{"grype_matches":[{"artifact":{"id":"3adca89c3c5f952b","cpes":["cpe:2.3:a:golang:crypto:v0.55.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.55.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.55.0","type":"go-module","version":"v0.55.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:+KWHjbgOaAQ66dh/YlkZKHlz9ZUlq61AFirAR9ntP8M=","mainModule":"github.com/cloudflare/cloudflared","architecture":"amd64","goCompiledVersion":"go1.26.8"},"locations":[{"path":"/usr/local/bin/cloudflared","layerID":"sha256:57327e6467daae34e7bdcffe17eca8ce4d1f72f94bf0c216bc5c19132ba23b09","accessPath":"/usr/local/bin/cloudflared","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.56.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6355","versionConstraint":"<0.56.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.55.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6355","fix":{"state":"fixed","versions":["0.56.0"],"available":[{"date":"2026-09-02","kind":"release","version":"0.56.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56855","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56855","date":"2026-10-08","epss":0.005,"percentile":0.4091}],"risk":0.375,"urls":["https://go.dev/cl/826524","https://groups.google.com/g/golang-announce/c/1y3fb2np35U"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/81317","description":"Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection.\n\nNow, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking."},"relatedVulnerabilities":[{"id":"CVE-2026-56855","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56855","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56855","date":"2026-10-08","epss":0.005,"percentile":0.4091}],"urls":["https://go.dev/cl/826524","https://go.dev/issue/81317","https://groups.google.com/g/golang-announce/c/1y3fb2np35U","https://pkg.go.dev/vuln/GO-2026-6355"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56855","description":"Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking."}]},{"artifact":{"id":"36b0b2f615d7105d","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54873","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54873","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"risk":0.34650000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary.  Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer.  To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received.  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-54873","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"urls":["https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23","https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53","https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb","https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"3adca89c3c5f952b","cpes":["cpe:2.3:a:golang:crypto:v0.55.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.55.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.55.0","type":"go-module","version":"v0.55.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:+KWHjbgOaAQ66dh/YlkZKHlz9ZUlq61AFirAR9ntP8M=","mainModule":"github.com/cloudflare/cloudflared","architecture":"amd64","goCompiledVersion":"go1.26.8"},"locations":[{"path":"/usr/local/bin/cloudflared","layerID":"sha256:57327e6467daae34e7bdcffe17eca8ce4d1f72f94bf0c216bc5c19132ba23b09","accessPath":"/usr/local/bin/cloudflared","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.56.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6354","versionConstraint":"<0.56.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.55.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6354","fix":{"state":"fixed","versions":["0.56.0"],"available":[{"date":"2026-09-02","kind":"release","version":"0.56.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78662","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-78662","date":"2026-10-08","epss":0.00431,"percentile":0.3535}],"risk":0.32325,"urls":["https://go.dev/cl/826504","https://groups.google.com/g/golang-announce/c/1y3fb2np35U"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/81316","description":"Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection.\n\nNow, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection."},"relatedVulnerabilities":[{"id":"CVE-2026-78662","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78662","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-78662","date":"2026-10-08","epss":0.00431,"percentile":0.3535}],"urls":["https://go.dev/cl/826504","https://go.dev/issue/81316","https://groups.google.com/g/golang-announce/c/1y3fb2np35U","https://pkg.go.dev/vuln/GO-2026-6354"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78662","description":"Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection."}]},{"artifact":{"id":"36b0b2f615d7105d","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84782","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.30615,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly.  Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region.  CWE: CWE-125: Out-of-bounds Read  Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue.  The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer.  Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build.  The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-84782","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"36b0b2f615d7105d","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84784","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-84784","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-08","epss":0.00403,"percentile":0.32493}],"risk":0.30225,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use.  Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay).  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired.  The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame.  Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth.  [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-84784","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-08","epss":0.00403,"percentile":0.32493}],"urls":["https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a","https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806","https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f","https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC\nstack with NEW_CONNECTION_ID frames by avoiding a limit check on\nhow many connection IDs the remote QUIC stack can use.\n\nImpact summary: The local QUIC stack sends a RETIRE_CONN_ID frame\nfor every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID\nframe is dispatched via the Control Frame Queue (CFQ). If the remote\npeer also withholds ACKs, then it can force the local stack\nto allocate ~400MB (depending on ACK delay).