parsing allocates from unvalidated channel and grid dimensions"},"relatedVulnerabilities":[{"id":"CVE-2026-106114","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106114","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106114","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"urls":["https://github.com/SixLabors/ImageSharp/commit/8de892a7623aa8a09ba2333b624c8d2eb98325df","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-gwg2-r3hj-4w44"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106114","description":"ImageSharp is a 2D graphics library. From 1.0.0-beta0001 until 4.1.2, ICC CLUT parsing calculates allocation sizes from attacker-declared channel and grid dimensions before confirming that the profile contains the declared values. IccDataReader.ReadClutF32 can request a large float array, and earlier public IccProfile.Entries parsing paths can allocate a large jagged representation, from a short truncated profile. In version 4, automatic image conversion reaches the parser when DecoderOptions.ColorProfileHandling is Convert; the default Preserve mode avoids that conversion path. The demonstrated impact is memory pressure and input-validation failure, not unhandled process termination. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"27074e88c8facc24","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Host.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Host.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gwg2-r3hj-4w44","versionConstraint":">=1.0.0-beta0001,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-gwg2-r3hj-4w44","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106114","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106114","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"risk":0.18849000000000002,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-gwg2-r3hj-4w44","https://nvd.nist.gov/vuln/detail/CVE-2026-106114","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/8de892a7623aa8a09ba2333b624c8d2eb98325df","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gwg2-r3hj-4w44","description":"ImageSharp: ICC CLUT parsing allocates from unvalidated channel and grid dimensions"},"relatedVulnerabilities":[{"id":"CVE-2026-106114","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106114","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106114","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"urls":["https://github.com/SixLabors/ImageSharp/commit/8de892a7623aa8a09ba2333b624c8d2eb98325df","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-gwg2-r3hj-4w44"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106114","description":"ImageSharp is a 2D graphics library. From 1.0.0-beta0001 until 4.1.2, ICC CLUT parsing calculates allocation sizes from attacker-declared channel and grid dimensions before confirming that the profile contains the declared values. IccDataReader.ReadClutF32 can request a large float array, and earlier public IccProfile.Entries parsing paths can allocate a large jagged representation, from a short truncated profile. In version 4, automatic image conversion reaches the parser when DecoderOptions.ColorProfileHandling is Convert; the default Preserve mode avoids that conversion path. The demonstrated impact is memory pressure and input-validation failure, not unhandled process termination. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"3e3b14319bc01e58","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Core.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Core.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gwg2-r3hj-4w44","versionConstraint":">=1.0.0-beta0001,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-gwg2-r3hj-4w44","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106114","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106114","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"risk":0.18849000000000002,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-gwg2-r3hj-4w44","https://nvd.nist.gov/vuln/detail/CVE-2026-106114","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/8de892a7623aa8a09ba2333b624c8d2eb98325df","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gwg2-r3hj-4w44","description":"ImageSharp: ICC CLUT parsing allocates from unvalidated channel and grid dimensions"},"relatedVulnerabilities":[{"id":"CVE-2026-106114","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106114","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106114","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"urls":["https://github.com/SixLabors/ImageSharp/commit/8de892a7623aa8a09ba2333b624c8d2eb98325df","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-gwg2-r3hj-4w44"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106114","description":"ImageSharp is a 2D graphics library. From 1.0.0-beta0001 until 4.1.2, ICC CLUT parsing calculates allocation sizes from attacker-declared channel and grid dimensions before confirming that the profile contains the declared values. IccDataReader.ReadClutF32 can request a large float array, and earlier public IccProfile.Entries parsing paths can allocate a large jagged representation, from a short truncated profile. In version 4, automatic image conversion reaches the parser when DecoderOptions.ColorProfileHandling is Convert; the default Preserve mode avoids that conversion path. The demonstrated impact is memory pressure and input-validation failure, not unhandled process termination. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"27074e88c8facc24","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Host.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Host.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wmxv-xphr-5c9g","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-wmxv-xphr-5c9g","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106116","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106116","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"risk":0.18849000000000002,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-wmxv-xphr-5c9g","https://nvd.nist.gov/vuln/detail/CVE-2026-106116","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/92b12d72550ebb6be5b1e22e559c361fd863a6ec","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wmxv-xphr-5c9g","description":"ImageSharp: BigTIFF IFD count can keep a decoder thread in a non-progressing loop"},"relatedVulnerabilities":[{"id":"CVE-2026-106116","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106116","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106116","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"urls":["https://github.com/SixLabors/ImageSharp/commit/92b12d72550ebb6be5b1e22e559c361fd863a6ec","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-wmxv-xphr-5c9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106116","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, ExifReader.ReadValues64 trusts the 64-bit BigTIFF IFD entry count and iterates once per declared entry. When fewer than 20 bytes remain, ExifReader.ReadValue64 returns without advancing the stream or terminating the outer loop, so a small malformed BigTIFF can keep one decoder thread executing for an attacker-controlled duration. This report does not claim worker-pool exhaustion. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"7d1ad195f96bf365","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Api.V1.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Api.V1.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wmxv-xphr-5c9g","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-wmxv-xphr-5c9g","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106116","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106116","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"risk":0.18849000000000002,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-wmxv-xphr-5c9g","https://nvd.nist.gov/vuln/detail/CVE-2026-106116","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/92b12d72550ebb6be5b1e22e559c361fd863a6ec","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wmxv-xphr-5c9g","description":"ImageSharp: BigTIFF IFD count can keep a decoder thread in a non-progressing loop"},"relatedVulnerabilities":[{"id":"CVE-2026-106116","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106116","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106116","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"urls":["https://github.com/SixLabors/ImageSharp/commit/92b12d72550ebb6be5b1e22e559c361fd863a6ec","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-wmxv-xphr-5c9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106116","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, ExifReader.ReadValues64 trusts the 64-bit BigTIFF IFD entry count and iterates once per declared entry. When fewer than 20 bytes remain, ExifReader.ReadValue64 returns without advancing the stream or terminating the outer loop, so a small malformed BigTIFF can keep one decoder thread executing for an attacker-controlled duration. This report does not claim worker-pool exhaustion. