{"grype_matches":[{"artifact":{"id":"97c784845da42004","cpes":["cpe:2.3:a:squizlabs\\/php-codesniffer:squizlabs\\/php-codesniffer:3.13.5:*:*:*:*:*:*:*","cpe:2.3:a:squizlabs\\/php-codesniffer:squizlabs\\/php_codesniffer:3.13.5:*:*:*:*:*:*:*","cpe:2.3:a:squizlabs\\/php_codesniffer:squizlabs\\/php-codesniffer:3.13.5:*:*:*:*:*:*:*","cpe:2.3:a:squizlabs\\/php_codesniffer:squizlabs\\/php_codesniffer:3.13.5:*:*:*:*:*:*:*","cpe:2.3:a:squizlabs\\/php:squizlabs\\/php-codesniffer:3.13.5:*:*:*:*:*:*:*","cpe:2.3:a:squizlabs\\/php:squizlabs\\/php_codesniffer:3.13.5:*:*:*:*:*:*:*"],"name":"squizlabs/php_codesniffer","purl":"pkg:composer/squizlabs/php_codesniffer@3.13.5","type":"php-composer","version":"3.13.5","language":"php","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.13.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hmqg-cxww-wqhq","versionConstraint":"<3.13.6 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"squizlabs/php_codesniffer","version":"3.13.5"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-hmqg-cxww-wqhq","fix":{"state":"fixed","versions":["3.13.6"],"available":[{"date":"2026-08-07","kind":"first-observed","version":"3.13.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-67434","cwe":"CWE-78","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-67434","date":"2026-10-08","epss":0.01063,"percentile":0.63605}],"risk":0.78662,"urls":["https://github.com/PHPCSStandards/PHP_CodeSniffer/security/advisories/GHSA-hmqg-cxww-wqhq","https://github.com/PHPCSStandards/PHP_CodeSniffer/pull/1473","https://github.com/PHPCSStandards/PHP_CodeSniffer/commit/7a3a6bbf153a03fa3a9413afc60bded6b764e76b","https://github.com/PHPCSStandards/PHP_CodeSniffer/commit/f0e1ebb0563f0e5d7f190497a787bcaf8474f3fe","https://github.com/FriendsOfPHP/security-advisories/blob/master/squizlabs/php_codesniffer/CVE-2026-67434.yaml","https://github.com/PHPCSStandards/PHP_CodeSniffer/releases/tag/3.13.6","https://github.com/PHPCSStandards/PHP_CodeSniffer/releases/tag/4.0.2"],"severity":"High","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hmqg-cxww-wqhq","description":"PHP_CodeSniffer gitblame report command injection via crafted filename"},"relatedVulnerabilities":[{"id":"CVE-2026-67434","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-67434","cwe":"CWE-78","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-67434","date":"2026-10-08","epss":0.01063,"percentile":0.63605}],"urls":["https://github.com/PHPCSStandards/PHP_CodeSniffer/commit/7a3a6bbf153a03fa3a9413afc60bded6b764e76b","https://github.com/PHPCSStandards/PHP_CodeSniffer/commit/f0e1ebb0563f0e5d7f190497a787bcaf8474f3fe","https://github.com/PHPCSStandards/PHP_CodeSniffer/pull/1473","https://github.com/PHPCSStandards/PHP_CodeSniffer/releases/tag/3.13.6","https://github.com/PHPCSStandards/PHP_CodeSniffer/releases/tag/4.0.2","https://github.com/PHPCSStandards/PHP_CodeSniffer/security/advisories/GHSA-hmqg-cxww-wqhq"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-67434","description":"PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13.6 and 4.0.2, PHP_CodeSniffer contains a command injection vulnerability in the code that generates the Gitblame, Hgblame, and Svnblame report formats. As a result, running PHP_CodeSniffer over untrusted files, for example in a continuous integration pipeline that scans pull requests, or on a developer machine reviewing third party code, could result in attacker controlled shell commands being executed when the Gitblame, Hgblame, or Svnblame report processes a file whose name contains shell metacharacters. Users using the default Full report, or any of the other non-blame reports, are not affected. Users on a runtime platform which does not allow filenames to contain shell metacharacters, such as \" and ;, are not affected. This issue is fixed in versions 3.13.6 and 4.0.2."}]},{"artifact":{"id":"e964e2f6e76929df","cpes":["cpe:2.3:a:league\\/commonmark:league\\/commonmark:2.8.2:*:*:*:*:*:*:*"],"name":"league/commonmark","purl":"pkg:composer/league/commonmark@2.8.2","type":"php-composer","version":"2.8.2","language":"php","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.9.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-2q4p-g7hv-5rgv","versionConstraint":">=0.6.0,<2.9.0 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"league/commonmark","version":"2.8.2"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-2q4p-g7hv-5rgv","fix":{"state":"fixed","versions":["2.9.0"],"available":[{"date":"2026-08-07","kind":"first-observed","version":"2.9.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-71488","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-71488","cwe":"CWE-1050","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-71488","date":"2026-10-08","epss":0.0063,"percentile":0.48561}],"risk":0.47250000000000003,"urls":["https://github.com/thephpleague/commonmark/security/advisories/GHSA-2q4p-g7hv-5rgv","https://github.com/thephpleague/commonmark/commit/a6ef6cdc308dfa39a34239c35818e75892a0e6a8","https://github.com/thephpleague/commonmark/commit/a70979ea0d7d3377bd7127536748454a922bf5eb","https://github.com/thephpleague/commonmark/commit/c97b02e5e652b992033b93ba5d6182f706343fc6","https://github.com/thephpleague/commonmark/releases/tag/2.9.0"],"severity":"High","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-2q4p-g7hv-5rgv","description":"league/commonmark: Quadratic-time denial of service when parsing crafted Markdown"},"relatedVulnerabilities":[{"id":"CVE-2026-71488","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-71488","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-71488","cwe":"CWE-1050","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-71488","date":"2026-10-08","epss":0.0063,"percentile":0.48561}],"urls":["https://github.com/thephpleague/commonmark/commit/a6ef6cdc308dfa39a34239c35818e75892a0e6a8","https://github.com/thephpleague/commonmark/commit/a70979ea0d7d3377bd7127536748454a922bf5eb","https://github.com/thephpleague/commonmark/commit/c97b02e5e652b992033b93ba5d6182f706343fc6","https://github.com/thephpleague/commonmark/releases/tag/2.9.0","https://github.com/thephpleague/commonmark/security/advisories/GHSA-2q4p-g7hv-5rgv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-71488","description":"league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several parsing paths repeatedly rescan growing portions of a line to translate between character positions and byte positions, and the Autolink extension can also copy and validate the remaining line at every URL-like prefix, allowing an attacker who can submit Markdown for conversion to consume disproportionate CPU time with a comparatively small request. This issue is fixed in 2.9.0."}]},{"artifact":{"id":"eb222fe89d397776","cpes":["cpe:2.3:a:zlib:zlib:1.3.2-r0:*:*:*:*:*:*:*"],"name":"zlib","purl":"pkg:apk/alpine/zlib@1.3.2-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"1.3.2-r0","language":"","licenses":["Zlib"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libz.so.1"},{"path":"/usr/lib/libz.so.1.3.2"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"zlib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.3.2-r1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"< 1.3.2-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.2"},"package":{"name":"zlib","version":"1.3.2-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"1.3.2-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"< 1.3.2-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.2"},"package":{"name":"zlib","version":"1.3.2-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-85091","fix":{"state":"fixed","versions":["1.3.2-r1"],"available":[{"date":"2026-10-07","kind":"first-observed","version":"1.3.2-r1"}]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"risk":0.28124,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-85091"},"relatedVulnerabilities":[{"id":"CVE-2026-85091","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."}]},{"artifact":{"id":"8c29de47f797c6e9","cpes":["cpe:2.3:a:guzzlehttp\\/guzzle:guzzlehttp\\/guzzle:7.13.3:*:*:*:*:*:*:*"],"name":"guzzlehttp/guzzle","purl":"pkg:composer/guzzlehttp/guzzle@7.13.3","type":"php-composer","version":"7.13.3","language":"php","licenses":["MIT"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.15.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-v5mv-p594-2x33","versionConstraint":"<7.15.2 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"guzzlehttp/guzzle","version":"7.13.3"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-v5mv-p594-2x33","fix":{"state":"fixed","versions":["7.15.2"],"available":[{"date":"2026-08-04","kind":"first-observed","version":"7.15.