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism\nby which a remote peer can notify the local QUIC stack to change the\ndestination connection ID (a.k.a. CID) the local stack uses to\nidentify the connection at the remote peer. Each CID is associated\nwith a sequence number. The sequence number is transmitted\nin NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID\nwhich is being either associated with a connection or retired.\n\nThe remote peer sends a NEW_CONNECTION_ID frame to let the local stack know\na new CID is being associated with an existing connection. The\nNEW_CONNECTION_ID frame carries the new CID, its sequence number, and the\nretire-prior-to number. The retire-prior-to identifies existing\nCIDs that are to be retired. The local QUIC stack must send a\nRETIRE_CONNECTION_ID for every destination CID whose sequence number\nis less than retire-prior-to. The CID becomes retired after the\nlocal stack receives an ACK for its RETIRE_CONNECTION_ID frame.\n\nAlthough the OpenSSL QUIC stack supports at most one destination CID\nfor every connection, it can be tricked into processing more than\none RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC\nstack currently retires the destination CID as soon as it receives\nthe NEW_CONNECTION_ID, while in fact the destination CID must\nbe retired after an ACK for the RETIRE_CONNECTION_ID frame is received.\nCorrecting the flawed logic also fixes the backlog growth.\n\n[1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"27e0524b85198251","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"risk":0.29156,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"27e0524b85198251","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"risk":0.28785000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."},"relatedVulnerabilities":[{"id":"CVE-2018-20796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."}]},{"artifact":{"id":"9624b8abfaf8a472","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.3.dfsg\\+really1.3.1-1\\+b1:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/debian/zlib1g@1%3A1.3.dfsg%2Breally1.3.1-1%2Bb1?arch=amd64&distro=debian-13.7&upstream=zlib%401%3A1.3.dfsg%2Breally1.3.1-1","type":"deb","version":"1:1.3.dfsg+really1.3.1-1+b1","language":"","licenses":["Zlib"],"locations":[{"path":"/var/lib/dpkg/status.d/zlib1g","layerID":"sha256:e4ba966d7f0527dfe0fcb559e4e18d4da42c4e6beae924719255e0dedb554ed0","accessPath":"/var/lib/dpkg/status.d/zlib1g","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:e4ba966d7f0527dfe0fcb559e4e18d4da42c4e6beae924719255e0dedb554ed0","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/zlib1g.md5sums","layerID":"sha256:e4ba966d7f0527dfe0fcb559e4e18d4da42c4e6beae924719255e0dedb554ed0","accessPath":"/var/lib/dpkg/status.d/zlib1g.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib","version":"1:1.3.dfsg+really1.3.1-1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"zlib","version":"1:1.3.dfsg+really1.3.1-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-85091","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"risk":0.28124,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-85091","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."}]},{"artifact":{"id":"27e0524b85198251","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"27e0524b85198251","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19499","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"risk":0.22572,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.  Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.  At the time of publication, no network-facing application impact is known."},"relatedVulnerabilities":[{"id":"CVE-2026-19499","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34510","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0017"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known."}]},{"artifact":{"id":"27e0524b85198251","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"27e0524b85198251","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"36b0b2f615d7105d","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-72897","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-72897","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.1995,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected.  Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service.  CWE: CWE-787: Out-of-bounds Write  Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags.  An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process.  Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3.  The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity.  FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-72897","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"urls":["https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922","https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e","https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61","https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"36b0b2f615d7105d","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75806","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"risk":0.199305,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead.  Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact.  CWE: CWE-1284: Improper Validation of Specified Quantity in Input  Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication.  In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS.  The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75806","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"36b0b2f615d7105d","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75804","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-75804","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"risk":0.18128,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits.  Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size).  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data.  Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error.  The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met:   - the remote peer opens several streams   - each stream must stay within the stream-level flow control limit   - there must be no zero-offset byte sent on any of the streams     (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection.  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75804","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"urls":["https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e","https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538","https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a","https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"27e0524b85198251","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17612999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.  The resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"36b0b2f615d7105d","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42772","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42772","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"risk":0.16995000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data.  Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth.  CWE: CWE-407: Inefficient Algorithmic Complexity  Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`.  By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process.  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-42772","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"urls":["https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09","https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e","https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773","https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"27e0524b85198251","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010022","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010022","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-08","epss":0.03249,"percentile":0.8796}],"risk":0.16245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010022","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-08","epss":0.03249,"percentile":0.8796}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010022","https://sourceware.org/bugzilla/show_bug.cgi?id=22850","https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3","https://ubuntu.com/security/CVE-2019-1010022"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"27e0524b85198251","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010024","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010024","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-08","epss":0.03193,"percentile":0.87729}],"risk":0.15965000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010024","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-08","epss":0.03193,"percentile":0.87729}],"urls":["http://www.securityfocus.com/bid/109162","https://security-tracker.debian.org/tracker/CVE-2019-1010024","https://sourceware.org/bugzilla/show_bug.cgi?id=22852","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010024"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"27e0524b85198251","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010023","fix":{"state":"not-fixed","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-08","epss":0.03044,"percentile":0.87139}],"risk":0.1522,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010023","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-08","epss":0.03044,"percentile":0.87139}],"urls":["http://www.securityfocus.com/bid/109167","https://security-tracker.debian.org/tracker/CVE-2019-1010023","https://sourceware.org/bugzilla/show_bug.cgi?id=22851","https://support.f5.com/csp/article/K11932200?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010023"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"36b0b2f615d7105d","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-35189","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-35189","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"risk":0.13750500000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions.  Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake.  This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations.  The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-35189","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"urls":["https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84","https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89","https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f","https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"27e0524b85198251","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2010-4756","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2010-4756","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-08","epss":0.02633,"percentile":0.85093}],"risk":0.13165,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."},"relatedVulnerabilities":[{"id":"CVE-2010-4756","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"impactScore":2.9,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-08","epss":0.02633,"percentile":0.85093}],"urls":["http://cxib.net/stuff/glob-0day.c","http://securityreason.com/achievement_securityalert/89","http://securityreason.com/exploitalert/9223","https://bugzilla.redhat.com/show_bug.cgi?id=681681","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4756","https://security.netapp.com/advisory/ntap-20241108-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."}]},{"artifact":{"id":"27e0524b85198251","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6791","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"risk":0.1276,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."},"relatedVulnerabilities":[{"id":"CVE-2026-6791","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."}]},{"artifact":{"id":"27e0524b85198251","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9192","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-9192","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-08","epss":0.02447,"percentile":0.83872}],"risk":0.12235,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"},"relatedVulnerabilities":[{"id":"CVE-2019-9192","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-08","epss":0.02447,"percentile":0.83872}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=24269","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"}]},{"artifact":{"id":"27e0524b85198251","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.12190000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a  stack overflow when a malicious DNS server returns too large a response  for a DNS query, resulting in degraded DNS resolution for the system.    Exploitation of this bug needs a system that has nscd enabled and using  an untrusted DNS server for name resolution, with the compromised DNS  server being capable of processing records large enough to result in a  stack overflow in an nscd thread stack.  During experimentation, bind 9  was unable to handle large records, but that could change in future or  with a different name server.  In typical installations, nscd is  executed in an isolated context as its own user without a shell, due to  which any compromise of that service is isolated.    There is a remote possibility of nscd cache corruption if an attacker  manages to get the stack pointer into a desired point in the heap,  potentially resulting in other caches in nscd being overwritten with  corrupt data through the stack overflow, until the buggy code path  eventually results in a crash.    Finally, a crash in nscd may result in performance degradation when  resolving names, but it does not result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"27e0524b85198251","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19542","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"risk":0.11978,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.  The tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."