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"17272c7abf1a8571","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Http.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Http.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wmxv-xphr-5c9g","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-wmxv-xphr-5c9g","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106116","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106116","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"risk":0.18849000000000002,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-wmxv-xphr-5c9g","https://nvd.nist.gov/vuln/detail/CVE-2026-106116","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/92b12d72550ebb6be5b1e22e559c361fd863a6ec","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wmxv-xphr-5c9g","description":"ImageSharp: BigTIFF IFD count can keep a decoder thread in a non-progressing loop"},"relatedVulnerabilities":[{"id":"CVE-2026-106116","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106116","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106116","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"urls":["https://github.com/SixLabors/ImageSharp/commit/92b12d72550ebb6be5b1e22e559c361fd863a6ec","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-wmxv-xphr-5c9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106116","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, ExifReader.ReadValues64 trusts the 64-bit BigTIFF IFD entry count and iterates once per declared entry. When fewer than 20 bytes remain, ExifReader.ReadValue64 returns without advancing the stream or terminating the outer loop, so a small malformed BigTIFF can keep one decoder thread executing for an attacker-controlled duration. This report does not claim worker-pool exhaustion. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"75b9753b56f635f4","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.SignalR.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.SignalR.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wmxv-xphr-5c9g","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-wmxv-xphr-5c9g","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106116","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106116","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"risk":0.18849000000000002,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-wmxv-xphr-5c9g","https://nvd.nist.gov/vuln/detail/CVE-2026-106116","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/92b12d72550ebb6be5b1e22e559c361fd863a6ec","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wmxv-xphr-5c9g","description":"ImageSharp: BigTIFF IFD count can keep a decoder thread in a non-progressing loop"},"relatedVulnerabilities":[{"id":"CVE-2026-106116","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106116","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106116","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"urls":["https://github.com/SixLabors/ImageSharp/commit/92b12d72550ebb6be5b1e22e559c361fd863a6ec","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-wmxv-xphr-5c9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106116","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, ExifReader.ReadValues64 trusts the 64-bit BigTIFF IFD entry count and iterates once per declared entry. When fewer than 20 bytes remain, ExifReader.ReadValue64 returns without advancing the stream or terminating the outer loop, so a small malformed BigTIFF can keep one decoder thread executing for an attacker-controlled duration. This report does not claim worker-pool exhaustion. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"ebfa5695b11b7ea8","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wmxv-xphr-5c9g","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-wmxv-xphr-5c9g","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106116","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106116","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"risk":0.18849000000000002,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-wmxv-xphr-5c9g","https://nvd.nist.gov/vuln/detail/CVE-2026-106116","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/92b12d72550ebb6be5b1e22e559c361fd863a6ec","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wmxv-xphr-5c9g","description":"ImageSharp: BigTIFF IFD count can keep a decoder thread in a non-progressing loop"},"relatedVulnerabilities":[{"id":"CVE-2026-106116","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106116","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106116","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"urls":["https://github.com/SixLabors/ImageSharp/commit/92b12d72550ebb6be5b1e22e559c361fd863a6ec","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-wmxv-xphr-5c9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106116","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, ExifReader.ReadValues64 trusts the 64-bit BigTIFF IFD entry count and iterates once per declared entry. When fewer than 20 bytes remain, ExifReader.ReadValue64 returns without advancing the stream or terminating the outer loop, so a small malformed BigTIFF can keep one decoder thread executing for an attacker-controlled duration. This report does not claim worker-pool exhaustion. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"3e3b14319bc01e58","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.11:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.11:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.11","type":"dotnet","version":"3.1.11","language":"dotnet","licenses":[],"locations":[{"path":"/app/lidarr/bin/Lidarr.Core.deps.json","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/Lidarr.Core.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/lidarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/app/lidarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wmxv-xphr-5c9g","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.11"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-wmxv-xphr-5c9g","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106116","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106116","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"risk":0.18849000000000002,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-wmxv-xphr-5c9g","https://nvd.nist.gov/vuln/detail/CVE-2026-106116","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/92b12d72550ebb6be5b1e22e559c361fd863a6ec","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wmxv-xphr-5c9g","description":"ImageSharp: BigTIFF IFD count can keep a decoder thread in a non-progressing loop"},"relatedVulnerabilities":[{"id":"CVE-2026-106116","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106116","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106116","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"urls":["https://github.com/SixLabors/ImageSharp/commit/92b12d72550ebb6be5b1e22e559c361fd863a6ec","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-wmxv-xphr-5c9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106116","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, ExifReader.ReadValues64 trusts the 64-bit BigTIFF IFD entry count and iterates once per declared entry. When fewer than 20 bytes remain, ExifReader.ReadValue64 returns without advancing the stream or terminating the outer loop, so a small malformed BigTIFF can keep one decoder thread executing for an attacker-controlled duration. This report does not claim worker-pool exhaustion. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"fef07e9c95ea2bda","cpes":["cpe:2.3:a:busybox:busybox:1.37.0-r31:*:*:*:*:*:*:*"],"name":"busybox","purl":"pkg:apk/alpine/busybox@1.37.0-r31?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"1.37.0-r31","language":"","licenses":["GPL-2.0-only"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/busybox"},{"path":"/etc"},{"path":"/etc/securetty"},{"path":"/etc/busybox-paths.d"},{"path":"/etc/busybox-paths.d/busybox"},{"path":"/etc/logrotate.d"},{"path":"/etc/logrotate.d/acpid"},{"path":"/etc/network"},{"path":"/etc/network/if-down.d"},{"path":"/etc/network/if-post-down.d"},{"path":"/etc/network/if-post-up.d"},{"path":"/etc/network/if-pre-down.d"},{"path":"/etc/network/if-pre-up.d"},{"path":"/etc/network/if-up.d"},{"path":"/etc/network/if-up.d/dad"},{"path":"/etc/udhcpc"},{"path":"/etc/udhcpc/udhcpc.conf"},{"path":"/sbin"},{"path":"/usr"},{"path":"/usr/sbin"},{"path":"/usr/share"},{"path":"/usr/share/udhcpc"},{"path":"/usr/share/udhcpc/default.script"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"busybox"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-60876","versionConstraint":"<= 1.37.