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69246","cwe":"CWE-180","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69246","cwe":"CWE-436","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69246","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69246","cwe":"CWE-941","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69246","date":"2026-10-08","epss":0.0037,"percentile":0.28843}],"risk":0.27195,"urls":["https://github.com/guzzle/guzzle/security/advisories/GHSA-v5mv-p594-2x33","https://github.com/guzzle/guzzle/pull/3907","https://github.com/guzzle/guzzle/pull/3908","https://github.com/guzzle/guzzle/commit/3aeea0406aab88cbbd86531313d7cebf8ae149a4","https://github.com/guzzle/guzzle/commit/744101956d78b7c1384d0cbf379db13e859167bf","https://github.com/guzzle/guzzle/releases/tag/7.15.2","https://github.com/guzzle/guzzle/releases/tag/8.0.1"],"severity":"High","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-v5mv-p594-2x33","description":"Guzzle: Noncanonical host can bypass host-based checks"},"relatedVulnerabilities":[{"id":"CVE-2026-69246","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69246","cwe":"CWE-180","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69246","cwe":"CWE-436","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69246","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69246","cwe":"CWE-941","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69246","date":"2026-10-08","epss":0.0037,"percentile":0.28843}],"urls":["https://github.com/guzzle/guzzle/commit/3aeea0406aab88cbbd86531313d7cebf8ae149a4","https://github.com/guzzle/guzzle/commit/744101956d78b7c1384d0cbf379db13e859167bf","https://github.com/guzzle/guzzle/pull/3907","https://github.com/guzzle/guzzle/pull/3908","https://github.com/guzzle/guzzle/releases/tag/7.15.2","https://github.com/guzzle/guzzle/releases/tag/8.0.1","https://github.com/guzzle/guzzle/security/advisories/GHSA-v5mv-p594-2x33"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-69246","description":"Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push that Host into CURLOPT_HTTPHEADER; StreamHandler does the same through fopen(). libcurl then parses the authority itself, percent-decoding it and, on an IDN-capable build, applying IDNA mapping, and uses the result to resolve, connect, name the TLS peer and address a proxy CONNECT, while the supplied Host suppresses the aligned one libcurl would have generated. For a URI host written as 127.0.0.%31, filter_var() rejects the host as an IP literal, yet libcurl decodes it to 127.0.0.1 and reaches loopback with no DNS lookup while the server receives Host: 127.0.0.%31. An attacker who influences a fetched URI can therefore reach a host the application's checks excluded and read whatever the host exposes of the response. The same divergence moves Guzzle's own decisions onto a spelling the transport does not use: no_proxy selects proxy routing from the literal host, and RedirectMiddleware decides from it whether to strip Authorization and Cookie. Exploitation requires the application to build a request URI from untrusted input and to make a host decision before handing it to Guzzle. This issue is fixed in versions 7.15.2 and 8.0.1."}]},{"artifact":{"id":"8c29de47f797c6e9","cpes":["cpe:2.3:a:guzzlehttp\\/guzzle:guzzlehttp\\/guzzle:7.13.3:*:*:*:*:*:*:*"],"name":"guzzlehttp/guzzle","purl":"pkg:composer/guzzlehttp/guzzle@7.13.3","type":"php-composer","version":"7.13.3","language":"php","licenses":["MIT"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.15.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-f283-ghqc-fg79","versionConstraint":"<7.15.1 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"guzzlehttp/guzzle","version":"7.13.3"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-f283-ghqc-fg79","fix":{"state":"fixed","versions":["7.15.1"],"available":[{"date":"2026-07-21","kind":"first-observed","version":"7.15.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-67353","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-67353","date":"2026-10-08","epss":0.00418,"percentile":0.34076}],"risk":0.21527,"urls":["https://github.com/guzzle/guzzle/security/advisories/GHSA-f283-ghqc-fg79","https://github.com/guzzle/guzzle/pull/3901","https://github.com/guzzle/guzzle/commit/7b68220d6543f6f80fe62e633361fc9d4ead14d4","https://github.com/guzzle/guzzle/releases/tag/7.15.1","https://nvd.nist.gov/vuln/detail/CVE-2026-67353","https://www.vulncheck.com/advisories/guzzlehttp-guzzle-before-unbounded-cookie-denial-of-service"],"severity":"Medium","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-f283-ghqc-fg79","description":"Guzzle: Unbounded response cookies risk denial of service"},"relatedVulnerabilities":[{"id":"CVE-2026-67353","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-67353","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-67353","date":"2026-10-08","epss":0.00418,"percentile":0.34076}],"urls":["https://github.com/guzzle/guzzle/security/advisories/GHSA-f283-ghqc-fg79","https://www.vulncheck.com/advisories/guzzlehttp-guzzle-before-unbounded-cookie-denial-of-service"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-67353","description":"guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data in memory and generate oversized Cookie headers that fail in handlers or destination servers."}]},{"artifact":{"id":"8c29de47f797c6e9","cpes":["cpe:2.3:a:guzzlehttp\\/guzzle:guzzlehttp\\/guzzle:7.13.3:*:*:*:*:*:*:*"],"name":"guzzlehttp/guzzle","purl":"pkg:composer/guzzlehttp/guzzle@7.13.3","type":"php-composer","version":"7.13.3","language":"php","licenses":["MIT"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.15.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-h95v-h523-3mw8","versionConstraint":"<7.15.1 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"guzzlehttp/guzzle","version":"7.13.3"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-h95v-h523-3mw8","fix":{"state":"fixed","versions":["7.15.1"],"available":[{"date":"2026-07-21","kind":"first-observed","version":"7.15.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-67354","cwe":"CWE-201","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-67354","date":"2026-10-08","epss":0.00372,"percentile":0.29086}],"risk":0.20274000000000003,"urls":["https://github.com/guzzle/guzzle/security/advisories/GHSA-h95v-h523-3mw8","https://github.com/guzzle/guzzle/pull/3901","https://github.com/guzzle/guzzle/commit/7b68220d6543f6f80fe62e633361fc9d4ead14d4","https://github.com/guzzle/guzzle/releases/tag/7.15.1","https://nvd.nist.gov/vuln/detail/CVE-2026-67354","https://www.vulncheck.com/advisories/guzzlehttp-guzzle-before-uri-fragment-disclosure-via-referer"],"severity":"Medium","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-h95v-h523-3mw8","description":"Guzzle: URI fragments disclosed in redirect Referer headers"},"relatedVulnerabilities":[{"id":"CVE-2026-67354","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-67354","cwe":"CWE-201","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-67354","date":"2026-10-08","epss":0.00372,"percentile":0.29086}],"urls":["https://github.com/guzzle/guzzle/security/advisories/GHSA-h95v-h523-3mw8","https://www.vulncheck.com/advisories/guzzlehttp-guzzle-before-uri-fragment-disclosure-via-referer"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-67354","description":"guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the portion after '#') from the referring request into the generated Referer header when following a same-scheme redirect (e.g., HTTPS to HTTPS). An attacker who controls the redirect destination can read this fragment from the incoming Referer header, potentially disclosing one-time login secrets, access tokens, state values, or other sensitive client data to a server never meant to receive it. The referer setting is disabled by default. Fixed in 7.15.1, which strips the fragment before generating the Referer value."}]},{"artifact":{"id":"6921667c3af65467","cpes":["cpe:2.3:a:coreutils:coreutils:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:apk/alpine/coreutils@9.11-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/base64"},{"path":"/bin/cat"},{"path":"/bin/chgrp"},{"path":"/bin/chmod"},{"path":"/bin/chown"},{"path":"/bin/coreutils"},{"path":"/bin/cp"},{"path":"/bin/date"},{"path":"/bin/dd"},{"path":"/bin/df"},{"path":"/bin/echo"},{"path":"/bin/false"},{"path":"/bin/link"},{"path":"/bin/ln"},{"path":"/bin/ls"},{"path":"/bin/mkdir"},{"path":"/bin/mknod"},{"path":"/bin/mktemp"},{"path":"/bin/mv"},{"path":"/bin/nice"},{"path":"/bin/printenv"},{"path":"/bin/pwd"},{"path":"/bin/rm"},{"path":"/bin/rmdir"},{"path":"/bin/sleep"},{"path":"/bin/stat"},{"path":"/bin/stty"},{"path":"/bin/sync"},{"path":"/bin/touch"},{"path":"/bin/true"},{"path":"/bin/uname"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/["},{"path":"/usr/bin/b2sum"},{"path":"/usr/bin/base32"},{"path":"/usr/bin/basename"},{"path":"/usr/bin/basenc"},{"path":"/usr/bin/cksum"},{"path":"/usr/bin/comm"},{"path":"/usr/bin/csplit"},{"path":"/usr/bin/cut"},{"path":"/usr/bin/dir"},{"path":"/usr/bin/dircolors"},{"path":"/usr/bin/dirname"},{"path":"/usr/bin/du"},{"path":"/usr/bin/expand"},{"path":"/usr/bin/expr"},{"path":"/usr/bin/factor"},{"path":"/usr/bin/fold"},{"path":"/usr/bin/head"},{"path":"/usr/bin/hostid"},{"path":"/usr/bin/id"},{"path":"/usr/bin/install"},{"path":"/usr/bin/join"},{"path":"/usr/bin/logname"},{"path":"/usr/bin/md5sum"},{"path":"/usr/bin/mkfifo"},{"path":"/usr/bin/nl"},{"path":"/usr/bin/nohup"},{"path":"/usr/bin/nproc"},{"path":"/usr/bin/numfmt"},{"path":"/usr/bin/od"},{"path":"/usr/bin/paste"},{"path":"/usr/bin/pathchk"},{"path":"/usr/bin/pinky"},{"path":"/usr/bin/pr"},{"path":"/usr/bin/printf"},{"path":"/usr/bin/ptx"},{"path":"/usr/bin/readlink"},{"path":"/usr/bin/realpath"},{"path":"/usr/bin/seq"},{"path":"/usr/bin/sha1sum"},{"path":"/usr/bin/sha224sum"},{"path":"/usr/bin/sha256sum"},{"path":"/usr/bin/sha384sum"},{"path":"/usr/bin/shred"},{"path":"/usr/bin/shuf"},{"path":"/usr/bin/sort"},{"path":"/usr/bin/split"},{"path":"/usr/bin/stdbuf"},{"path":"/usr/bin/sum"},{"path":"/usr/bin/tac"},{"path":"/usr/bin/tail"},{"path":"/usr/bin/tee"},{"path":"/usr/bin/test"},{"path":"/usr/bin/timeout"},{"path":"/usr/bin/tr"},{"path":"/usr/bin/truncate"},{"path":"/usr/bin/tsort"},{"path":"/usr/bin/tty"},{"path":"/usr/bin/unexpand"},{"path":"/usr/bin/uniq"},{"path":"/usr/bin/unlink"},{"path":"/usr/bin/users"},{"path":"/usr/bin/vdir"},{"path":"/usr/bin/wc"},{"path":"/usr/bin/who"},{"path":"/usr/bin/whoami"},{"path":"/usr/bin/yes"},{"path":"/usr/libexec"},{"path":"/usr/libexec/coreutils"},{"path":"/usr/libexec/coreutils/libstdbuf.so"},{"path":"/usr/sbin"},{"path":"/usr/sbin/chroot"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"16361c4de507bb4c","cpes":["cpe:2.3:a:coreutils-env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_env:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-env","purl":"pkg:apk/alpine/coreutils-env@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/env"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c43a637992609b6","cpes":["cpe:2.3:a:coreutils-fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-fmt","purl":"pkg:apk/alpine/coreutils-fmt@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/fmt"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"157238390cea3b89","cpes":["cpe:2.3:a:coreutils-sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-sha512sum","purl":"pkg:apk/alpine/coreutils-sha512sum@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/sha512sum"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"8c29de47f797c6e9","cpes":["cpe:2.3:a:guzzlehttp\\/guzzle:guzzlehttp\\/guzzle:7.13.3:*:*:*:*:*:*:*"],"name":"guzzlehttp/guzzle","purl":"pkg:composer/guzzlehttp/guzzle@7.13.3","type":"php-composer","version":"7.13.3","language":"php","licenses":["MIT"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.15.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wm3w-8rrp-j577","versionConstraint":"<7.15.1 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"guzzlehttp/guzzle","version":"7.13.3"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-wm3w-8rrp-j577","fix":{"state":"fixed","versions":["7.15.1"],"available":[{"date":"2026-07-21","kind":"first-observed","version":"7.15.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-67355","cwe":"CWE-201","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-67355","date":"2026-10-08","epss":0.00366,"percentile":0.28387}],"risk":0.19947000000000004,"urls":["https://github.com/guzzle/guzzle/security/advisories/GHSA-wm3w-8rrp-j577","https://github.com/guzzle/guzzle/pull/3901","https://github.com/guzzle/guzzle/commit/7b68220d6543f6f80fe62e633361fc9d4ead14d4","https://github.com/guzzle/guzzle/releases/tag/7.15.1","https://nvd.nist.gov/vuln/detail/CVE-2026-67355","https://www.vulncheck.com/advisories/guzzlehttp-guzzle-before-host-only-cookie-scope"],"severity":"Medium","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wm3w-8rrp-j577","description":"Guzzle: Host-only cookie scope is not preserved"},"relatedVulnerabilities":[{"id":"CVE-2026-67355","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-67355","cwe":"CWE-201","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-67355","date":"2026-10-08","epss":0.00366,"percentile":0.28387}],"urls":["https://github.com/guzzle/guzzle/security/advisories/GHSA-wm3w-8rrp-j577","https://www.vulncheck.com/advisories/guzzlehttp-guzzle-before-host-only-cookie-scope"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-67355","description":"guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. Attackers controlling child hosts can receive host-only cookies intended only for parent hosts, potentially disclosing session identifiers and authorization tokens when the same cookie jar is reused across trust boundaries."}]},{"artifact":{"id":"e964e2f6e76929df","cpes":["cpe:2.3:a:league\\/commonmark:league\\/commonmark:2.8.2:*:*:*:*:*:*:*"],"name":"league/commonmark","purl":"pkg:composer/league/commonmark@2.8.2","type":"php-composer","version":"2.8.2","language":"php","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.9.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-29pj-957v-52mc","versionConstraint":">=1.5.0,<=2.8.3 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"league/commonmark","version":"2.8.2"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-29pj-957v-52mc","fix":{"state":"fixed","versions":["2.9.0"],"available":[{"date":"2026-08-07","kind":"first-observed","version":"2.9.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-71478","cwe":"CWE-79","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-71478","cwe":"CWE-86","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-71478","cwe":"CWE-692","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-71478","date":"2026-10-08","epss":0.00355,"percentile":0.27139}],"risk":0.19702499999999998,"urls":["https://github.com/thephpleague/commonmark/security/advisories/GHSA-29pj-957v-52mc","https://github.com/thephpleague/commonmark/commit/493a5aa7d65754b73846006eaff9c2c4431a8e2c","https://github.com/thephpleague/commonmark/releases/tag/2.9.0"],"severity":"Medium","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-29pj-957v-52mc","description":"league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes"},"relatedVulnerabilities":[{"id":"CVE-2026-71478","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-71478","cwe":"CWE-79","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-71478","cwe":"CWE-86","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-71478","cwe":"CWE-692","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-71478","date":"2026-10-08","epss":0.00355,"percentile":0.27139}],"urls":["https://github.com/thephpleague/commonmark/commit/493a5aa7d65754b73846006eaff9c2c4431a8e2c","https://github.com/thephpleague/commonmark/releases/tag/2.9.0","https://github.com/thephpleague/commonmark/security/advisories/GHSA-29pj-957v-52mc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-71478","description":"league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab, carriage return, line feed, or leading C0 control character, in a javascript: URL that browsers discard before parsing the scheme, causing the browser to still execute the script even when the unsafe-link filter is enabled. This issue is fixed in 2.9.0."}]},{"artifact":{"id":"8c29de47f797c6e9","cpes":["cpe:2.3:a:guzzlehttp\\/guzzle:guzzlehttp\\/guzzle:7.13.3:*:*:*:*:*:*:*"],"name":"guzzlehttp/guzzle","purl":"pkg:composer/guzzlehttp/guzzle@7.13.3","type":"php-composer","version":"7.13.3","language":"php","licenses":["MIT"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.14.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-94pj-82f3-465w","versionConstraint":"<7.14.2 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"guzzlehttp/guzzle","version":"7.13.3"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-94pj-82f3-465w","fix":{"state":"fixed","versions":["7.14.2"],"available":[{"date":"2026-07-21","kind":"first-observed","version":"7.14.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-67339","cwe":"CWE-200","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-67339","date":"2026-10-08","epss":0.00372,"percentile":0.29061}],"risk":0.19158,"urls":["https://github.com/guzzle/guzzle/security/advisories/GHSA-94pj-82f3-465w","https://github.com/guzzle/guzzle/pull/3876","https://github.com/guzzle/guzzle/commit/9e4580d4b9981e903dc6323fe37f50a96e85b05e","https://github.com/guzzle/guzzle/releases/tag/7.14.2","https://nvd.nist.gov/vuln/detail/CVE-2026-67339","https://www.vulncheck.com/advisories/guzzlehttp-guzzle-before-proxy-authorization-header-disclosure"],"severity":"Medium","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-94pj-82f3-465w","description":"Guzzle: Proxy-Authorization headers can be sent to origin servers"},"relatedVulnerabilities":[{"id":"CVE-2026-67339","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-67339","cwe":"CWE-200","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-67339","date":"2026-10-08","epss":0.00372,"percentile":0.29061}],"urls":["https://github.com/guzzle/guzzle/security/advisories/GHSA-94pj-82f3-465w","https://www.vulncheck.com/advisories/guzzlehttp-guzzle-before-proxy-authorization-header-disclosure"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-67339","description":"guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies that Guzzle misclassifies as direct connections."}]},{"artifact":{"id":"fef07e9c95ea2bda","cpes":["cpe:2.3:a:busybox:busybox:1.37.0-r31:*:*:*:*:*:*:*"],"name":"busybox","purl":"pkg:apk/alpine/busybox@1.37.0-r31?