},"relatedVulnerabilities":[{"id":"CVE-2026-19542","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34506","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0018"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."}]},{"artifact":{"id":"36b0b2f615d7105d","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-35191","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-35191","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"risk":0.11959499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received.  Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack.  CWE: CWE-440: Expected Behavior Violation   Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack.  If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed.  The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC.  FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE."},"relatedVulnerabilities":[{"id":"CVE-2026-35191","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"urls":["https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239","https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5","https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address\nvalidation, can be forced to count incoming packets multiple times in its\nunvalidated credit computation, leading to a violation of the RFC 9000\nunvalidated connection amplification limit of 3 times the amount of data\nreceived.\n\nImpact summary: A remote attacker able to spoof packets to a server using the\nOpenSSL QUIC implementation might use the server for an amplification of\na DDoS attack.\n\nCWE: CWE-440: Expected Behavior Violation \n\nDescription: OpenSSL's QUIC stack, when operating as a server, enforces client\naddress validation (RFC 9000, Section 8), to confirm the peer address is not\nused for a traffic amplification attack.  If this feature is disabled on the\nserver, the QUIC stack limits the amount of server data that can be sent to 3\ntimes the amount of data received from the peer address, until such time as the\nTLS handshake is completed.\n\nThe OpenSSL QUIC server, when operating in non-validation mode, adds the\nlength of the whole datagram received to the unvalidated credit limit when\nprocessing each QUIC packet in the datagram. A remote peer may,\nafter establishing a connection with an initial client hello frame, send a\nsubsequent datagram containing multiple QUIC packets, leading the server to\naccount the entire datagram length for each packet in the datagram, resulting\nin the server believing that the peer has sent more data than it actually has,\nthereby violating the 3x amplification limit mandated by the RFC.\n\nFIPS impact: no\nAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."}]},{"artifact":{"id":"36b0b2f615d7105d","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75805","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-75805","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"risk":0.11433000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response.   Impact summary: The NULL pointer dereference happens on a read which  leads to a crash and a Denial of Service for the affected client application.  CWE: CWE-476: NULL-pointer dereference  Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API.  A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash.  The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected.  FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75805","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"urls":["https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166","https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7","https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3","https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"27e0524b85198251","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010025","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010025","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-08","epss":0.02267,"percentile":0.825}],"risk":0.11334999999999999,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2019-1010025","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-08","epss":0.02267,"percentile":0.825}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010025","https://sourceware.org/bugzilla/show_bug.cgi?id=22853","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010025"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."}]},{"artifact":{"id":"9624b8abfaf8a472","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.3.dfsg\\+really1.3.1-1\\+b1:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/debian/zlib1g@1%3A1.3.dfsg%2Breally1.3.1-1%2Bb1?arch=amd64&distro=debian-13.7&upstream=zlib%401%3A1.3.dfsg%2Breally1.3.1-1","type":"deb","version":"1:1.3.dfsg+really1.3.1-1+b1","language":"","licenses":["Zlib"],"locations":[{"path":"/var/lib/dpkg/status.d/zlib1g","layerID":"sha256:e4ba966d7f0527dfe0fcb559e4e18d4da42c4e6beae924719255e0dedb554ed0","accessPath":"/var/lib/dpkg/status.d/zlib1g","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:e4ba966d7f0527dfe0fcb559e4e18d4da42c4e6beae924719255e0dedb554ed0","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/zlib1g.md5sums","layerID":"sha256:e4ba966d7f0527dfe0fcb559e4e18d4da42c4e6beae924719255e0dedb554ed0","accessPath":"/var/lib/dpkg/status.d/zlib1g.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib","version":"1:1.3.dfsg+really1.3.1-1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27171","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"zlib","version":"1:1.3.dfsg+really1.3.1-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-27171","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27171","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-27171","date":"2026-10-08","epss":0.00191,"percentile":0.08065}],"risk":0.10027499999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27171","description":"zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition."},"relatedVulnerabilities":[{"id":"CVE-2026-27171","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27171","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-27171","date":"2026-10-08","epss":0.00191,"percentile":0.08065}],"urls":["https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/","https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf","https://github.com/madler/zlib/issues/904","https://github.com/madler/zlib/releases/tag/v1.3.2","https://ostif.org/zlib-audit-complete/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27171","description":"zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition."}]},{"artifact":{"id":"36b0b2f615d7105d","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54875","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54875","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"risk":0.09849,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms.  Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar.  CWE: CWE-208: Observable Timing Discrepancy  Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel.  FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module.  OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V.  OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.  OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.  This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov.  -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov"},"relatedVulnerabilities":[{"id":"CVE-2026-54875","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"urls":["https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257","https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8","https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28","https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov"}]},{"artifact":{"id":"27e0524b85198251","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.09781999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.  This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"36b0b2f615d7105d","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54872","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54872","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"risk":0.08810499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing.  Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key.  CWE: CWE-208: Observable Timing Discrepancy  Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce.  The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1.  Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue.  The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected.  FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path."},"relatedVulnerabilities":[{"id":"CVE-2026-54872","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"urls":["https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179","https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb","https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd","https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."}]},{"artifact":{"id":"36b0b2f615d7105d","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:ada8421c741188c83c2e6de96450043e65ce6233e7d2a1d84cd789a0ad97f420","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77696","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-77696","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"risk":0.08140499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77696","description":"Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel.  Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key.  CWE: CWE-208: Observable Timing Discrepancy  Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel.  Applications performing SM2 signature generation are affected on all platforms.  FIPS Impact: no SM2 is not a FIPS algorithm."},"relatedVulnerabilities":[{"id":"CVE-2026-77696","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"urls":["https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9","https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb","https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64","https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77696","description":"Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm."}]},{"artifact":{"id":"27e0524b85198251","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07128000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.    This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"27e0524b85198251","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.07005999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.  Exploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"27e0524b85198251","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.04257,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.  When such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"27e0524b85198251","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:8a3b315d45080ecb38e39d42d28e951303c67c2ce7482bcdbbc3b5424be19013","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6368","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6368","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6368","date":"2026-10-08","epss":0.00107,"percentile":0.01073}],"risk":0.027285,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6368","description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process."},"relatedVulnerabilities":[{"id":"CVE-2026-6368","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6368","date":"2026-10-08","epss":0.00107,"percentile":0.01073}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34090","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6368","description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process."}]},{"artifact":{"id":"fcf05dfa1b134d92","cpes":["cpe:2.3:a:klauspost:compress:v1.18.0:*:*:*:*:*:*:*"],"name":"github.com/klauspost/compress","purl":"pkg:golang/github.com/klauspost/compress@v1.18.0","type":"go-module","version":"v1.18.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:c/Cqfb0r+Yi+JtIEq73FWXVkRonBlf0CRNYc8Zttxdo=","mainModule":"github.com/cloudflare/cloudflared","architecture":"amd64","goCompiledVersion":"go1.26.8"},"locations":[{"path":"/usr/local/bin/cloudflared","layerID":"sha256:57327e6467daae34e7bdcffe17eca8ce4d1f72f94bf0c216bc5c19132ba23b09","accessPath":"/usr/local/bin/cloudflared","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.18.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5841","versionConstraint":">=1.16.0,<1.18.7 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/klauspost/compress","version":"v1.18.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5841","fix":{"state":"fixed","versions":["1.18.7"],"available":[{"date":"2026-06-30","kind":"release","version":"1.18.7"}]},"cvss":[],"risk":0,"urls":["https://github.com/klauspost/compress/commit/8668e357e776d5152ed62f33c17f21b8690664fa"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://github.com/klauspost/compress/security/advisories/GHSA-259r-337f-4rfw","description":"Providing a specially crafted dictionary to s2.NewDict and using it to encode data can make the encoder read out of bounds."},"relatedVulnerabilities":[{"id":"GHSA-259r-337f-4rfw","cvss":[],"urls":[],"severity":"Unknown","namespace":"github:language:go","dataSource":"github"}]},{"artifact":{"id":"3adca89c3c5f952b","cpes":["cpe:2.3:a:golang:crypto:v0.55.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.55.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.55.0","type":"go-module","version":"v0.55.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:+KWHjbgOaAQ66dh/YlkZKHlz9ZUlq61AFirAR9ntP8M=","mainModule":"github.com/cloudflare/cloudflared","architecture":"amd64","goCompiledVersion":"go1.26.8"},"locations":[{"path":"/usr/local/bin/cloudflared","layerID":"sha256:57327e6467daae34e7bdcffe17eca8ce4d1f72f94bf0c216bc5c19132ba23b09","accessPath":"/usr/local/bin/cloudflared","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5932","versionConstraint":"none (unknown)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.55.