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:busybox:busybox:1.37.0:*:*:*:*:*:*:*"],"package":{"name":"busybox","version":"1.37.0-r31"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-60876","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-60876","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-60876","date":"2026-10-08","epss":0.00291,"percentile":0.19874}],"risk":0.16732499999999997,"urls":["https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092","https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm","https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-60876","description":"BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20)."},"relatedVulnerabilities":[]},{"artifact":{"id":"915155597fcdee9a","cpes":["cpe:2.3:a:busybox-binsh:busybox-binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox-binsh:busybox_binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox_binsh:busybox-binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox_binsh:busybox_binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox:busybox-binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox:busybox_binsh:1.37.0-r31:*:*:*:*:*:*:*"],"name":"busybox-binsh","purl":"pkg:apk/alpine/busybox-binsh@1.37.0-r31?arch=x86_64&distro=alpine-3.24.2&upstream=busybox","type":"apk","version":"1.37.0-r31","language":"","licenses":["GPL-2.0-only"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/sh"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"busybox"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-60876","versionConstraint":"<= 1.37.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:busybox:busybox:1.37.0:*:*:*:*:*:*:*"],"package":{"name":"busybox","version":"1.37.0-r31"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-60876","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-60876","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-60876","date":"2026-10-08","epss":0.00291,"percentile":0.19874}],"risk":0.16732499999999997,"urls":["https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092","https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm","https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-60876","description":"BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20)."},"relatedVulnerabilities":[]},{"artifact":{"id":"8a9ef44e1018f213","cpes":["cpe:2.3:a:ssl-client:ssl-client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl-client:ssl_client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl_client:ssl-client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl_client:ssl_client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl:ssl-client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl:ssl_client:1.37.0-r31:*:*:*:*:*:*:*"],"name":"ssl_client","purl":"pkg:apk/alpine/ssl_client@1.37.0-r31?arch=x86_64&distro=alpine-3.24.2&upstream=busybox","type":"apk","version":"1.37.0-r31","language":"","licenses":["GPL-2.0-only"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssl_client"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"busybox"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-60876","versionConstraint":"<= 1.37.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:busybox:busybox:1.37.0:*:*:*:*:*:*:*"],"package":{"name":"busybox","version":"1.37.0-r31"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-60876","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-60876","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-60876","date":"2026-10-08","epss":0.00291,"percentile":0.19874}],"risk":0.16732499999999997,"urls":["https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092","https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm","https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-60876","description":"BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20)."},"relatedVulnerabilities":[]},{"artifact":{"id":"cd1d29bf30c1bae9","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.28.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70632","versionConstraint":">= 4.4, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70632","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70632","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70632","date":"2026-10-08","epss":0.00202,"percentile":0.09259}],"risk":0.158065,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1006a2151236f9235bf02822f263b3fb0532111e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/db05df9d135fb56a4babb836d5e9f5c1d984e087","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23898","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-cfhd-decoder-via-avi-demuxing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70632","description":"FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer."},"relatedVulnerabilities":[]},{"artifact":{"id":"4173cf2fc659ac9d","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.12.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70632","versionConstraint":">= 4.4, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70632","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70632","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70632","date":"2026-10-08","epss":0.00202,"percentile":0.09259}],"risk":0.158065,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1006a2151236f9235bf02822f263b3fb0532111e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/db05df9d135fb56a4babb836d5e9f5c1d984e087","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23898","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-cfhd-decoder-via-avi-demuxing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70632","description":"FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c11220a4fbbc883","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.26.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70632","versionConstraint":">= 4.4, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70632","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70632","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70632","date":"2026-10-08","epss":0.00202,"percentile":0.09259}],"risk":0.158065,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1006a2151236f9235bf02822f263b3fb0532111e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/db05df9d135fb56a4babb836d5e9f5c1d984e087","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23898","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-cfhd-decoder-via-avi-demuxing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70632","description":"FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer."},"relatedVulnerabilities":[]},{"artifact":{"id":"a3d12aa6031708d4","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.3.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70632","versionConstraint":">= 4.4, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70632","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70632","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70632","date":"2026-10-08","epss":0.00202,"percentile":0.09259}],"risk":0.158065,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1006a2151236f9235bf02822f263b3fb0532111e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/db05df9d135fb56a4babb836d5e9f5c1d984e087","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23898","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-cfhd-decoder-via-avi-demuxing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70632","description":"FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer."},"relatedVulnerabilities":[]},{"artifact":{"id":"cd1d29bf30c1bae9","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.28.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65706","versionConstraint":">= 3.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65706","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65706","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65706","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65706","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1463275,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23779","https://www.vulncheck.com/advisories/ffmpeg-vf-swaprect-out-of-bounds-write-via-nv12-frame-processing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65706","description":"FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"4173cf2fc659ac9d","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.12.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65706","versionConstraint":">= 3.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65706","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65706","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65706","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65706","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1463275,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23779","https://www.vulncheck.com/advisories/ffmpeg-vf-swaprect-out-of-bounds-write-via-nv12-frame-processing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65706","description":"FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c11220a4fbbc883","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.26.