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"1.37.0-r31","language":"","licenses":["GPL-2.0-only"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/busybox"},{"path":"/etc"},{"path":"/etc/securetty"},{"path":"/etc/busybox-paths.d"},{"path":"/etc/busybox-paths.d/busybox"},{"path":"/etc/logrotate.d"},{"path":"/etc/logrotate.d/acpid"},{"path":"/etc/network"},{"path":"/etc/network/if-down.d"},{"path":"/etc/network/if-post-down.d"},{"path":"/etc/network/if-post-up.d"},{"path":"/etc/network/if-pre-down.d"},{"path":"/etc/network/if-pre-up.d"},{"path":"/etc/network/if-up.d"},{"path":"/etc/network/if-up.d/dad"},{"path":"/etc/udhcpc"},{"path":"/etc/udhcpc/udhcpc.conf"},{"path":"/sbin"},{"path":"/usr"},{"path":"/usr/sbin"},{"path":"/usr/share"},{"path":"/usr/share/udhcpc"},{"path":"/usr/share/udhcpc/default.script"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"busybox"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-60876","versionConstraint":"<= 1.37.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:busybox:busybox:1.37.0:*:*:*:*:*:*:*"],"package":{"name":"busybox","version":"1.37.0-r31"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-60876","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-60876","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-60876","date":"2026-10-08","epss":0.00291,"percentile":0.19874}],"risk":0.16732499999999997,"urls":["https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092","https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm","https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-60876","description":"BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20)."},"relatedVulnerabilities":[]},{"artifact":{"id":"915155597fcdee9a","cpes":["cpe:2.3:a:busybox-binsh:busybox-binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox-binsh:busybox_binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox_binsh:busybox-binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox_binsh:busybox_binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox:busybox-binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox:busybox_binsh:1.37.0-r31:*:*:*:*:*:*:*"],"name":"busybox-binsh","purl":"pkg:apk/alpine/busybox-binsh@1.37.0-r31?arch=x86_64&distro=alpine-3.24.2&upstream=busybox","type":"apk","version":"1.37.0-r31","language":"","licenses":["GPL-2.0-only"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/sh"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"busybox"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-60876","versionConstraint":"<= 1.37.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:busybox:busybox:1.37.0:*:*:*:*:*:*:*"],"package":{"name":"busybox","version":"1.37.0-r31"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-60876","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-60876","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-60876","date":"2026-10-08","epss":0.00291,"percentile":0.19874}],"risk":0.16732499999999997,"urls":["https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092","https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm","https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-60876","description":"BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20)."},"relatedVulnerabilities":[]},{"artifact":{"id":"8a9ef44e1018f213","cpes":["cpe:2.3:a:ssl-client:ssl-client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl-client:ssl_client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl_client:ssl-client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl_client:ssl_client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl:ssl-client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl:ssl_client:1.37.0-r31:*:*:*:*:*:*:*"],"name":"ssl_client","purl":"pkg:apk/alpine/ssl_client@1.37.0-r31?arch=x86_64&distro=alpine-3.24.2&upstream=busybox","type":"apk","version":"1.37.0-r31","language":"","licenses":["GPL-2.0-only"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssl_client"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"busybox"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-60876","versionConstraint":"<= 1.37.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:busybox:busybox:1.37.0:*:*:*:*:*:*:*"],"package":{"name":"busybox","version":"1.37.0-r31"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-60876","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-60876","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-60876","date":"2026-10-08","epss":0.00291,"percentile":0.19874}],"risk":0.16732499999999997,"urls":["https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092","https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm","https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-60876","description":"BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20)."},"relatedVulnerabilities":[]},{"artifact":{"id":"23b1b1d87f1363da","cpes":["cpe:2.3:a:nginx:nginx:1.30.4-r1:*:*:*:*:*:*:*"],"name":"nginx","purl":"pkg:apk/alpine/nginx@1.30.4-r1?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"1.30.4-r1","language":"","licenses":["BSD-2-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/logrotate.d"},{"path":"/etc/logrotate.d/nginx"},{"path":"/etc/nginx"},{"path":"/etc/nginx/fastcgi.conf"},{"path":"/etc/nginx/fastcgi_params"},{"path":"/etc/nginx/mime.types"},{"path":"/etc/nginx/nginx.conf"},{"path":"/etc/nginx/scgi_params"},{"path":"/etc/nginx/uwsgi_params"},{"path":"/etc/nginx/http.d"},{"path":"/etc/nginx/modules"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/nginx"},{"path":"/usr/lib/nginx/modules"},{"path":"/usr/sbin"},{"path":"/usr/sbin/nginx"},{"path":"/usr/share"},{"path":"/usr/share/nginx"},{"path":"/usr/share/nginx/http-default_server.conf"},{"path":"/var"},{"path":"/var/lib"},{"path":"/var/lib/nginx"},{"path":"/var/lib/nginx/logs"},{"path":"/var/lib/nginx/modules"},{"path":"/var/lib/nginx/run"},{"path":"/var/lib/nginx/html"},{"path":"/var/lib/nginx/html/50x.html"},{"path":"/var/lib/nginx/html/index.html"},{"path":"/var/lib/nginx/tmp"},{"path":"/var/log"},{"path":"/var/log/nginx"},{"path":"/var/www"},{"path":"/var/www/localhost"},{"path":"/var/www/localhost/htdocs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"nginx"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:nginx:nginx:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-90439","versionConstraint":">= 1.29.2, < 1.30.0||>= 1.30.4, < 1.30.5||>= 1.31.0, < 1.31.6 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:nginx:nginx:1.30.4:*:*:*:*:*:*:*"],"package":{"name":"nginx","version":"1.30.4-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-90439","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"f5sirt@f5.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"f5sirt@f5.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90439","cwe":"CWE-122","type":"Secondary","source":"f5sirt@f5.com"}],"epss":[{"cve":"CVE-2026-90439","date":"2026-10-08","epss":0.00256,"percentile":0.15865}],"risk":0.14976,"urls":["https://my.f5.com/manage/s/article/K000162604"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90439","description":"NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions <= OpenSSL 3.5.0 under certain configurations, a limited heap buffer overflow could happen while processing a TLS handshake. This can happen in a non-deterministic manner that is beyond the attacker's control. This may cause a heap buffer overflow in the NGINX worker process leading to a restart and/or limited data corruption.\n\nImpact:\nThis vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or limited data corruption. There is no control plane exposure; this is a data plane issue only.\n\n\n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."},"relatedVulnerabilities":[]},{"artifact":{"id":"8c29de47f797c6e9","cpes":["cpe:2.3:a:guzzlehttp\\/guzzle:guzzlehttp\\/guzzle:7.13.3:*:*:*:*:*:*:*"],"name":"guzzlehttp/guzzle","purl":"pkg:composer/guzzlehttp/guzzle@7.13.3","type":"php-composer","version":"7.13.3","language":"php","licenses":["MIT"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.15.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-f7vp-7xgx-4w4r","versionConstraint":"<7.15.2 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"guzzlehttp/guzzle","version":"7.13.3"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-f7vp-7xgx-4w4r","fix":{"state":"fixed","versions":["7.15.2"],"available":[{"date":"2026-08-04","kind":"first-observed","version":"7.15.