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5932","fix":{"state":"","versions":[]},"cvss":[],"risk":0,"urls":[],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/44226","description":"The golang.org/x/crypto/openpgp package is unsafe by design, has numerous known security issues, is not maintained, and should not be used.\n\nIf you are required to interoperate with OpenPGP systems and need a maintained package, consider github.com/ProtonMail/go-crypto/openpgp which is a maintained fork that aims to be a drop-in replacement for this package."},"relatedVulnerabilities":[]},{"artifact":{"id":"5ed4813328099e53","cpes":["cpe:2.3:a:golang:networking:v0.58.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.58.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.58.0","type":"go-module","version":"v0.58.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ynWG7rqYi4ccpTEuPZ2QGWHktVEM9DMCj9yzDE0Q7To=","mainModule":"github.com/cloudflare/cloudflared","architecture":"amd64","goCompiledVersion":"go1.26.8"},"locations":[{"path":"/usr/local/bin/cloudflared","layerID":"sha256:57327e6467daae34e7bdcffe17eca8ce4d1f72f94bf0c216bc5c19132ba23b09","accessPath":"/usr/local/bin/cloudflared","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.60.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6603","versionConstraint":"<0.60.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.58.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6603","fix":{"state":"fixed","versions":["0.60.0"],"available":[{"date":"2026-10-08","kind":"release","version":"0.60.0"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847185","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."},"relatedVulnerabilities":[{"id":"CVE-2026-78659","cvss":[],"urls":["https://go.dev/cl/847185","https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6603"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78659","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."}]},{"artifact":{"id":"5ed4813328099e53","cpes":["cpe:2.3:a:golang:networking:v0.58.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.58.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.58.0","type":"go-module","version":"v0.58.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ynWG7rqYi4ccpTEuPZ2QGWHktVEM9DMCj9yzDE0Q7To=","mainModule":"github.com/cloudflare/cloudflared","architecture":"amd64","goCompiledVersion":"go1.26.8"},"locations":[{"path":"/usr/local/bin/cloudflared","layerID":"sha256:57327e6467daae34e7bdcffe17eca8ce4d1f72f94bf0c216bc5c19132ba23b09","accessPath":"/usr/local/bin/cloudflared","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.60.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6610","versionConstraint":"<0.60.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.58.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6610","fix":{"state":"fixed","versions":["0.60.0"],"available":[{"date":"2026-10-08","kind":"release","version":"0.60.0"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/835145","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."},"relatedVulnerabilities":[{"id":"CVE-2026-78660","cvss":[],"urls":["https://go.dev/cl/835145","https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6610"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78660","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."}]},{"artifact":{"id":"5ed4813328099e53","cpes":["cpe:2.3:a:golang:networking:v0.58.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.58.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.58.0","type":"go-module","version":"v0.58.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ynWG7rqYi4ccpTEuPZ2QGWHktVEM9DMCj9yzDE0Q7To=","mainModule":"github.com/cloudflare/cloudflared","architecture":"amd64","goCompiledVersion":"go1.26.8"},"locations":[{"path":"/usr/local/bin/cloudflared","layerID":"sha256:57327e6467daae34e7bdcffe17eca8ce4d1f72f94bf0c216bc5c19132ba23b09","accessPath":"/usr/local/bin/cloudflared","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.60.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6611","versionConstraint":"<0.60.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.58.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6611","fix":{"state":"fixed","versions":["0.60.0"],"available":[{"date":"2026-10-08","kind":"release","version":"0.60.0"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847186","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."},"relatedVulnerabilities":[{"id":"CVE-2026-78669","cvss":[],"urls":["https://go.dev/cl/847186","https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6611"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78669","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."}]},{"artifact":{"id":"5ed4813328099e53","cpes":["cpe:2.3:a:golang:networking:v0.58.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.58.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.58.0","type":"go-module","version":"v0.58.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ynWG7rqYi4ccpTEuPZ2QGWHktVEM9DMCj9yzDE0Q7To=","mainModule":"github.com/cloudflare/cloudflared","architecture":"amd64","goCompiledVersion":"go1.26.8"},"locations":[{"path":"/usr/local/bin/cloudflared","layerID":"sha256:57327e6467daae34e7bdcffe17eca8ce4d1f72f94bf0c216bc5c19132ba23b09","accessPath":"/usr/local/bin/cloudflared","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.60.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6612","versionConstraint":"<0.60.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.58.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6612","fix":{"state":"fixed","versions":["0.60.0"],"available":[{"date":"2026-10-08","kind":"release","version":"0.60.0"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847187","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."},"relatedVulnerabilities":[{"id":"CVE-2026-78663","cvss":[],"urls":["https://go.dev/cl/847187","https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6612"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78663","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."}]},{"artifact":{"id":"5ed4813328099e53","cpes":["cpe:2.3:a:golang:networking:v0.58.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.58.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.58.0","type":"go-module","version":"v0.58.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ynWG7rqYi4ccpTEuPZ2QGWHktVEM9DMCj9yzDE0Q7To=","mainModule":"github.com/cloudflare/cloudflared","architecture":"amd64","goCompiledVersion":"go1.26.8"},"locations":[{"path":"/usr/local/bin/cloudflared","layerID":"sha256:57327e6467daae34e7bdcffe17eca8ce4d1f72f94bf0c216bc5c19132ba23b09","accessPath":"/usr/local/bin/cloudflared","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.60.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6617","versionConstraint":"<0.60.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.58.