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65706","versionConstraint":">= 3.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65706","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65706","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65706","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65706","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1463275,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23779","https://www.vulncheck.com/advisories/ffmpeg-vf-swaprect-out-of-bounds-write-via-nv12-frame-processing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65706","description":"FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"a3d12aa6031708d4","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.3.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65706","versionConstraint":">= 3.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65706","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65706","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65706","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65706","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1463275,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23779","https://www.vulncheck.com/advisories/ffmpeg-vf-swaprect-out-of-bounds-write-via-nv12-frame-processing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65706","description":"FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"cd1d29bf30c1bae9","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.28.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65705","versionConstraint":">= 3.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65705","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65705","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65705","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65705","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1407175,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780","https://www.vulncheck.com/advisories/ffmpeg-vf-floodfill-out-of-bounds-write-via-filter-frame"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65705","description":"FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening."},"relatedVulnerabilities":[]},{"artifact":{"id":"4173cf2fc659ac9d","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.12.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65705","versionConstraint":">= 3.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65705","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65705","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65705","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65705","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1407175,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780","https://www.vulncheck.com/advisories/ffmpeg-vf-floodfill-out-of-bounds-write-via-filter-frame"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65705","description":"FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c11220a4fbbc883","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.26.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65705","versionConstraint":">= 3.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65705","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65705","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65705","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65705","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1407175,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780","https://www.vulncheck.com/advisories/ffmpeg-vf-floodfill-out-of-bounds-write-via-filter-frame"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65705","description":"FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening."},"relatedVulnerabilities":[]},{"artifact":{"id":"a3d12aa6031708d4","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.3.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65705","versionConstraint":">= 3.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65705","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65705","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65705","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65705","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1407175,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780","https://www.vulncheck.com/advisories/ffmpeg-vf-floodfill-out-of-bounds-write-via-filter-frame"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65705","description":"FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening."},"relatedVulnerabilities":[]},{"artifact":{"id":"cd1d29bf30c1bae9","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.28.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65704","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65704","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65704","cwe":"CWE-191","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65704","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65704","date":"2026-10-08","epss":0.00178,"percentile":0.06786}],"risk":0.13394499999999998,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/de771bd52774a52d45b0e2c82e56995a1ef40df7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23767","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-via-ty-demuxer-and-shorten-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65704","description":"FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size without bounds checking, producing a negative size value that is passed to memcpy() in shorten_decode_frame(), where conversion to size_t wraps the value to near SIZE_MAX and triggers reads beyond the source allocation and writes far beyond the Shorten decoder's bitstream buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"4173cf2fc659ac9d","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.12.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65704","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65704","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65704","cwe":"CWE-191","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65704","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65704","date":"2026-10-08","epss":0.00178,"percentile":0.06786}],"risk":0.13394499999999998,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/de771bd52774a52d45b0e2c82e56995a1ef40df7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23767","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-via-ty-demuxer-and-shorten-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65704","description":"FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size without bounds checking, producing a negative size value that is passed to memcpy() in shorten_decode_frame(), where conversion to size_t wraps the value to near SIZE_MAX and triggers reads beyond the source allocation and writes far beyond the Shorten decoder's bitstream buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c11220a4fbbc883","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.26.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65704","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65704","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65704","cwe":"CWE-191","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65704","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65704","date":"2026-10-08","epss":0.00178,"percentile":0.06786}],"risk":0.13394499999999998,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/de771bd52774a52d45b0e2c82e56995a1ef40df7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23767","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-via-ty-demuxer-and-shorten-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65704","description":"FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size without bounds checking, producing a negative size value that is passed to memcpy() in shorten_decode_frame(), where conversion to size_t wraps the value to near SIZE_MAX and triggers reads beyond the source allocation and writes far beyond the Shorten decoder's bitstream buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"a3d12aa6031708d4","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.3.