{"grype_matches":[{"artifact":{"id":"ebdf865d13d21735","cpes":["cpe:2.3:a:libwmf-0.2-7:libwmf-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf-0.2-7:libwmf_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf_0.2_7:libwmf-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf_0.2_7:libwmf_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf-0.2:libwmf-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf-0.2:libwmf_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf_0.2:libwmf-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf_0.2:libwmf_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf:libwmf-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf:libwmf_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*"],"name":"libwmf-0.2-7","purl":"pkg:deb/debian/libwmf-0.2-7@0.2.12-5.1?arch=amd64&distro=debian-12.15&upstream=libwmf","type":"deb","version":"0.2.12-5.1","language":"","licenses":["AGPL-3","GD","ISC","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libwmf-0.2-7/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libwmf-0.2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libwmf-0.2-7:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libwmf-0.2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libwmf"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2009-3546","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libwmf","version":"0.2.12-5.1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2009-3546","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2009-3546","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2009-3546","date":"2026-10-08","epss":0.10247,"percentile":0.95576}],"risk":5.1235,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2009-3546","description":"The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information."},"relatedVulnerabilities":[{"id":"CVE-2009-3546","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","metrics":{"baseScore":9.3,"impactScore":10.1,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2009-3546","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2009-3546","date":"2026-10-08","epss":0.10247,"percentile":0.95576}],"urls":["http://marc.info/?l=oss-security&m=125562113503923&w=2","http://secunia.com/advisories/37069","http://secunia.com/advisories/37080","http://secunia.com/advisories/38055","http://svn.php.net/viewvc?view=revision&revision=289557","http://www.mandriva.com/security/advisories?name=MDVSA-2009:285","http://www.openwall.com/lists/oss-security/2009/11/20/5","http://www.redhat.com/support/errata/RHSA-2010-0003.html","http://www.securityfocus.com/bid/36712","http://www.vupen.com/english/advisories/2009/2929","http://www.vupen.com/english/advisories/2009/2930","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11199"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2009-3546","description":"The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information."}]},{"artifact":{"id":"fefa72b1191e1443","cpes":["cpe:2.3:a:libwmf-dev:libwmf-dev:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf-dev:libwmf_dev:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf_dev:libwmf-dev:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf_dev:libwmf_dev:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf:libwmf-dev:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf:libwmf_dev:0.2.12-5.1:*:*:*:*:*:*:*"],"name":"libwmf-dev","purl":"pkg:deb/debian/libwmf-dev@0.2.12-5.1?arch=amd64&distro=debian-12.15&upstream=libwmf","type":"deb","version":"0.2.12-5.1","language":"","licenses":["AGPL-3","GD","ISC","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libwmf-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libwmf-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libwmf-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libwmf-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libwmf-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libwmf-dev.list"},{"path":"/var/lib/dpkg/info/libwmf-dev.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libwmf-dev.preinst"}],"upstreams":[{"name":"libwmf"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2009-3546","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libwmf","version":"0.2.12-5.1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2009-3546","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2009-3546","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2009-3546","date":"2026-10-08","epss":0.10247,"percentile":0.95576}],"risk":5.1235,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2009-3546","description":"The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information."},"relatedVulnerabilities":[{"id":"CVE-2009-3546","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","metrics":{"baseScore":9.3,"impactScore":10.1,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2009-3546","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2009-3546","date":"2026-10-08","epss":0.10247,"percentile":0.95576}],"urls":["http://marc.info/?l=oss-security&m=125562113503923&w=2","http://secunia.com/advisories/37069","http://secunia.com/advisories/37080","http://secunia.com/advisories/38055","http://svn.php.net/viewvc?view=revision&revision=289557","http://www.mandriva.com/security/advisories?name=MDVSA-2009:285","http://www.openwall.com/lists/oss-security/2009/11/20/5","http://www.redhat.com/support/errata/RHSA-2010-0003.html","http://www.securityfocus.com/bid/36712","http://www.vupen.com/english/advisories/2009/2929","http://www.vupen.com/english/advisories/2009/2930","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11199"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2009-3546","description":"The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information."