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6617","fix":{"state":"fixed","versions":["0.60.0"],"available":[{"date":"2026-10-08","kind":"release","version":"0.60.0"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847188","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."},"relatedVulnerabilities":[{"id":"CVE-2026-97032","cvss":[],"urls":["https://go.dev/cl/847188","https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6617"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97032","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."}]},{"artifact":{"id":"06ec5725311f8f8d","cpes":["cpe:2.3:a:golang:go:1.26.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.8","type":"go-module","version":"go1.26.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.8"},"locations":[{"path":"/usr/local/bin/cloudflared","layerID":"sha256:57327e6467daae34e7bdcffe17eca8ce4d1f72f94bf0c216bc5c19132ba23b09","accessPath":"/usr/local/bin/cloudflared","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6599","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6599","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81821","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/839866","description":"When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression.\n\nWe now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped."},"relatedVulnerabilities":[{"id":"CVE-2026-94448","cvss":[],"urls":["https://go.dev/cl/839866","https://go.dev/issue/81821","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6599"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94448","description":"When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression. We now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped."}]},{"artifact":{"id":"06ec5725311f8f8d","cpes":["cpe:2.3:a:golang:go:1.26.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.8","type":"go-module","version":"go1.26.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.8"},"locations":[{"path":"/usr/local/bin/cloudflared","layerID":"sha256:57327e6467daae34e7bdcffe17eca8ce4d1f72f94bf0c216bc5c19132ba23b09","accessPath":"/usr/local/bin/cloudflared","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6600","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6600","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81823","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/840925","description":"A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped.\n\nWe now ensure that valid keyword uses are escaped and non-keyword uses are not escaped."},"relatedVulnerabilities":[{"id":"CVE-2026-97030","cvss":[],"urls":["https://go.dev/cl/840925","https://go.dev/issue/81823","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6600"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97030","description":"A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped."}]},{"artifact":{"id":"06ec5725311f8f8d","cpes":["cpe:2.3:a:golang:go:1.26.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.8","type":"go-module","version":"go1.26.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.8"},"locations":[{"path":"/usr/local/bin/cloudflared","layerID":"sha256:57327e6467daae34e7bdcffe17eca8ce4d1f72f94bf0c216bc5c19132ba23b09","accessPath":"/usr/local/bin/cloudflared","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6603","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6603","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847185","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."},"relatedVulnerabilities":[{"id":"CVE-2026-78659","cvss":[],"urls":["https://go.dev/cl/847185","https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6603"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78659","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."}]},{"artifact":{"id":"06ec5725311f8f8d","cpes":["cpe:2.3:a:golang:go:1.26.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.8","type":"go-module","version":"go1.26.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.8"},"locations":[{"path":"/usr/local/bin/cloudflared","layerID":"sha256:57327e6467daae34e7bdcffe17eca8ce4d1f72f94bf0c216bc5c19132ba23b09","accessPath":"/usr/local/bin/cloudflared","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6604","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6604","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81739","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847305","description":"On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target)."},"relatedVulnerabilities":[{"id":"CVE-2026-56857","cvss":[],"urls":["https://go.dev/cl/847305","https://go.dev/issue/81739","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6604"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56857","description":"On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target)."}]},{"artifact":{"id":"06ec5725311f8f8d","cpes":["cpe:2.3:a:golang:go:1.26.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.8","type":"go-module","version":"go1.26.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.8"},"locations":[{"path":"/usr/local/bin/cloudflared","layerID":"sha256:57327e6467daae34e7bdcffe17eca8ce4d1f72f94bf0c216bc5c19132ba23b09","accessPath":"/usr/local/bin/cloudflared","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6605","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6605","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81740","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847306","description":"When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning."},"relatedVulnerabilities":[{"id":"CVE-2026-56866","cvss":[],"urls":["https://go.dev/cl/847306","https://go.dev/issue/81740","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6605"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56866","description":"When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning."}]},{"artifact":{"id":"06ec5725311f8f8d","cpes":["cpe:2.3:a:golang:go:1.26.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.8","type":"go-module","version":"go1.26.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.8"},"locations":[{"path":"/usr/local/bin/cloudflared","layerID":"sha256:57327e6467daae34e7bdcffe17eca8ce4d1f72f94bf0c216bc5c19132ba23b09","accessPath":"/usr/local/bin/cloudflared","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6607","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6607","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81855","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847312","description":"Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references.\n\nWe now reject these as malformed and curb the memory amplification vector as a result."},"relatedVulnerabilities":[{"id":"CVE-2026-97031","cvss":[],"urls":["https://go.dev/cl/847312","https://go.dev/issue/81855","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6607"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97031","description":"Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result."