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69245","cwe":"CWE-180","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69245","cwe":"CWE-346","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69245","cwe":"CWE-384","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69245","date":"2026-10-08","epss":0.00199,"percentile":0.08956}],"risk":0.11442499999999999,"urls":["https://github.com/guzzle/guzzle/security/advisories/GHSA-f7vp-7xgx-4w4r","https://github.com/guzzle/guzzle/pull/3907","https://github.com/guzzle/guzzle/pull/3908","https://github.com/guzzle/guzzle/commit/3aeea0406aab88cbbd86531313d7cebf8ae149a4","https://github.com/guzzle/guzzle/commit/744101956d78b7c1384d0cbf379db13e859167bf","https://github.com/guzzle/guzzle/releases/tag/7.15.2","https://github.com/guzzle/guzzle/releases/tag/8.0.1"],"severity":"Medium","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-f7vp-7xgx-4w4r","description":"Guzzle: Noncanonical cookie domain keeps subdomain scope"},"relatedVulnerabilities":[{"id":"CVE-2026-69245","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69245","cwe":"CWE-180","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69245","cwe":"CWE-346","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69245","cwe":"CWE-384","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69245","date":"2026-10-08","epss":0.00199,"percentile":0.08956}],"urls":["https://github.com/guzzle/guzzle/commit/3aeea0406aab88cbbd86531313d7cebf8ae149a4","https://github.com/guzzle/guzzle/commit/744101956d78b7c1384d0cbf379db13e859167bf","https://github.com/guzzle/guzzle/pull/3907","https://github.com/guzzle/guzzle/pull/3908","https://github.com/guzzle/guzzle/releases/tag/7.15.2","https://github.com/guzzle/guzzle/releases/tag/8.0.1","https://github.com/guzzle/guzzle/security/advisories/GHSA-f7vp-7xgx-4w4r"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-69245","description":"Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric host, and the decision comes from the domain's own text, so two spellings a transport reads as an address keep subdomain scope. Hexadecimal and mixed-base forms such as 0x7f000001 and 0177.0.0.0x1 go unrecognized while libcurl 8.21.0 reads both as 127.0.0.1. A percent-escaped Domain keeps that scope on both branches because percent-decoding sits above numeric parsing, so 192.168.0.%31 and 127.0.0.1%2e are registered names in the URI grammar rather than address literals, and no numeric rule in any base classifies them, while libcurl decodes the host before resolving and reads them as 192.168.0.1 and 127.0.0.1. A cookie stored for Domain=0x7f000001 is placed in the Cookie header of a request to evil.0x7f000001, disclosing a session identifier or token to a host that is not that address, and a response from evil.0x7f000001 setting Domain=0x7f000001 is accepted into the jar and replayed to the address, so a server answering for the look-alike name can fix a session or set application state. Exploitation requires the application to enable cookie support, address an origin by one of these spellings, and contact a host whose name ends in that spelling. This issue is fixed in versions 7.15.2 and 8.0.1."}]},{"artifact":{"id":"fc9c37c033fa02f1","cpes":["cpe:2.3:a:league\\/flysystem:league\\/flysystem:3.35.2:*:*:*:*:*:*:*"],"name":"league/flysystem","purl":"pkg:composer/league/flysystem@3.35.2","type":"php-composer","version":"3.35.2","language":"php","licenses":["MIT"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.35.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxf4-7mrp-vvpr","versionConstraint":"<=3.35.2 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"league/flysystem","version":"3.35.2"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-cxf4-7mrp-vvpr","fix":{"state":"fixed","versions":["3.35.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.35.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.5,"impactScore":1.5,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102601","cwe":"CWE-150","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102601","date":"2026-10-08","epss":0.00337,"percentile":0.25047}],"risk":0.10952499999999998,"urls":["https://github.com/thephpleague/flysystem/security/advisories/GHSA-cxf4-7mrp-vvpr","https://github.com/thephpleague/flysystem/commit/ef4a9a557d769b5d472c403125716706a0d9cc77","https://github.com/thephpleague/flysystem/releases/tag/3.35.3","https://nvd.nist.gov/vuln/detail/CVE-2026-102601"],"severity":"Low","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxf4-7mrp-vvpr","description":"Flysystem: WhitespacePathNormalizer's control-character (CorruptedPathDetected) check is bypassed by malformed UTF-8 in the path, affecting every adapter"},"relatedVulnerabilities":[{"id":"CVE-2026-102601","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.5,"impactScore":1.5,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102601","cwe":"CWE-150","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102601","date":"2026-10-08","epss":0.00337,"percentile":0.25047}],"urls":["https://github.com/thephpleague/flysystem/commit/ef4a9a557d769b5d472c403125716706a0d9cc77","https://github.com/thephpleague/flysystem/releases/tag/3.35.3","https://github.com/thephpleague/flysystem/security/advisories/GHSA-cxf4-7mrp-vvpr"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102601","description":"Flysystem is an open source file storage library for PHP. Prior to 3.35.3, the default WhitespacePathNormalizer in src/WhitespacePathNormalizer.php used by Filesystem across adapters calls preg_match with the u modifier and treats both false and 0 as falsy. A path containing malformed UTF-8 causes PCRE to return false, so paths that also contain control characters bypass CorruptedPathDetected::forPath() in normalizePath(). Filesystem::write() can store such names and Filesystem::listContents() can return the raw ANSI escape sequences, allowing hidden or spoofed terminal file listings when an administrator displays them. This issue is fixed in version 3.35.3."}]},{"artifact":{"id":"6921667c3af65467","cpes":["cpe:2.3:a:coreutils:coreutils:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:apk/alpine/coreutils@9.11-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/base64"},{"path":"/bin/cat"},{"path":"/bin/chgrp"},{"path":"/bin/chmod"},{"path":"/bin/chown"},{"path":"/bin/coreutils"},{"path":"/bin/cp"},{"path":"/bin/date"},{"path":"/bin/dd"},{"path":"/bin/df"},{"path":"/bin/echo"},{"path":"/bin/false"},{"path":"/bin/link"},{"path":"/bin/ln"},{"path":"/bin/ls"},{"path":"/bin/mkdir"},{"path":"/bin/mknod"},{"path":"/bin/mktemp"},{"path":"/bin/mv"},{"path":"/bin/nice"},{"path":"/bin/printenv"},{"path":"/bin/pwd"},{"path":"/bin/rm"},{"path":"/bin/rmdir"},{"path":"/bin/sleep"},{"path":"/bin/stat"},{"path":"/bin/stty"},{"path":"/bin/sync"},{"path":"/bin/touch"},{"path":"/bin/true"},{"path":"/bin/uname"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/["},{"path":"/usr/bin/b2sum"},{"path":"/usr/bin/base32"},{"path":"/usr/bin/basename"},{"path":"/usr/bin/basenc"},{"path":"/usr/bin/cksum"},{"path":"/usr/bin/comm"},{"path":"/usr/bin/csplit"},{"path":"/usr/bin/cut"},{"path":"/usr/bin/dir"},{"path":"/usr/bin/dircolors"},{"path":"/usr/bin/dirname"},{"path":"/usr/bin/du"},{"path":"/usr/bin/expand"},{"path":"/usr/bin/expr"},{"path":"/usr/bin/factor"},{"path":"/usr/bin/fold"},{"path":"/usr/bin/head"},{"path":"/usr/bin/hostid"},{"path":"/usr/bin/id"},{"path":"/usr/bin/install"},{"path":"/usr/bin/join"},{"path":"/usr/bin/logname"},{"path":"/usr/bin/md5sum"},{"path":"/usr/bin/mkfifo"},{"path":"/usr/bin/nl"},{"path":"/usr/bin/nohup"},{"path":"/usr/bin/nproc"},{"path":"/usr/bin/numfmt"},{"path":"/usr/bin/od"},{"path":"/usr/bin/paste"},{"path":"/usr/bin/pathchk"},{"path":"/usr/bin/pinky"},{"path":"/usr/bin/pr"},{"path":"/usr/bin/printf"},{"path":"/usr/bin/ptx"},{"path":"/usr/bin/readlink"},{"path":"/usr/bin/realpath"},{"path":"/usr/bin/seq"},{"path":"/usr/bin/sha1sum"},{"path":"/usr/bin/sha224sum"},{"path":"/usr/bin/sha256sum"},{"path":"/usr/bin/sha384sum"},{"path":"/usr/bin/shred"},{"path":"/usr/bin/shuf"},{"path":"/usr/bin/sort"},{"path":"/usr/bin/split"},{"path":"/usr/bin/stdbuf"},{"path":"/usr/bin/sum"},{"path":"/usr/bin/tac"},{"path":"/usr/bin/tail"},{"path":"/usr/bin/tee"},{"path":"/usr/bin/test"},{"path":"/usr/bin/timeout"},{"path":"/usr/bin/tr"},{"path":"/usr/bin/truncate"},{"path":"/usr/bin/tsort"},{"path":"/usr/bin/tty"},{"path":"/usr/bin/unexpand"},{"path":"/usr/bin/uniq"},{"path":"/usr/bin/unlink"},{"path":"/usr/bin/users"},{"path":"/usr/bin/vdir"},{"path":"/usr/bin/wc"},{"path":"/usr/bin/who"},{"path":"/usr/bin/whoami"},{"path":"/usr/bin/yes"},{"path":"/usr/libexec"},{"path":"/usr/libexec/coreutils"},{"path":"/usr/libexec/coreutils/libstdbuf.so"},{"path":"/usr/sbin"},{"path":"/usr/sbin/chroot"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56391","versionConstraint":">= 9.5, <= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.0884925,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[]},{"artifact":{"id":"16361c4de507bb4c","cpes":["cpe:2.3:a:coreutils-env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_env:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-env","purl":"pkg:apk/alpine/coreutils-env@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/env"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56391","versionConstraint":">= 9.5, <= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.0884925,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c43a637992609b6","cpes":["cpe:2.3:a:coreutils-fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-fmt","purl":"pkg:apk/alpine/coreutils-fmt@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/fmt"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56391","versionConstraint":">= 9.5, <= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.0884925,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[]},{"artifact":{"id":"157238390cea3b89","cpes":["cpe:2.3:a:coreutils-sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-sha512sum","purl":"pkg:apk/alpine/coreutils-sha512sum@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/sha512sum"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56391","versionConstraint":">= 