}]},{"artifact":{"id":"218765409402dcb0","cpes":["cpe:2.3:a:libwmflite-0.2-7:libwmflite-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite-0.2-7:libwmflite_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite_0.2_7:libwmflite-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite_0.2_7:libwmflite_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite-0.2:libwmflite-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite-0.2:libwmflite_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite_0.2:libwmflite-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite_0.2:libwmflite_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite:libwmflite-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite:libwmflite_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*"],"name":"libwmflite-0.2-7","purl":"pkg:deb/debian/libwmflite-0.2-7@0.2.12-5.1?arch=amd64&distro=debian-12.15&upstream=libwmf","type":"deb","version":"0.2.12-5.1","language":"","licenses":["AGPL-3","GD","ISC","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libwmflite-0.2-7/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libwmflite-0.2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libwmflite-0.2-7:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libwmflite-0.2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libwmf"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2009-3546","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libwmf","version":"0.2.12-5.1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2009-3546","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2009-3546","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2009-3546","date":"2026-10-08","epss":0.10247,"percentile":0.95576}],"risk":5.1235,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2009-3546","description":"The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information."},"relatedVulnerabilities":[{"id":"CVE-2009-3546","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","metrics":{"baseScore":9.3,"impactScore":10.1,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2009-3546","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2009-3546","date":"2026-10-08","epss":0.10247,"percentile":0.95576}],"urls":["http://marc.info/?l=oss-security&m=125562113503923&w=2","http://secunia.com/advisories/37069","http://secunia.com/advisories/37080","http://secunia.com/advisories/38055","http://svn.php.net/viewvc?view=revision&revision=289557","http://www.mandriva.com/security/advisories?name=MDVSA-2009:285","http://www.openwall.com/lists/oss-security/2009/11/20/5","http://www.redhat.com/support/errata/RHSA-2010-0003.html","http://www.securityfocus.com/bid/36712","http://www.vupen.com/english/advisories/2009/2929","http://www.vupen.com/english/advisories/2009/2930","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11199"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2009-3546","description":"The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information."}]},{"artifact":{"id":"d1631d475c37518a","cpes":["cpe:2.3:a:libgnutls30:libgnutls30:3.7.9-2\\+deb12u7:*:*:*:*:*:*:*"],"name":"libgnutls30","purl":"pkg:deb/debian/libgnutls30@3.7.9-2%2Bdeb12u7?arch=amd64&distro=debian-12.15&upstream=gnutls28","type":"deb","version":"3.7.9-2+deb12u7","language":"","licenses":["sha256:bb7e5c24b3e27bbba5671dd710d159a0066833bda4caa1d55d8027ffed539337"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgnutls30/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libgnutls30/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30:amd64.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libgnutls30:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2011-3389","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnutls28","version":"3.7.9-2+deb12u7"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2011-3389","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2011-3389","cwe":"CWE-326","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-3389","date":"2026-10-08","epss":0.73327,"percentile":0.99453}],"risk":3.66635,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-3389","description":"The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack."},"relatedVulnerabilities":[{"id":"CVE-2011-3389","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2011-3389","cwe":"CWE-326","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-3389","date":"2026-10-08","epss":0.73327,"percentile":0.99453}],"urls":["http://blog.mozilla.com/security/2011/09/27/attack-against-tls-protected-communications/","http://blogs.technet.com/b/msrc/archive/2011/09/26/microsoft-releases-security-advisory-2588513.aspx","http://blogs.technet.com/b/srd/archive/2011/09/26/is-ssl-broken-more-about-security-advisory-2588513.aspx","http://curl.haxx.se/docs/adv_20120124B.html","http://downloads.asterisk.org/pub/security/AST-2016-001.html","http://ekoparty.org/2011/juliano-rizzo.php","http://eprint.iacr.org/2004/111","http://eprint.iacr.org/2006/136","http://googlechromereleases.blogspot.com/2011/10/chrome-stable-release.html","http://isc.sans.edu/diary/SSL+TLS+part+3+/11635","http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html","http://lists.apple.com/archives/Security-announce/2011//Oct/msg00002.html","http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html","http://lists.apple.com/archives/security-announce/2012/Jul/msg00001.html","http://lists.apple.com/archives/security-announce/2012/May/msg00001.html","http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html","http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.html","http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.html","http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00051.html","http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00009.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","http://marc.info/?l=bugtraq&m=132750579901589&w=2","http://marc.info/?l=bugtraq&m=132872385320240&w=2","http://marc.info/?l=bugtraq&m=133365109612558&w=2","http://marc.info/?l=bugtraq&m=133728004526190&w=2","http://marc.info/?l=bugtraq&m=134254866602253&w=2","http://marc.info/?l=bugtraq&m=134254957702612&w=2","http://my.opera.com/securitygroup/blog/2011/09/28/the-beast-ssl-tls-issue","http://osvdb.org/74829","http://rhn.redhat.com/errata/RHSA-2012-0508.html","http://rhn.redhat.com/errata/RHSA-2013-1455.html","http://secunia.com/advisories/45791","http://secunia.com/advisories/47998","http://secunia.com/advisories/48256","http://secunia.com/advisories/48692","http://secunia.com/advisories/48915","http://secunia.com/advisories/48948","http://secunia.com/advisories/49198","http://secunia.com/advisories/55322","http://secunia.com/advisories/55350","http://secunia.com/advisories/55351","http://security.gentoo.org/glsa/glsa-201203-02.xml","http://security.gentoo.org/glsa/glsa-201406-32.xml","http://support.apple.com/kb/HT4999","http://support.apple.com/kb/HT5001","http://support.apple.com/kb/HT5130","http://support.apple.com/kb/HT5281","http://support.apple.com/kb/HT5501","http://support.apple.com/kb/HT6150","http://technet.microsoft.com/security/advisory/2588513","http://vnhacker.blogspot.com/2011/09/beast.html","http://www.apcmedia.com/salestools/SJHN-7RKGNM/SJHN-7RKGNM_R4_EN.pdf","http://www.debian.org/security/2012/dsa-2398","http://www.educatedguesswork.org/2011/09/security_impact_of_the_rizzodu.html","http://www.ibm.com/developerworks/java/jdk/alerts/","http://www.imperialviolet.org/2011/09/23/chromeandbeast.html","http://www.insecure.cl/Beast-SSL.rar","http://www.kb.cert.org/vuls/id/864643","http://www.mandriva.com/security/advisories?name=MDVSA-2012:058","http://www.opera.com/docs/changelogs/mac/1151/","http://www.opera.com/docs/changelogs/mac/1160/","http://www.opera.com/docs/changelogs/unix/1151/","http://www.opera.com/docs/changelogs/unix/1160/","http://www.opera.com/docs/changelogs/windows/1151/","http://www.opera.com/docs/changelogs/windows/1160/","http://www.opera.com/support/kb/view/1004/","http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html","http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html","http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html","http://www.redhat.com/support/errata/RHSA-2011-1384.html","http://www.redhat.com/support/errata/RHSA-2012-0006.html","http://www.securityfocus.com/bid/49388","http://www.securityfocus.com/bid/49778","http://www.securitytracker.com/id/1029190","http://www.securitytracker.com/id?1025997","http://www.securitytracker.com/id?1026103","http://www.securitytracker.com/id?1026704","http://www.ubuntu.com/usn/USN-1263-1","http://www.us-cert.gov/cas/techalerts/TA12-010A.html","https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_fetchmail","https://bugzilla.novell.com/show_bug.cgi?id=719047","https://bugzilla.redhat.com/show_bug.cgi?id=737506","https://cert-portal.siemens.com/productcert/pdf/ssa-556833.pdf","https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-006","https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03839862","https://hermes.opensuse.org/messages/13154861","https://hermes.opensuse.org/messages/13155432","https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14752"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-3389","description":"The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack."}]},{"artifact":{"id":"3f28e512f3f6e928","cpes":["cpe:2.3:a:zlib1g-dev:zlib1g-dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:zlib1g-dev:zlib1g_dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:zlib1g_dev:zlib1g-dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:zlib1g_dev:zlib1g_dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:zlib1g:zlib1g-dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:zlib1g:zlib1g_dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*"],"name":"zlib1g-dev","purl":"pkg:deb/debian/zlib1g-dev@1%3A1.2.13.dfsg-1?arch=amd64&distro=debian-12.15&upstream=zlib","type":"deb","version":"1:1.2.13.dfsg-1","language":"","licenses":["Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/zlib1g-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/zlib1g-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-45853","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"zlib","version":"1:1.2.13.dfsg-1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-45853","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-45853","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-45853","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-45853","date":"2026-10-08","epss":0.03179,"percentile":0.87678}],"risk":2.9882600000000004,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-45853","description":"MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API."