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65704","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65704","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65704","cwe":"CWE-191","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65704","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65704","date":"2026-10-08","epss":0.00178,"percentile":0.06786}],"risk":0.13394499999999998,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/de771bd52774a52d45b0e2c82e56995a1ef40df7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23767","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-via-ty-demuxer-and-shorten-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65704","description":"FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size without bounds checking, producing a negative size value that is passed to memcpy() in shorten_decode_frame(), where conversion to size_t wraps the value to near SIZE_MAX and triggers reads beyond the source allocation and writes far beyond the Shorten decoder's bitstream buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"cd1d29bf30c1bae9","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.28.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70628","versionConstraint":">= 0.5, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70628","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70628","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-70628","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70628","date":"2026-10-08","epss":0.00145,"percentile":0.03262}],"risk":0.11346249999999998,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/02fc47e13f903768b75f7985a2706a6223ab4506","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/93f2a525ec6c7b467bae68322720d10188fc6e30","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c6ec28b18cd1eb7d39e6163137367f2d1c62aa7c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23897","https://www.vulncheck.com/advisories/ffmpeg-dvb-subtitle-parser-heap-buffer-overflow-via-wtv-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70628","description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expression to wrap to INT_MIN, bypassing the PARSE_BUF_SIZE comparison and invoking memcpy() with attacker-controlled data into a heap buffer, resulting in an out-of-bounds heap write and potential memory corruption or code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"4173cf2fc659ac9d","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.12.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70628","versionConstraint":">= 0.5, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70628","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70628","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-70628","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70628","date":"2026-10-08","epss":0.00145,"percentile":0.03262}],"risk":0.11346249999999998,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/02fc47e13f903768b75f7985a2706a6223ab4506","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/93f2a525ec6c7b467bae68322720d10188fc6e30","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c6ec28b18cd1eb7d39e6163137367f2d1c62aa7c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23897","https://www.vulncheck.com/advisories/ffmpeg-dvb-subtitle-parser-heap-buffer-overflow-via-wtv-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70628","description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expression to wrap to INT_MIN, bypassing the PARSE_BUF_SIZE comparison and invoking memcpy() with attacker-controlled data into a heap buffer, resulting in an out-of-bounds heap write and potential memory corruption or code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c11220a4fbbc883","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.26.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70628","versionConstraint":">= 0.5, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70628","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70628","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-70628","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70628","date":"2026-10-08","epss":0.00145,"percentile":0.03262}],"risk":0.11346249999999998,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/02fc47e13f903768b75f7985a2706a6223ab4506","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/93f2a525ec6c7b467bae68322720d10188fc6e30","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c6ec28b18cd1eb7d39e6163137367f2d1c62aa7c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23897","https://www.vulncheck.com/advisories/ffmpeg-dvb-subtitle-parser-heap-buffer-overflow-via-wtv-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70628","description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expression to wrap to INT_MIN, bypassing the PARSE_BUF_SIZE comparison and invoking memcpy() with attacker-controlled data into a heap buffer, resulting in an out-of-bounds heap write and potential memory corruption or code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"a3d12aa6031708d4","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.3.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70628","versionConstraint":">= 0.5, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70628","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70628","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-70628","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70628","date":"2026-10-08","epss":0.00145,"percentile":0.03262}],"risk":0.11346249999999998,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/02fc47e13f903768b75f7985a2706a6223ab4506","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/93f2a525ec6c7b467bae68322720d10188fc6e30","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c6ec28b18cd1eb7d39e6163137367f2d1c62aa7c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23897","https://www.vulncheck.com/advisories/ffmpeg-dvb-subtitle-parser-heap-buffer-overflow-via-wtv-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70628","description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expression to wrap to INT_MIN, bypassing the PARSE_BUF_SIZE comparison and invoking memcpy() with attacker-controlled data into a heap buffer, resulting in an out-of-bounds heap write and potential memory corruption or code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"cd1d29bf30c1bae9","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.28.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70631","versionConstraint":">= 0.5, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70631","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70631","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70631","date":"2026-10-08","epss":0.00178,"percentile":0.06732}],"risk":0.09923499999999999,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2f234ea34c81288e3840fca632dd16481d8de39f","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/3c287af3affe1286350faa69c02bcc5d49de18bb","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a991b1fecbd8c9e6f4fc31c191bd12e4be27dbf7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23899","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-tiff-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70631","description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply a valid Deflate-compressed strip that terminates successfully after producing fewer bytes than the declared strip requires. The tiff_unpack_zlib() function allocates a heap buffer sized for the full declared strip but copies all declared rows via memcpy() regardless of how many bytes zlib actually decompressed, causing unwritten bytes that can contain stale data from prior heap allocations to be incorporated into decoded image output and potentially exposing sensitive data in persistent services."},"relatedVulnerabilities":[]},{"artifact":{"id":"4173cf2fc659ac9d","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.12.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70631","versionConstraint":">= 0.5, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70631","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70631","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70631","date":"2026-10-08","epss":0.00178,"percentile":0.06732}],"risk":0.09923499999999999,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2f234ea34c81288e3840fca632dd16481d8de39f","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/3c287af3affe1286350faa69c02bcc5d49de18bb","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a991b1fecbd8c9e6f4fc31c191bd12e4be27dbf7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23899","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-tiff-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70631","description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply a valid Deflate-compressed strip that terminates successfully after producing fewer bytes than the declared strip requires. The tiff_unpack_zlib() function allocates a heap buffer sized for the full declared strip but copies all declared rows via memcpy() regardless of how many bytes zlib actually decompressed, causing unwritten bytes that can contain stale data from prior heap allocations to be incorporated into decoded image output and potentially exposing sensitive data in persistent services."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c11220a4fbbc883","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.26.