9.5, <= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.0884925,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[]},{"artifact":{"id":"6921667c3af65467","cpes":["cpe:2.3:a:coreutils:coreutils:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:apk/alpine/coreutils@9.11-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/base64"},{"path":"/bin/cat"},{"path":"/bin/chgrp"},{"path":"/bin/chmod"},{"path":"/bin/chown"},{"path":"/bin/coreutils"},{"path":"/bin/cp"},{"path":"/bin/date"},{"path":"/bin/dd"},{"path":"/bin/df"},{"path":"/bin/echo"},{"path":"/bin/false"},{"path":"/bin/link"},{"path":"/bin/ln"},{"path":"/bin/ls"},{"path":"/bin/mkdir"},{"path":"/bin/mknod"},{"path":"/bin/mktemp"},{"path":"/bin/mv"},{"path":"/bin/nice"},{"path":"/bin/printenv"},{"path":"/bin/pwd"},{"path":"/bin/rm"},{"path":"/bin/rmdir"},{"path":"/bin/sleep"},{"path":"/bin/stat"},{"path":"/bin/stty"},{"path":"/bin/sync"},{"path":"/bin/touch"},{"path":"/bin/true"},{"path":"/bin/uname"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/["},{"path":"/usr/bin/b2sum"},{"path":"/usr/bin/base32"},{"path":"/usr/bin/basename"},{"path":"/usr/bin/basenc"},{"path":"/usr/bin/cksum"},{"path":"/usr/bin/comm"},{"path":"/usr/bin/csplit"},{"path":"/usr/bin/cut"},{"path":"/usr/bin/dir"},{"path":"/usr/bin/dircolors"},{"path":"/usr/bin/dirname"},{"path":"/usr/bin/du"},{"path":"/usr/bin/expand"},{"path":"/usr/bin/expr"},{"path":"/usr/bin/factor"},{"path":"/usr/bin/fold"},{"path":"/usr/bin/head"},{"path":"/usr/bin/hostid"},{"path":"/usr/bin/id"},{"path":"/usr/bin/install"},{"path":"/usr/bin/join"},{"path":"/usr/bin/logname"},{"path":"/usr/bin/md5sum"},{"path":"/usr/bin/mkfifo"},{"path":"/usr/bin/nl"},{"path":"/usr/bin/nohup"},{"path":"/usr/bin/nproc"},{"path":"/usr/bin/numfmt"},{"path":"/usr/bin/od"},{"path":"/usr/bin/paste"},{"path":"/usr/bin/pathchk"},{"path":"/usr/bin/pinky"},{"path":"/usr/bin/pr"},{"path":"/usr/bin/printf"},{"path":"/usr/bin/ptx"},{"path":"/usr/bin/readlink"},{"path":"/usr/bin/realpath"},{"path":"/usr/bin/seq"},{"path":"/usr/bin/sha1sum"},{"path":"/usr/bin/sha224sum"},{"path":"/usr/bin/sha256sum"},{"path":"/usr/bin/sha384sum"},{"path":"/usr/bin/shred"},{"path":"/usr/bin/shuf"},{"path":"/usr/bin/sort"},{"path":"/usr/bin/split"},{"path":"/usr/bin/stdbuf"},{"path":"/usr/bin/sum"},{"path":"/usr/bin/tac"},{"path":"/usr/bin/tail"},{"path":"/usr/bin/tee"},{"path":"/usr/bin/test"},{"path":"/usr/bin/timeout"},{"path":"/usr/bin/tr"},{"path":"/usr/bin/truncate"},{"path":"/usr/bin/tsort"},{"path":"/usr/bin/tty"},{"path":"/usr/bin/unexpand"},{"path":"/usr/bin/uniq"},{"path":"/usr/bin/unlink"},{"path":"/usr/bin/users"},{"path":"/usr/bin/vdir"},{"path":"/usr/bin/wc"},{"path":"/usr/bin/who"},{"path":"/usr/bin/whoami"},{"path":"/usr/bin/yes"},{"path":"/usr/libexec"},{"path":"/usr/libexec/coreutils"},{"path":"/usr/libexec/coreutils/libstdbuf.so"},{"path":"/usr/sbin"},{"path":"/usr/sbin/chroot"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56392","versionConstraint":"= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56392","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56392","cwe":"CWE-122","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56392","date":"2026-10-08","epss":0.00186,"percentile":0.07525}],"risk":0.083235,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56392","description":"GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"},"relatedVulnerabilities":[]},{"artifact":{"id":"16361c4de507bb4c","cpes":["cpe:2.3:a:coreutils-env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_env:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-env","purl":"pkg:apk/alpine/coreutils-env@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/env"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56392","versionConstraint":"= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56392","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56392","cwe":"CWE-122","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56392","date":"2026-10-08","epss":0.00186,"percentile":0.07525}],"risk":0.083235,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56392","description":"GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"},"relatedVulnerabilities":[]},{"artifact":{"id":"0c43a637992609b6","cpes":["cpe:2.3:a:coreutils-fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-fmt","purl":"pkg:apk/alpine/coreutils-fmt@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/fmt"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56392","versionConstraint":"= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56392","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56392","cwe":"CWE-122","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56392","date":"2026-10-08","epss":0.00186,"percentile":0.07525}],"risk":0.083235,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56392","description":"GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"},"relatedVulnerabilities":[]},{"artifact":{"id":"157238390cea3b89","cpes":["cpe:2.3:a:coreutils-sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-sha512sum","purl":"pkg:apk/alpine/coreutils-sha512sum@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/sha512sum"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56392","versionConstraint":"= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56392","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56392","cwe":"CWE-122","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56392","date":"2026-10-08","epss":0.00186,"percentile":0.07525}],"risk":0.083235,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56392","description":"GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"},"relatedVulnerabilities":[]},{"artifact":{"id":"22cc25b71164504a","cpes":["cpe:2.3:a:laravel\\/framework:laravel\\/framework:v13.19.0:*:*:*:*:*:*:*"],"name":"laravel/framework","purl":"pkg:composer/laravel/framework@v13.19.0","type":"php-composer","version":"v13.19.0","language":"php","licenses":["MIT"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"13.30.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jh5r-qr3c-85q8","versionConstraint":">=13.0.0,<13.30.0 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"laravel/framework","version":"v13.19.0"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-jh5r-qr3c-85q8","fix":{"state":"fixed","versions":["13.30.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"13.30.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102279","cwe":"CWE-80","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102279","date":"2026-10-08","epss":0.00202,"percentile":0.09236}],"risk":0.061610000000000005,"urls":["https://github.com/laravel/framework/security/advisories/GHSA-jh5r-qr3c-85q8","https://nvd.nist.gov/vuln/detail/CVE-2026-102279","https://github.com/laravel/framework/pull/61381","https://github.com/laravel/framework/commit/b495ca2ec4e15a977e8700328bf13e8a79f29d12","https://github.com/laravel/framework/releases/tag/v12.69.0","https://github.com/laravel/framework/releases/tag/v13.30.0"],"severity":"Low","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jh5r-qr3c-85q8","description":"Laravel: XSS in Debug Page Information"},"relatedVulnerabilities":[{"id":"CVE-2026-102279","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102279","cwe":"CWE-80","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102279","date":"2026-10-08","epss":0.00202,"percentile":0.09236}],"urls":["https://github.com/laravel/framework/commit/b495ca2ec4e15a977e8700328bf13e8a79f29d12","https://github.com/laravel/framework/pull/61381","https://github.com/laravel/framework/releases/tag/v12.69.0","https://github.com/laravel/framework/releases/tag/v13.30.0","https://github.com/laravel/framework/security/advisories/GHSA-jh5r-qr3c-85q8"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102279","description":"Laravel is a web application framework. Prior to 12.69.0 and 13.30.0, Laravel exception debug pages with APP_DEBUG=true pass attacker-controlled input to a Tippy.js tooltip configured with allowHTML true, enabling DOM-based cross-site scripting when a user hovers over the tooltip. This issue is fixed in versions 12.69.0 and 13.30.0."}]},{"artifact":{"id":"e964e2f6e76929df","cpes":["cpe:2.3:a:league\\/commonmark:league\\/commonmark:2.8.2:*:*:*:*:*:*:*"],"name":"league/commonmark","purl":"pkg:composer/league/commonmark@2.8.2","type":"php-composer","version":"2.8.2","language":"php","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.10.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-3q6v-r5mr-hxv8","versionConstraint":">=2.0.0,<=2.10.1 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"league/commonmark","version":"2.8.2"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-3q6v-r5mr-hxv8","fix":{"state":"fixed","versions":["2.10.2"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.10.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/thephpleague/commonmark/security/advisories/GHSA-3q6v-r5mr-hxv8","https://github.com/thephpleague/commonmark/commit/5f63680a5e29dd57f9c6be9743b0e90493d3c2d0","https://github.com/thephpleague/commonmark/releases/tag/2.10.2"],"severity":"High","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-3q6v-r5mr-hxv8","description":"league/commonmark: Quadratic-time denial of service in the GitHub Flavored Markdown Table extension block-start scan"},"relatedVulnerabilities":[]},{"artifact":{"id":"e964e2f6e76929df","cpes":["cpe:2.3:a:league\\/commonmark:league\\/commonmark:2.8.2:*:*:*:*:*:*:*"],"name":"league/commonmark","purl":"pkg:composer/league/commonmark@2.8.2","type":"php-composer","version":"2.8.2","language":"php","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.10.