},"relatedVulnerabilities":[{"id":"CVE-2023-45853","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-45853","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-45853","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-45853","date":"2026-10-08","epss":0.03179,"percentile":0.87678}],"urls":["http://www.openwall.com/lists/oss-security/2023/10/20/9","http://www.openwall.com/lists/oss-security/2024/01/24/10","https://chromium.googlesource.com/chromium/src/+/d709fb23806858847131027da95ef4c548813356","https://chromium.googlesource.com/chromium/src/+/de29dd6c7151d3cd37cb4cf0036800ddfb1d8b61","https://github.com/madler/zlib/blob/ac8f12c97d1afd9bafa9c710f827d40a407d3266/contrib/README.contrib#L1-L4","https://github.com/madler/zlib/pull/843","https://lists.debian.org/debian-lts-announce/2023/11/msg00026.html","https://pypi.org/project/pyminizip/#history","https://security.gentoo.org/glsa/202401-18","https://security.netapp.com/advisory/ntap-20231130-0009/","https://www.winimage.com/zLibDll/minizip.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-470355.html","https://cert-portal.siemens.com/productcert/html/ssa-769027.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45853","description":"MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API."}]},{"artifact":{"id":"ebdf865d13d21735","cpes":["cpe:2.3:a:libwmf-0.2-7:libwmf-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf-0.2-7:libwmf_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf_0.2_7:libwmf-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf_0.2_7:libwmf_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf-0.2:libwmf-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf-0.2:libwmf_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf_0.2:libwmf-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf_0.2:libwmf_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf:libwmf-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf:libwmf_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*"],"name":"libwmf-0.2-7","purl":"pkg:deb/debian/libwmf-0.2-7@0.2.12-5.1?arch=amd64&distro=debian-12.15&upstream=libwmf","type":"deb","version":"0.2.12-5.1","language":"","licenses":["AGPL-3","GD","ISC","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libwmf-0.2-7/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libwmf-0.2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libwmf-0.2-7:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libwmf-0.2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libwmf"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-3996","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libwmf","version":"0.2.12-5.1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2007-3996","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-3996","cwe":"CWE-189","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-3996","date":"2026-10-08","epss":0.04219,"percentile":0.90736}],"risk":2.1094999999999997,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-3996","description":"Multiple integer overflows in libgd in PHP before 5.2.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large (1) srcW or (2) srcH value to the (a) gdImageCopyResized function, or a large (3) sy (height) or (4) sx (width) value to the (b) gdImageCreate or the (c) gdImageCreateTrueColor function."},"relatedVulnerabilities":[{"id":"CVE-2007-3996","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-3996","cwe":"CWE-189","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-3996","date":"2026-10-08","epss":0.04219,"percentile":0.90736}],"urls":["http://bugs.gentoo.org/show_bug.cgi?id=201546","http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00006.html","http://rhn.redhat.com/errata/RHSA-2007-0889.html","http://secunia.com/advisories/26642","http://secunia.com/advisories/26822","http://secunia.com/advisories/26838","http://secunia.com/advisories/26871","http://secunia.com/advisories/26895","http://secunia.com/advisories/26930","http://secunia.com/advisories/26967","http://secunia.com/advisories/27102","http://secunia.com/advisories/27351","http://secunia.com/advisories/27377","http://secunia.com/advisories/27545","http://secunia.com/advisories/28009","http://secunia.com/advisories/28147","http://secunia.com/advisories/28658","http://secunia.com/advisories/31168","http://security.gentoo.org/glsa/glsa-200712-13.xml","http://securityreason.com/securityalert/3103","http://secweb.se/en/advisories/php-imagecopyresized-integer-overflow/","http://secweb.se/en/advisories/php-imagecreatetruecolor-integer-overflow/","http://support.avaya.com/elmodocs2/security/ASA-2007-449.htm","http://www.debian.org/security/2008/dsa-1613","http://www.gentoo.org/security/en/glsa/glsa-200710-02.xml","http://www.mandriva.com/security/advisories?name=MDKSA-2007:187","http://www.php.net/ChangeLog-5.php#5.2.4","http://www.php.net/releases/5_2_4.php","http://www.redhat.com/support/errata/RHSA-2007-0888.html","http://www.redhat.com/support/errata/RHSA-2007-0890.html","http://www.redhat.com/support/errata/RHSA-2007-0891.html","http://www.trustix.org/errata/2007/0026/","http://www.ubuntu.com/usn/usn-557-1","http://www.vupen.com/english/advisories/2007/3023","https://exchange.xforce.ibmcloud.com/vulnerabilities/36382","https://exchange.xforce.ibmcloud.com/vulnerabilities/36383","https://issues.rpath.com/browse/RPL-1693","https://issues.rpath.com/browse/RPL-1702","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11147","https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00354.