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70631","versionConstraint":">= 0.5, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70631","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70631","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70631","date":"2026-10-08","epss":0.00178,"percentile":0.06732}],"risk":0.09923499999999999,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2f234ea34c81288e3840fca632dd16481d8de39f","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/3c287af3affe1286350faa69c02bcc5d49de18bb","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a991b1fecbd8c9e6f4fc31c191bd12e4be27dbf7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23899","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-tiff-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70631","description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply a valid Deflate-compressed strip that terminates successfully after producing fewer bytes than the declared strip requires. The tiff_unpack_zlib() function allocates a heap buffer sized for the full declared strip but copies all declared rows via memcpy() regardless of how many bytes zlib actually decompressed, causing unwritten bytes that can contain stale data from prior heap allocations to be incorporated into decoded image output and potentially exposing sensitive data in persistent services."},"relatedVulnerabilities":[]},{"artifact":{"id":"a3d12aa6031708d4","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.3.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70631","versionConstraint":">= 0.5, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70631","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70631","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70631","date":"2026-10-08","epss":0.00178,"percentile":0.06732}],"risk":0.09923499999999999,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2f234ea34c81288e3840fca632dd16481d8de39f","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/3c287af3affe1286350faa69c02bcc5d49de18bb","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a991b1fecbd8c9e6f4fc31c191bd12e4be27dbf7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23899","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-tiff-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70631","description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply a valid Deflate-compressed strip that terminates successfully after producing fewer bytes than the declared strip requires. The tiff_unpack_zlib() function allocates a heap buffer sized for the full declared strip but copies all declared rows via memcpy() regardless of how many bytes zlib actually decompressed, causing unwritten bytes that can contain stale data from prior heap allocations to be incorporated into decoded image output and potentially exposing sensitive data in persistent services."},"relatedVulnerabilities":[]},{"artifact":{"id":"cd1d29bf30c1bae9","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.28.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70630","versionConstraint":">= 3.0, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70630","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70630","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70630","date":"2026-10-08","epss":0.00175,"percentile":0.06355}],"risk":0.09756250000000001,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/705890061467ad550ecc1dad5eea07f28ccfb43e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/9a3202a98b2e095b54dd784c3e01a09a676fc3fa","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c22667d0fd7916a33fd3e79685b7246fc48f1a62","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23896","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-screenpresso-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70630","description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a crafted SPV1 packet with a valid zlib stream that decompresses fewer bytes than the full frame requires. The screenpresso_decode_frame() function fails to validate the produced byte count before calling av_image_copy_plane() to copy the complete frame dimensions from the persistent ctx->inflated_buf buffer, causing unwritten heap memory from prior allocations or prior frames to be copied into decoded output and potentially exposing sensitive data such as userspace addresses from persistent decoding services."},"relatedVulnerabilities":[]},{"artifact":{"id":"4173cf2fc659ac9d","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.12.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70630","versionConstraint":">= 3.0, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70630","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70630","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70630","date":"2026-10-08","epss":0.00175,"percentile":0.06355}],"risk":0.09756250000000001,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/705890061467ad550ecc1dad5eea07f28ccfb43e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/9a3202a98b2e095b54dd784c3e01a09a676fc3fa","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c22667d0fd7916a33fd3e79685b7246fc48f1a62","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23896","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-screenpresso-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70630","description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a crafted SPV1 packet with a valid zlib stream that decompresses fewer bytes than the full frame requires. The screenpresso_decode_frame() function fails to validate the produced byte count before calling av_image_copy_plane() to copy the complete frame dimensions from the persistent ctx->inflated_buf buffer, causing unwritten heap memory from prior allocations or prior frames to be copied into decoded output and potentially exposing sensitive data such as userspace addresses from persistent decoding services."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c11220a4fbbc883","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.26.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70630","versionConstraint":">= 3.0, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70630","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70630","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70630","date":"2026-10-08","epss":0.00175,"percentile":0.06355}],"risk":0.09756250000000001,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/705890061467ad550ecc1dad5eea07f28ccfb43e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/9a3202a98b2e095b54dd784c3e01a09a676fc3fa","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c22667d0fd7916a33fd3e79685b7246fc48f1a62","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23896","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-screenpresso-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70630","description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a crafted SPV1 packet with a valid zlib stream that decompresses fewer bytes than the full frame requires. The screenpresso_decode_frame() function fails to validate the produced byte count before calling av_image_copy_plane() to copy the complete frame dimensions from the persistent ctx->inflated_buf buffer, causing unwritten heap memory from prior allocations or prior frames to be copied into decoded output and potentially exposing sensitive data such as userspace addresses from persistent decoding services."},"relatedVulnerabilities":[]},{"artifact":{"id":"a3d12aa6031708d4","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.3.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70630","versionConstraint":">= 3.0, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70630","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70630","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70630","date":"2026-10-08","epss":0.00175,"percentile":0.06355}],"risk":0.09756250000000001,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/705890061467ad550ecc1dad5eea07f28ccfb43e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/9a3202a98b2e095b54dd784c3e01a09a676fc3fa","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c22667d0fd7916a33fd3e79685b7246fc48f1a62","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23896","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-screenpresso-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70630","description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a crafted SPV1 packet with a valid zlib stream that decompresses fewer bytes than the full frame requires. The screenpresso_decode_frame() function fails to validate the produced byte count before calling av_image_copy_plane() to copy the complete frame dimensions from the persistent ctx->inflated_buf buffer, causing unwritten heap memory from prior allocations or prior frames to be copied into decoded output and potentially exposing sensitive data such as userspace addresses from persistent decoding services."