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8rr7-cvq3-gmfh","versionConstraint":">=1.5.0,<2.10.0 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"league/commonmark","version":"2.8.2"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-8rr7-cvq3-gmfh","fix":{"state":"fixed","versions":["2.10.0"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"2.10.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/thephpleague/commonmark/security/advisories/GHSA-8rr7-cvq3-gmfh","https://github.com/thephpleague/commonmark/commit/f27eb720972490b5af4dbb635ad8634529faf9f2","https://github.com/thephpleague/commonmark/releases/tag/2.10.0"],"severity":"High","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8rr7-cvq3-gmfh","description":"league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension"},"relatedVulnerabilities":[]},{"artifact":{"id":"e964e2f6e76929df","cpes":["cpe:2.3:a:league\\/commonmark:league\\/commonmark:2.8.2:*:*:*:*:*:*:*"],"name":"league/commonmark","purl":"pkg:composer/league/commonmark@2.8.2","type":"php-composer","version":"2.8.2","language":"php","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.9.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-f8fg-pg57-v4j8","versionConstraint":">=2.7.0,<2.9.1 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"league/commonmark","version":"2.8.2"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-f8fg-pg57-v4j8","fix":{"state":"fixed","versions":["2.9.1"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"2.9.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/thephpleague/commonmark/security/advisories/GHSA-f8fg-pg57-v4j8","https://github.com/thephpleague/commonmark/commit/dfcdf4554c16aa37c15e3a5ee3243ee26147c239","https://github.com/thephpleague/commonmark/releases/tag/2.9.1"],"severity":"High","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-f8fg-pg57-v4j8","description":"league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed"},"relatedVulnerabilities":[]},{"artifact":{"id":"e964e2f6e76929df","cpes":["cpe:2.3:a:league\\/commonmark:league\\/commonmark:2.8.2:*:*:*:*:*:*:*"],"name":"league/commonmark","purl":"pkg:composer/league/commonmark@2.8.2","type":"php-composer","version":"2.8.2","language":"php","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.9.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-g2gp-3wwq-f4ph","versionConstraint":">=1.5.0,<2.9.0 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"league/commonmark","version":"2.8.2"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-g2gp-3wwq-f4ph","fix":{"state":"fixed","versions":["2.9.0"],"available":[{"date":"2026-08-07","kind":"first-observed","version":"2.9.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/thephpleague/commonmark/security/advisories/GHSA-g2gp-3wwq-f4ph","https://github.com/thephpleague/commonmark/commit/2d4c0fafa62501be919262064cffa6d71687430b","https://github.com/thephpleague/commonmark/releases/tag/2.9.0"],"severity":"High","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-g2gp-3wwq-f4ph","description":"league/commonmark: Denial of service via adjacent inline attribute blocks"},"relatedVulnerabilities":[]},{"artifact":{"id":"e964e2f6e76929df","cpes":["cpe:2.3:a:league\\/commonmark:league\\/commonmark:2.8.2:*:*:*:*:*:*:*"],"name":"league/commonmark","purl":"pkg:composer/league/commonmark@2.8.2","type":"php-composer","version":"2.8.2","language":"php","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.9.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j8pm-gj4c-rq4x","versionConstraint":">=0.6.0,<2.9.1 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"league/commonmark","version":"2.8.2"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-j8pm-gj4c-rq4x","fix":{"state":"fixed","versions":["2.9.1"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"2.9.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/thephpleague/commonmark/security/advisories/GHSA-j8pm-gj4c-rq4x","https://github.com/thephpleague/commonmark/commit/0768217751fbfaeb8d76762f6944e9af7114295e","https://github.com/thephpleague/commonmark/commit/d9375fadc308a63a02950a68d822417a6e4c33b2","https://github.com/thephpleague/commonmark/commit/e0036ef031fd36ec1c3c82db8743fc928b5271c8","https://github.com/thephpleague/commonmark/releases/tag/2.9.1"],"severity":"High","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j8pm-gj4c-rq4x","description":"league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters"},"relatedVulnerabilities":[]},{"artifact":{"id":"e964e2f6e76929df","cpes":["cpe:2.3:a:league\\/commonmark:league\\/commonmark:2.8.2:*:*:*:*:*:*:*"],"name":"league/commonmark","purl":"pkg:composer/league/commonmark@2.8.2","type":"php-composer","version":"2.8.2","language":"php","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.9.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jfm3-95jq-q3rf","versionConstraint":">=1.5.0,<2.9.0 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"league/commonmark","version":"2.8.2"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-jfm3-95jq-q3rf","fix":{"state":"fixed","versions":["2.9.0"],"available":[{"date":"2026-08-07","kind":"first-observed","version":"2.9.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/thephpleague/commonmark/security/advisories/GHSA-jfm3-95jq-q3rf","https://github.com/thephpleague/commonmark/commit/66028124a17ba193da7b11cc3dfda92df21bfbf4","https://github.com/thephpleague/commonmark/releases/tag/2.9.0"],"severity":"High","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jfm3-95jq-q3rf","description":"league/commonmark:  Denial of service via duplicate footnote definitions"},"relatedVulnerabilities":[]},{"artifact":{"id":"e964e2f6e76929df","cpes":["cpe:2.3:a:league\\/commonmark:league\\/commonmark:2.8.2:*:*:*:*:*:*:*"],"name":"league/commonmark","purl":"pkg:composer/league/commonmark@2.8.2","type":"php-composer","version":"2.8.2","language":"php","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.9.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jjv6-8j6v-6j52","versionConstraint":">=1.5.0,<2.9.1 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"league/commonmark","version":"2.8.2"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-jjv6-8j6v-6j52","fix":{"state":"fixed","versions":["2.9.1"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"2.9.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/thephpleague/commonmark/security/advisories/GHSA-jjv6-8j6v-6j52","https://github.com/thephpleague/commonmark/commit/04a5d11ef6bf2d0b927310810d6a2a85d3c184b9","https://github.com/thephpleague/commonmark/commit/2f611b599c51661b005dc45c16ceaa547546e687","https://github.com/thephpleague/commonmark/releases/tag/2.9.1"],"severity":"High","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jjv6-8j6v-6j52","description":"league/commonmark: Denial of service in the SmartPunct and Attributes extensions"},"relatedVulnerabilities":[]},{"artifact":{"id":"e964e2f6e76929df","cpes":["cpe:2.3:a:league\\/commonmark:league\\/commonmark:2.8.2:*:*:*:*:*:*:*"],"name":"league/commonmark","purl":"pkg:composer/league/commonmark@2.8.2","type":"php-composer","version":"2.8.2","language":"php","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.9.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mh25-x5hq-wrqp","versionConstraint":">=2.0.0,<2.9.0 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"league/commonmark","version":"2.8.2"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-mh25-x5hq-wrqp","fix":{"state":"fixed","versions":["2.9.0"],"available":[{"date":"2026-08-07","kind":"first-observed","version":"2.9.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/thephpleague/commonmark/security/advisories/GHSA-mh25-x5hq-wrqp","https://github.com/thephpleague/commonmark/releases/tag/2.9.0"],"severity":"High","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mh25-x5hq-wrqp","description":"league/commonmark: Denial of service via colliding heading slugs"},"relatedVulnerabilities":[]},{"artifact":{"id":"a7e1137fdae96eff","cpes":["cpe:2.3:a:enshrined\\/svg-sanitize:enshrined\\/svg-sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg-sanitize:enshrined\\/svg_sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg_sanitize:enshrined\\/svg-sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg_sanitize:enshrined\\/svg_sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg:enshrined\\/svg-sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg:enshrined\\/svg_sanitize:0.22.0:*:*:*:*:*:*:*"],"name":"enshrined/svg-sanitize","purl":"pkg:composer/enshrined/svg-sanitize@0.22.0","type":"php-composer","version":"0.22.0","language":"php","licenses":["GPL-2.0-or-later"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.0.