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-3996","description":"Multiple integer overflows in libgd in PHP before 5.2.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large (1) srcW or (2) srcH value to the (a) gdImageCopyResized function, or a large (3) sy (height) or (4) sx (width) value to the (b) gdImageCreate or the (c) gdImageCreateTrueColor function."}]},{"artifact":{"id":"fefa72b1191e1443","cpes":["cpe:2.3:a:libwmf-dev:libwmf-dev:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf-dev:libwmf_dev:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf_dev:libwmf-dev:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf_dev:libwmf_dev:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf:libwmf-dev:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf:libwmf_dev:0.2.12-5.1:*:*:*:*:*:*:*"],"name":"libwmf-dev","purl":"pkg:deb/debian/libwmf-dev@0.2.12-5.1?arch=amd64&distro=debian-12.15&upstream=libwmf","type":"deb","version":"0.2.12-5.1","language":"","licenses":["AGPL-3","GD","ISC","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libwmf-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libwmf-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libwmf-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libwmf-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libwmf-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libwmf-dev.list"},{"path":"/var/lib/dpkg/info/libwmf-dev.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libwmf-dev.preinst"}],"upstreams":[{"name":"libwmf"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-3996","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libwmf","version":"0.2.12-5.1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2007-3996","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-3996","cwe":"CWE-189","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-3996","date":"2026-10-08","epss":0.04219,"percentile":0.90736}],"risk":2.1094999999999997,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-3996","description":"Multiple integer overflows in libgd in PHP before 5.2.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large (1) srcW or (2) srcH value to the (a) gdImageCopyResized function, or a large (3) sy (height) or (4) sx (width) value to the (b) gdImageCreate or the (c) gdImageCreateTrueColor function."},"relatedVulnerabilities":[{"id":"CVE-2007-3996","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-3996","cwe":"CWE-189","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-3996","date":"2026-10-08","epss":0.04219,"percentile":0.90736}],"urls":["http://bugs.gentoo.org/show_bug.cgi?id=201546","http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00006.html","http://rhn.redhat.com/errata/RHSA-2007-0889.html","http://secunia.com/advisories/26642","http://secunia.com/advisories/26822","http://secunia.com/advisories/26838","http://secunia.com/advisories/26871","http://secunia.com/advisories/26895","http://secunia.com/advisories/26930","http://secunia.com/advisories/26967","http://secunia.com/advisories/27102","http://secunia.com/advisories/27351","http://secunia.com/advisories/27377","http://secunia.com/advisories/27545","http://secunia.com/advisories/28009","http://secunia.com/advisories/28147","http://secunia.com/advisories/28658","http://secunia.com/advisories/31168","http://security.gentoo.org/glsa/glsa-200712-13.xml","http://securityreason.com/securityalert/3103","http://secweb.se/en/advisories/php-imagecopyresized-integer-overflow/","http://secweb.se/en/advisories/php-imagecreatetruecolor-integer-overflow/","http://support.avaya.com/elmodocs2/security/ASA-2007-449.htm","http://www.debian.org/security/2008/dsa-1613","http://www.gentoo.org/security/en/glsa/glsa-200710-02.xml","http://www.mandriva.com/security/advisories?name=MDKSA-2007:187","http://www.php.net/ChangeLog-5.php#5.2.4","http://www.php.net/releases/5_2_4.php","http://www.redhat.com/support/errata/RHSA-2007-0888.html","http://www.redhat.com/support/errata/RHSA-2007-0890.html","http://www.redhat.com/support/errata/RHSA-2007-0891.html","http://www.trustix.org/errata/2007/0026/","http://www.ubuntu.com/usn/usn-557-1","http://www.vupen.com/english/advisories/2007/3023","https://exchange.xforce.ibmcloud.com/vulnerabilities/36382","https://exchange.xforce.ibmcloud.com/vulnerabilities/36383","https://issues.rpath.com/browse/RPL-1693","https://issues.rpath.com/browse/RPL-1702","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11147","https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00354.