},"relatedVulnerabilities":[]},{"artifact":{"id":"cd1d29bf30c1bae9","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.62"},{"path":"/usr/lib/libavcodec.so.62.28.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70629","versionConstraint":">= 3.0, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70629","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70629","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70629","date":"2026-10-08","epss":0.00175,"percentile":0.06354}],"risk":0.09756250000000001,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/533a6198505edd1379e1cd722852350ae4a85acc","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a5fe21a1a410a680fe93c33b0dd696b7e1c3aea4","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/cd1f545cf27ba08f6f5b31b1e92665d7874d4fd7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23895","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-rscc-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70629","description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted video file with a compressed tile that decompresses fewer bytes than the declared tile geometry requires. When rscc_decode_frame() calls av_image_copy_plane() without validating the decompressed byte count against the tile dimensions, the unwritten suffix of the persistent intermediate buffer ctx->inflated_buf is copied into the decoded frame, potentially exposing data from prior heap allocations or previous decoded frames in persistent decoding services."},"relatedVulnerabilities":[]},{"artifact":{"id":"4173cf2fc659ac9d","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.62"},{"path":"/usr/lib/libavformat.so.62.12.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70629","versionConstraint":">= 3.0, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70629","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70629","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70629","date":"2026-10-08","epss":0.00175,"percentile":0.06354}],"risk":0.09756250000000001,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/533a6198505edd1379e1cd722852350ae4a85acc","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a5fe21a1a410a680fe93c33b0dd696b7e1c3aea4","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/cd1f545cf27ba08f6f5b31b1e92665d7874d4fd7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23895","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-rscc-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70629","description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted video file with a compressed tile that decompresses fewer bytes than the declared tile geometry requires. When rscc_decode_frame() calls av_image_copy_plane() without validating the decompressed byte count against the tile dimensions, the unwritten suffix of the persistent intermediate buffer ctx->inflated_buf is copied into the decoded frame, potentially exposing data from prior heap allocations or previous decoded frames in persistent decoding services."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c11220a4fbbc883","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.60"},{"path":"/usr/lib/libavutil.so.60.26.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70629","versionConstraint":">= 3.0, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70629","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70629","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70629","date":"2026-10-08","epss":0.00175,"percentile":0.06354}],"risk":0.09756250000000001,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/533a6198505edd1379e1cd722852350ae4a85acc","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a5fe21a1a410a680fe93c33b0dd696b7e1c3aea4","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/cd1f545cf27ba08f6f5b31b1e92665d7874d4fd7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23895","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-rscc-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70629","description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted video file with a compressed tile that decompresses fewer bytes than the declared tile geometry requires. When rscc_decode_frame() calls av_image_copy_plane() without validating the decompressed byte count against the tile dimensions, the unwritten suffix of the persistent intermediate buffer ctx->inflated_buf is copied into the decoded frame, potentially exposing data from prior heap allocations or previous decoded frames in persistent decoding services."},"relatedVulnerabilities":[]},{"artifact":{"id":"a3d12aa6031708d4","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:8.1.2-r0:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:8.1.2-r0:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@8.1.2-r0?arch=x86_64&distro=alpine-3.24.2&upstream=ffmpeg","type":"apk","version":"8.1.2-r0","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.6"},{"path":"/usr/lib/libswresample.so.6.3.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70629","versionConstraint":">= 3.0, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:8.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"8.1.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70629","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70629","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70629","date":"2026-10-08","epss":0.00175,"percentile":0.06354}],"risk":0.09756250000000001,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/533a6198505edd1379e1cd722852350ae4a85acc","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a5fe21a1a410a680fe93c33b0dd696b7e1c3aea4","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/cd1f545cf27ba08f6f5b31b1e92665d7874d4fd7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23895","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-rscc-decoder"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70629","description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted video file with a compressed tile that decompresses fewer bytes than the declared tile geometry requires. When rscc_decode_frame() calls av_image_copy_plane() without validating the decompressed byte count against the tile dimensions, the unwritten suffix of the persistent intermediate buffer ctx->inflated_buf is copied into the decoded frame, potentially exposing data from prior heap allocations or previous decoded frames in persistent decoding services."},"relatedVulnerabilities":[]},{"artifact":{"id":"6921667c3af65467","cpes":["cpe:2.3:a:coreutils:coreutils:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:apk/alpine/coreutils@9.11-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/base64"},{"path":"/bin/cat"},{"path":"/bin/chgrp"},{"path":"/bin/chmod"},{"path":"/bin/chown"},{"path":"/bin/coreutils"},{"path":"/bin/cp"},{"path":"/bin/date"},{"path":"/bin/dd"},{"path":"/bin/df"},{"path":"/bin/echo"},{"path":"/bin/false"},{"path":"/bin/link"},{"path":"/bin/ln"},{"path":"/bin/ls"},{"path":"/bin/mkdir"},{"path":"/bin/mknod"},{"path":"/bin/mktemp"},{"path":"/bin/mv"},{"path":"/bin/nice"},{"path":"/bin/printenv"},{"path":"/bin/pwd"},{"path":"/bin/rm"},{"path":"/bin/rmdir"},{"path":"/bin/sleep"},{"path":"/bin/stat"},{"path":"/bin/stty"},{"path":"/bin/sync"},{"path":"/bin/touch"},{"path":"/bin/true"},{"path":"/bin/uname"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/["},{"path":"/usr/bin/b2sum"},{"path":"/usr/bin/base32"},{"path":"/usr/bin/basename"},{"path":"/usr/bin/basenc"},{"path":"/usr/bin/cksum"},{"path":"/usr/bin/comm"},{"path":"/usr/bin/csplit"},{"path":"/usr/bin/cut"},{"path":"/usr/bin/dir"},{"path":"/usr/bin/dircolors"},{"path":"/usr/bin/dirname"},{"path":"/usr/bin/du"},{"path":"/usr/bin/expand"},{"path":"/usr/bin/expr"},{"path":"/usr/bin/factor"},{"path":"/usr/bin/fold"},{"path":"/usr/bin/head"},{"path":"/usr/bin/hostid"},{"path":"/usr/bin/id"},{"path":"/usr/bin/install"},{"path":"/usr/bin/join"},{"path":"/usr/bin/logname"},{"path":"/usr/bin/md5sum"},{"path":"/usr/bin/mkfifo"},{"path":"/usr/bin/nl"},{"path":"/usr/bin/nohup"},{"path":"/usr/bin/nproc"},{"path":"/usr/bin/numfmt"},{"path":"/usr/bin/od"},{"path":"/usr/bin/paste"},{"path":"/usr/bin/pathchk"},{"path":"/usr/bin/pinky"},{"path":"/usr/bin/pr"},{"path":"/usr/bin/printf"},{"path":"/usr/bin/ptx"},{"path":"/usr/bin/readlink"},{"path":"/usr/bin/realpath"},{"path":"/usr/bin/seq"},{"path":"/usr/bin/sha1sum"},{"path":"/usr/bin/sha224sum"},{"path":"/usr/bin/sha256sum"},{"path":"/usr/bin/sha384sum"},{"path":"/usr/bin/shred"},{"path":"/usr/bin/shuf"},{"path":"/usr/bin/sort"},{"path":"/usr/bin/split"},{"path":"/usr/bin/stdbuf"},{"path":"/usr/bin/sum"},{"path":"/usr/bin/tac"},{"path":"/usr/bin/tail"},{"path":"/usr/bin/tee"},{"path":"/usr/bin/test"},{"path":"/usr/bin/timeout"},{"path":"/usr/bin/tr"},{"path":"/usr/bin/truncate"},{"path":"/usr/bin/tsort"},{"path":"/usr/bin/tty"},{"path":"/usr/bin/unexpand"},{"path":"/usr/bin/uniq"},{"path":"/usr/bin/unlink"},{"path":"/usr/bin/users"},{"path":"/usr/bin/vdir"},{"path":"/usr/bin/wc"},{"path":"/usr/bin/who"},{"path":"/usr/bin/whoami"},{"path":"/usr/bin/yes"},{"path":"/usr/libexec"},{"path":"/usr/libexec/coreutils"},{"path":"/usr/libexec/coreutils/libstdbuf.so"},{"path":"/usr/sbin"},{"path":"/usr/sbin/chroot"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56391","versionConstraint":">= 