}]},{"artifact":{"id":"06ec5725311f8f8d","cpes":["cpe:2.3:a:golang:go:1.26.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.8","type":"go-module","version":"go1.26.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.8"},"locations":[{"path":"/usr/local/bin/cloudflared","layerID":"sha256:57327e6467daae34e7bdcffe17eca8ce4d1f72f94bf0c216bc5c19132ba23b09","accessPath":"/usr/local/bin/cloudflared","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6608","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6608","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81741","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847307","description":"Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes."},"relatedVulnerabilities":[{"id":"CVE-2026-94440","cvss":[],"urls":["https://go.dev/cl/847307","https://go.dev/issue/81741","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6608"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94440","description":"Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes."}]},{"artifact":{"id":"06ec5725311f8f8d","cpes":["cpe:2.3:a:golang:go:1.26.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.8","type":"go-module","version":"go1.26.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.8"},"locations":[{"path":"/usr/local/bin/cloudflared","layerID":"sha256:57327e6467daae34e7bdcffe17eca8ce4d1f72f94bf0c216bc5c19132ba23b09","accessPath":"/usr/local/bin/cloudflared","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6609","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6609","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81858","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847309","description":"When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU."},"relatedVulnerabilities":[{"id":"CVE-2026-78667","cvss":[],"urls":["https://go.dev/cl/847309","https://go.dev/issue/81858","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6609"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78667","description":"When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU."}]},{"artifact":{"id":"06ec5725311f8f8d","cpes":["cpe:2.3:a:golang:go:1.26.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.8","type":"go-module","version":"go1.26.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.8"},"locations":[{"path":"/usr/local/bin/cloudflared","layerID":"sha256:57327e6467daae34e7bdcffe17eca8ce4d1f72f94bf0c216bc5c19132ba23b09","accessPath":"/usr/local/bin/cloudflared","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6610","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6610","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/835145","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."},"relatedVulnerabilities":[{"id":"CVE-2026-78660","cvss":[],"urls":["https://go.dev/cl/835145","https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6610"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78660","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."}]},{"artifact":{"id":"06ec5725311f8f8d","cpes":["cpe:2.3:a:golang:go:1.26.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.8","type":"go-module","version":"go1.26.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.8"},"locations":[{"path":"/usr/local/bin/cloudflared","layerID":"sha256:57327e6467daae34e7bdcffe17eca8ce4d1f72f94bf0c216bc5c19132ba23b09","accessPath":"/usr/local/bin/cloudflared","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6611","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6611","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847186","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."},"relatedVulnerabilities":[{"id":"CVE-2026-78669","cvss":[],"urls":["https://go.dev/cl/847186","https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6611"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78669","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."}]},{"artifact":{"id":"06ec5725311f8f8d","cpes":["cpe:2.3:a:golang:go:1.26.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.8","type":"go-module","version":"go1.26.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.8"},"locations":[{"path":"/usr/local/bin/cloudflared","layerID":"sha256:57327e6467daae34e7bdcffe17eca8ce4d1f72f94bf0c216bc5c19132ba23b09","accessPath":"/usr/local/bin/cloudflared","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6612","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6612","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847187","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."},"relatedVulnerabilities":[{"id":"CVE-2026-78663","cvss":[],"urls":["https://go.dev/cl/847187","https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6612"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78663","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."}]},{"artifact":{"id":"06ec5725311f8f8d","cpes":["cpe:2.3:a:golang:go:1.26.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.8","type":"go-module","version":"go1.26.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.8"},"locations":[{"path":"/usr/local/bin/cloudflared","layerID":"sha256:57327e6467daae34e7bdcffe17eca8ce4d1f72f94bf0c216bc5c19132ba23b09","accessPath":"/usr/local/bin/cloudflared","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6613","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6613","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81744","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847311","description":"When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP.\n\nThe impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP."},"relatedVulnerabilities":[{"id":"CVE-2026-94439","cvss":[],"urls":["https://go.dev/cl/847311","https://go.dev/issue/81744","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6613"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94439","description":"When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP. The impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP."}]},{"artifact":{"id":"06ec5725311f8f8d","cpes":["cpe:2.3:a:golang:go:1.26.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.8","type":"go-module","version":"go1.26.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.8"},"locations":[{"path":"/usr/local/bin/cloudflared","layerID":"sha256:57327e6467daae34e7bdcffe17eca8ce4d1f72f94bf0c216bc5c19132ba23b09","accessPath":"/usr/local/bin/cloudflared","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6617","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6617","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847188","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."},"relatedVulnerabilities":[{"id":"CVE-2026-97032","cvss":[],"urls":["https://go.dev/cl/847188","https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6617"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97032","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."}]}],"grade":"D","score":"40.00","as_of":"2026-10-10T12:28:16.811Z","grype_db_version":"2026-10-09T06:32:32.000Z"}