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9rjx-3jch-6vjf","versionConstraint":"<=0.22.0 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"enshrined/svg-sanitize","version":"0.22.0"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-9rjx-3jch-6vjf","fix":{"state":"fixed","versions":["1.0.0"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"1.0.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107380","cwe":"CWE-79","type":"Primary","source":"security-advisories@github.com"}],"risk":0,"urls":["https://github.com/darylldoyle/svg-sanitizer/security/advisories/GHSA-9rjx-3jch-6vjf","https://nvd.nist.gov/vuln/detail/CVE-2026-107380","https://github.com/darylldoyle/svg-sanitizer/commit/23877db7e76f1e1df5c3e65ab30239219c3d2867","https://github.com/darylldoyle/svg-sanitizer/releases/tag/1.0.0"],"severity":"Medium","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9rjx-3jch-6vjf","description":"enshrined/svg-sanitize: Stored XSS via DTD Entity / HTML5 Named Character Reference Collision"},"relatedVulnerabilities":[{"id":"CVE-2026-107380","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107380","cwe":"CWE-79","type":"Primary","source":"security-advisories@github.com"}],"urls":["https://github.com/darylldoyle/svg-sanitizer/commit/23877db7e76f1e1df5c3e65ab30239219c3d2867","https://github.com/darylldoyle/svg-sanitizer/releases/tag/1.0.0","https://github.com/darylldoyle/svg-sanitizer/security/advisories/GHSA-9rjx-3jch-6vjf"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-107380","description":"savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg-sanitizer's isHrefSafeValue() validates an SVG href after XML DTD entity expansion, but saveXML() serializes the original entity reference after removing the DTD declaration. A crafted entity such as Tab can appear to the sanitizer as a safe fragment prefix while HTML5 Named Character Reference resolution during inline HTML rendering later converts the surviving reference to whitespace, exposing a javascript: URL. When an application embeds the sanitized SVG inline, a user who activates the link can cause script to execute in the embedding page's origin. This issue is fixed in version 1.0.0."}]},{"artifact":{"id":"a7e1137fdae96eff","cpes":["cpe:2.3:a:enshrined\\/svg-sanitize:enshrined\\/svg-sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg-sanitize:enshrined\\/svg_sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg_sanitize:enshrined\\/svg-sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg_sanitize:enshrined\\/svg_sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg:enshrined\\/svg-sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg:enshrined\\/svg_sanitize:0.22.0:*:*:*:*:*:*:*"],"name":"enshrined/svg-sanitize","purl":"pkg:composer/enshrined/svg-sanitize@0.22.0","type":"php-composer","version":"0.22.0","language":"php","licenses":["GPL-2.0-or-later"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.0.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-m9xh-6747-9r6f","versionConstraint":"<=0.22.0 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"enshrined/svg-sanitize","version":"0.22.0"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-m9xh-6747-9r6f","fix":{"state":"fixed","versions":["1.0.0"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"1.0.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/darylldoyle/svg-sanitizer/security/advisories/GHSA-m9xh-6747-9r6f","https://github.com/darylldoyle/svg-sanitizer/commit/2dff6628314de8519155b7feb218bbe132785757","https://github.com/darylldoyle/svg-sanitizer/releases/tag/1.0.0"],"severity":"Medium","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-m9xh-6747-9r6f","description":"svg-sanitizer: Mixed-case xlink:HrEf skips the `<use>` nesting-DoS check in Resolver::processReferences"},"relatedVulnerabilities":[{"id":"CVE-2026-107381","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"a7e1137fdae96eff","cpes":["cpe:2.3:a:enshrined\\/svg-sanitize:enshrined\\/svg-sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg-sanitize:enshrined\\/svg_sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg_sanitize:enshrined\\/svg-sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg_sanitize:enshrined\\/svg_sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg:enshrined\\/svg-sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg:enshrined\\/svg_sanitize:0.22.0:*:*:*:*:*:*:*"],"name":"enshrined/svg-sanitize","purl":"pkg:composer/enshrined/svg-sanitize@0.22.0","type":"php-composer","version":"0.22.0","language":"php","licenses":["GPL-2.0-or-later"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.0.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-v383-3rw5-q8rf","versionConstraint":"<=0.22.0 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"enshrined/svg-sanitize","version":"0.22.0"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-v383-3rw5-q8rf","fix":{"state":"fixed","versions":["1.0.0"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"1.0.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107379","cwe":"CWE-770","type":"Primary","source":"security-advisories@github.com"}],"risk":0,"urls":["https://github.com/darylldoyle/svg-sanitizer/security/advisories/GHSA-v383-3rw5-q8rf","https://nvd.nist.gov/vuln/detail/CVE-2026-107379","https://github.com/darylldoyle/svg-sanitizer/commit/23877db7e76f1e1df5c3e65ab30239219c3d2867","https://github.com/darylldoyle/svg-sanitizer/releases/tag/1.0.0"],"severity":"Medium","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-v383-3rw5-q8rf","description":"enshrined/svg-sanitize: Denial of Service via DTD Attribute Declaration Crash"},"relatedVulnerabilities":[{"id":"CVE-2026-107379","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107379","cwe":"CWE-770","type":"Primary","source":"security-advisories@github.com"}],"urls":["https://github.com/darylldoyle/svg-sanitizer/commit/23877db7e76f1e1df5c3e65ab30239219c3d2867","https://github.com/darylldoyle/svg-sanitizer/releases/tag/1.0.0","https://github.com/darylldoyle/svg-sanitizer/security/advisories/GHSA-v383-3rw5-q8rf"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-107379","description":"savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg-sanitizer allows a crafted SVG DTD with a #FIXED attribute default to make cleanAttributesOnWhitelist() perform a double DOMElement::removeAttribute() call on the same attribute name in src/Sanitizer.php. The first removal deletes the explicit attribute, while the DTD default rematerializes the value before the href safety path performs the second removal, which can corrupt libxml state and terminate the PHP worker. An attacker who can submit SVG content to a sanitization endpoint can repeatedly interrupt workers and degrade or exhaust application availability. This issue is fixed in version 1.0.0."}]},{"artifact":{"id":"e964e2f6e76929df","cpes":["cpe:2.3:a:league\\/commonmark:league\\/commonmark:2.8.2:*:*:*:*:*:*:*"],"name":"league/commonmark","purl":"pkg:composer/league/commonmark@2.8.2","type":"php-composer","version":"2.8.2","language":"php","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.10.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-97jj-33gv-5xf9","versionConstraint":">=1.3.0,<=2.10.1 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"league/commonmark","version":"2.8.2"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-97jj-33gv-5xf9","fix":{"state":"fixed","versions":["2.10.2"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.10.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/thephpleague/commonmark/security/advisories/GHSA-97jj-33gv-5xf9","https://github.com/thephpleague/commonmark/commit/411afcc2a7402756d96c89af8882c724d12d47ca","https://github.com/thephpleague/commonmark/releases/tag/2.10.2"],"severity":"Medium","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-97jj-33gv-5xf9","description":"league/commonmark: DisallowedRawHtml bypassed when a disallowed tag name ends the raw-HTML literal"},"relatedVulnerabilities":[]},{"artifact":{"id":"e964e2f6e76929df","cpes":["cpe:2.3:a:league\\/commonmark:league\\/commonmark:2.8.2:*:*:*:*:*:*:*"],"name":"league/commonmark","purl":"pkg:composer/league/commonmark@2.8.2","type":"php-composer","version":"2.8.2","language":"php","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:2b2984e8f63021488bc0ba4af9c52aaa6b798d5aab75778c6945b6e42ab36974","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.9.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mj63-m3rc-8ppr","versionConstraint":">=2.0.0,<2.9.0 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"league/commonmark","version":"2.8.2"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-mj63-m3rc-8ppr","fix":{"state":"fixed","versions":["2.9.0"],"available":[{"date":"2026-08-07","kind":"first-observed","version":"2.9.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/thephpleague/commonmark/security/advisories/GHSA-mj63-m3rc-8ppr","https://github.com/thephpleague/commonmark/commit/b5ac8c3947ca81844e85a09c7e0a5b4148bde2e1","https://github.com/thephpleague/commonmark/releases/tag/2.9.0"],"severity":"Medium","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mj63-m3rc-8ppr","description":"league/commonmark: Denial of service via deeply nested XML output"},"relatedVulnerabilities":[]}],"grade":"F","score":"0.00","as_of":"2026-10-10T03:13:00.010Z","grype_db_version":"2026-10-09T06:32:32.000Z"}