9.5, <= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.0884925,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[]},{"artifact":{"id":"16361c4de507bb4c","cpes":["cpe:2.3:a:coreutils-env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_env:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-env","purl":"pkg:apk/alpine/coreutils-env@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/env"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56391","versionConstraint":">= 9.5, <= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.0884925,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c43a637992609b6","cpes":["cpe:2.3:a:coreutils-fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-fmt","purl":"pkg:apk/alpine/coreutils-fmt@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/fmt"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56391","versionConstraint":">= 9.5, <= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.0884925,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[]},{"artifact":{"id":"157238390cea3b89","cpes":["cpe:2.3:a:coreutils-sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-sha512sum","purl":"pkg:apk/alpine/coreutils-sha512sum@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/sha512sum"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56391","versionConstraint":">= 9.5, <= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.0884925,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[]},{"artifact":{"id":"6921667c3af65467","cpes":["cpe:2.3:a:coreutils:coreutils:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:apk/alpine/coreutils@9.11-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/base64"},{"path":"/bin/cat"},{"path":"/bin/chgrp"},{"path":"/bin/chmod"},{"path":"/bin/chown"},{"path":"/bin/coreutils"},{"path":"/bin/cp"},{"path":"/bin/date"},{"path":"/bin/dd"},{"path":"/bin/df"},{"path":"/bin/echo"},{"path":"/bin/false"},{"path":"/bin/link"},{"path":"/bin/ln"},{"path":"/bin/ls"},{"path":"/bin/mkdir"},{"path":"/bin/mknod"},{"path":"/bin/mktemp"},{"path":"/bin/mv"},{"path":"/bin/nice"},{"path":"/bin/printenv"},{"path":"/bin/pwd"},{"path":"/bin/rm"},{"path":"/bin/rmdir"},{"path":"/bin/sleep"},{"path":"/bin/stat"},{"path":"/bin/stty"},{"path":"/bin/sync"},{"path":"/bin/touch"},{"path":"/bin/true"},{"path":"/bin/uname"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/["},{"path":"/usr/bin/b2sum"},{"path":"/usr/bin/base32"},{"path":"/usr/bin/basename"},{"path":"/usr/bin/basenc"},{"path":"/usr/bin/cksum"},{"path":"/usr/bin/comm"},{"path":"/usr/bin/csplit"},{"path":"/usr/bin/cut"},{"path":"/usr/bin/dir"},{"path":"/usr/bin/dircolors"},{"path":"/usr/bin/dirname"},{"path":"/usr/bin/du"},{"path":"/usr/bin/expand"},{"path":"/usr/bin/expr"},{"path":"/usr/bin/factor"},{"path":"/usr/bin/fold"},{"path":"/usr/bin/head"},{"path":"/usr/bin/hostid"},{"path":"/usr/bin/id"},{"path":"/usr/bin/install"},{"path":"/usr/bin/join"},{"path":"/usr/bin/logname"},{"path":"/usr/bin/md5sum"},{"path":"/usr/bin/mkfifo"},{"path":"/usr/bin/nl"},{"path":"/usr/bin/nohup"},{"path":"/usr/bin/nproc"},{"path":"/usr/bin/numfmt"},{"path":"/usr/bin/od"},{"path":"/usr/bin/paste"},{"path":"/usr/bin/pathchk"},{"path":"/usr/bin/pinky"},{"path":"/usr/bin/pr"},{"path":"/usr/bin/printf"},{"path":"/usr/bin/ptx"},{"path":"/usr/bin/readlink"},{"path":"/usr/bin/realpath"},{"path":"/usr/bin/seq"},{"path":"/usr/bin/sha1sum"},{"path":"/usr/bin/sha224sum"},{"path":"/usr/bin/sha256sum"},{"path":"/usr/bin/sha384sum"},{"path":"/usr/bin/shred"},{"path":"/usr/bin/shuf"},{"path":"/usr/bin/sort"},{"path":"/usr/bin/split"},{"path":"/usr/bin/stdbuf"},{"path":"/usr/bin/sum"},{"path":"/usr/bin/tac"},{"path":"/usr/bin/tail"},{"path":"/usr/bin/tee"},{"path":"/usr/bin/test"},{"path":"/usr/bin/timeout"},{"path":"/usr/bin/tr"},{"path":"/usr/bin/truncate"},{"path":"/usr/bin/tsort"},{"path":"/usr/bin/tty"},{"path":"/usr/bin/unexpand"},{"path":"/usr/bin/uniq"},{"path":"/usr/bin/unlink"},{"path":"/usr/bin/users"},{"path":"/usr/bin/vdir"},{"path":"/usr/bin/wc"},{"path":"/usr/bin/who"},{"path":"/usr/bin/whoami"},{"path":"/usr/bin/yes"},{"path":"/usr/libexec"},{"path":"/usr/libexec/coreutils"},{"path":"/usr/libexec/coreutils/libstdbuf.so"},{"path":"/usr/sbin"},{"path":"/usr/sbin/chroot"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56392","versionConstraint":"= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56392","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56392","cwe":"CWE-122","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56392","date":"2026-10-08","epss":0.00186,"percentile":0.07525}],"risk":0.083235,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56392","description":"GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"},"relatedVulnerabilities":[]},{"artifact":{"id":"16361c4de507bb4c","cpes":["cpe:2.3:a:coreutils-env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_env:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-env","purl":"pkg:apk/alpine/coreutils-env@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/env"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56392","versionConstraint":"= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56392","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56392","cwe":"CWE-122","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56392","date":"2026-10-08","epss":0.00186,"percentile":0.07525}],"risk":0.083235,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56392","description":"GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"},"relatedVulnerabilities":[]},{"artifact":{"id":"0c43a637992609b6","cpes":["cpe:2.3:a:coreutils-fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-fmt","purl":"pkg:apk/alpine/coreutils-fmt@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/fmt"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56392","versionConstraint":"= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56392","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56392","cwe":"CWE-122","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56392","date":"2026-10-08","epss":0.00186,"percentile":0.07525}],"risk":0.083235,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56392","description":"GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"},"relatedVulnerabilities":[]},{"artifact":{"id":"157238390cea3b89","cpes":["cpe:2.3:a:coreutils-sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-sha512sum","purl":"pkg:apk/alpine/coreutils-sha512sum@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/sha512sum"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56392","versionConstraint":"= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56392","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56392","cwe":"CWE-122","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56392","date":"2026-10-08","epss":0.00186,"percentile":0.07525}],"risk":0.083235,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56392","description":"GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"},"relatedVulnerabilities":[]},{"artifact":{"id":"cbd77e4fe96fe423","cpes":["cpe:2.3:a:rust-random:rand:0.9.1:*:*:*:*:rust:*:*"],"name":"rand","purl":"pkg:cargo/rand@0.9.1","type":"rust-crate","version":"0.9.1","language":"rust","licenses":[],"locations":[{"path":"/usr/lib/librav1e.so.0.8.1","layerID":"sha256:4d1e5cfa3a9b1e28d36aa4a59e8750799c05de209544243aeee8948d6e82e916","accessPath":"/usr/lib/librav1e.so.0.8.1","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.9.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cq8v-f236-94qc","versionConstraint":">=0.9.0,<0.9.3 (unknown)"},"matcher":"rust-matcher","searchedBy":{"package":{"name":"rand","version":"0.9.1"},"language":"rust","namespace":"github:language:rust"}}],"vulnerability":{"id":"GHSA-cq8v-f236-94qc","fix":{"state":"fixed","versions":["0.9.3"],"available":[{"date":"2026-04-14","kind":"first-observed","version":"0.9.3"}]},"cvss":[],"risk":0,"urls":["https://github.com/rust-random/rand/pull/1763","https://rustsec.org/advisories/RUSTSEC-2026-0097.html"],"severity":"Low","namespace":"github:language:rust","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cq8v-f236-94qc","description":"Rand is unsound with a custom logger using rand::rng()"},"relatedVulnerabilities":[]}],"grade":"F","score":"0.00","as_of":"2026-10-09T23:19:06.641Z","grype_db_version":"2026-10-09T06:32:32.000Z"}