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-3996","description":"Multiple integer overflows in libgd in PHP before 5.2.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large (1) srcW or (2) srcH value to the (a) gdImageCopyResized function, or a large (3) sy (height) or (4) sx (width) value to the (b) gdImageCreate or the (c) gdImageCreateTrueColor function."}]},{"artifact":{"id":"218765409402dcb0","cpes":["cpe:2.3:a:libwmflite-0.2-7:libwmflite-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite-0.2-7:libwmflite_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite_0.2_7:libwmflite-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite_0.2_7:libwmflite_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite-0.2:libwmflite-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite-0.2:libwmflite_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite_0.2:libwmflite-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite_0.2:libwmflite_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite:libwmflite-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite:libwmflite_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*"],"name":"libwmflite-0.2-7","purl":"pkg:deb/debian/libwmflite-0.2-7@0.2.12-5.1?arch=amd64&distro=debian-12.15&upstream=libwmf","type":"deb","version":"0.2.12-5.1","language":"","licenses":["AGPL-3","GD","ISC","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libwmflite-0.2-7/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libwmflite-0.2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libwmflite-0.2-7:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libwmflite-0.2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libwmf"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-3996","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libwmf","version":"0.2.12-5.1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2007-3996","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-3996","cwe":"CWE-189","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-3996","date":"2026-10-08","epss":0.04219,"percentile":0.90736}],"risk":2.1094999999999997,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-3996","description":"Multiple integer overflows in libgd in PHP before 5.2.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large (1) srcW or (2) srcH value to the (a) gdImageCopyResized function, or a large (3) sy (height) or (4) sx (width) value to the (b) gdImageCreate or the (c) gdImageCreateTrueColor function."},"relatedVulnerabilities":[{"id":"CVE-2007-3996","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-3996","cwe":"CWE-189","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-3996","date":"2026-10-08","epss":0.04219,"percentile":0.90736}],"urls":["http://bugs.gentoo.org/show_bug.cgi?id=201546","http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00006.html","http://rhn.redhat.com/errata/RHSA-2007-0889.html","http://secunia.com/advisories/26642","http://secunia.com/advisories/26822","http://secunia.com/advisories/26838","http://secunia.com/advisories/26871","http://secunia.com/advisories/26895","http://secunia.com/advisories/26930","http://secunia.com/advisories/26967","http://secunia.com/advisories/27102","http://secunia.com/advisories/27351","http://secunia.com/advisories/27377","http://secunia.com/advisories/27545","http://secunia.com/advisories/28009","http://secunia.com/advisories/28147","http://secunia.com/advisories/28658","http://secunia.com/advisories/31168","http://security.gentoo.org/glsa/glsa-200712-13.xml","http://securityreason.com/securityalert/3103","http://secweb.se/en/advisories/php-imagecopyresized-integer-overflow/","http://secweb.se/en/advisories/php-imagecreatetruecolor-integer-overflow/","http://support.avaya.com/elmodocs2/security/ASA-2007-449.htm","http://www.debian.org/security/2008/dsa-1613","http://www.gentoo.org/security/en/glsa/glsa-200710-02.xml","http://www.mandriva.com/security/advisories?name=MDKSA-2007:187","http://www.php.net/ChangeLog-5.php#5.2.4","http://www.php.net/releases/5_2_4.php","http://www.redhat.com/support/errata/RHSA-2007-0888.html","http://www.redhat.com/support/errata/RHSA-2007-0890.html","http://www.redhat.com/support/errata/RHSA-2007-0891.html","http://www.trustix.org/errata/2007/0026/","http://www.ubuntu.com/usn/usn-557-1","http://www.vupen.com/english/advisories/2007/3023","https://exchange.xforce.ibmcloud.com/vulnerabilities/36382","https://exchange.xforce.ibmcloud.com/vulnerabilities/36383","https://issues.rpath.com/browse/RPL-1693","https://issues.rpath.com/browse/RPL-1702","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11147","https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00354.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-3996","description":"Multiple integer overflows in libgd in PHP before 5.2.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large (1) srcW or (2) srcH value to the (a) gdImageCopyResized function, or a large (3) sy (height) or (4) sx (width) value to the (b) gdImageCreate or the (c) gdImageCreateTrueColor function."}]},{"artifact":{"id":"ebdf865d13d21735","cpes":["cpe:2.3:a:libwmf-0.2-7:libwmf-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf-0.2-7:libwmf_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf_0.2_7:libwmf-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf_0.2_7:libwmf_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf-0.2:libwmf-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf-0.2:libwmf_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf_0.2:libwmf-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf_0.2:libwmf_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf:libwmf-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf:libwmf_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*"],"name":"libwmf-0.2-7","purl":"pkg:deb/debian/libwmf-0.2-7@0.2.12-5.1?arch=amd64&distro=debian-12.15&upstream=libwmf","type":"deb","version":"0.2.12-5.1","language":"","licenses":["AGPL-3","GD","ISC","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libwmf-0.2-7/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libwmf-0.2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libwmf-0.2-7:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libwmf-0.2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libwmf"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-3477","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libwmf","version":"0.2.12-5.1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2007-3477","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-3477","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-3477","date":"2026-10-08","epss":0.04857,"percentile":0.91808}],"risk":1.4571,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-3477","description":"The (a) imagearc and (b) imagefilledarc functions in GD Graphics Library (libgd) before 2.0.35 allow attackers to cause a denial of service (CPU consumption) via a large (1) start or (2) end angle degree value."},"relatedVulnerabilities":[{"id":"CVE-2007-3477","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-3477","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-3477","date":"2026-10-08","epss":0.04857,"percentile":0.91808}],"urls":["ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/gd-2.0.35-i486-1_slack11.0.tgz","http://bugs.libgd.org/?do=details&task_id=74","http://bugs.libgd.org/?do=details&task_id=92","http://fedoranews.org/updates/FEDORA-2007-205.shtml","http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052848.html","http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052854.html","http://osvdb.org/42062","http://secunia.com/advisories/25860","http://secunia.com/advisories/26272","http://secunia.com/advisories/26390","http://secunia.com/advisories/26415","http://secunia.com/advisories/26467","http://secunia.com/advisories/26663","http://secunia.com/advisories/26766","http://secunia.com/advisories/26856","http://secunia.com/advisories/30168","http://secunia.com/advisories/31168","http://secunia.com/advisories/42813","http://security.gentoo.org/glsa/glsa-200708-05.xml","http://security.gentoo.org/glsa/glsa-200711-34.xml","http://security.gentoo.org/glsa/glsa-200805-13.xml","http://www.debian.org/security/2008/dsa-1613","http://www.libgd.org/ReleaseNote020035","http://www.mandriva.com/security/advisories?name=MDKSA-2007:153","http://www.mandriva.com/security/advisories?name=MDKSA-2007:164","http://www.novell.com/linux/security/advisories/2007_15_sr.html","http://www.redhat.com/archives/fedora-package-announce/2007-September/msg00311.html","http://www.securityfocus.com/archive/1/478796/100/0/threaded","http://www.securityfocus.com/bid/24651","http://www.trustix.org/errata/2007/0024/","http://www.vupen.com/english/advisories/2011/0022","https://bugzilla.redhat.com/show_bug.cgi?id=277421","https://issues.rpath.com/browse/RPL-1643"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-3477","description":"The (a) imagearc and (b) imagefilledarc functions in GD Graphics Library (libgd) before 2.0.35 allow attackers to cause a denial of service (CPU consumption) via a large (1) start or (2) end angle degree value."}]},{"artifact":{"id":"fefa72b1191e1443","cpes":["cpe:2.3:a:libwmf-dev:libwmf-dev:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf-dev:libwmf_dev:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf_dev:libwmf-dev:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf_dev:libwmf_dev:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf:libwmf-dev:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf:libwmf_dev:0.2.12-5.1:*:*:*:*:*:*:*"],"name":"libwmf-dev","purl":"pkg:deb/debian/libwmf-dev@0.2.12-5.1?arch=amd64&distro=debian-12.15&upstream=libwmf","type":"deb","version":"0.2.12-5.1","language":"","licenses":["AGPL-3","GD","ISC","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libwmf-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libwmf-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libwmf-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libwmf-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libwmf-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libwmf-dev.list"},{"path":"/var/lib/dpkg/info/libwmf-dev.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libwmf-dev.preinst"}],"upstreams":[{"name":"libwmf"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-3477","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libwmf","version":"0.2.12-5.1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2007-3477","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-3477","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-3477","date":"2026-10-08","epss":0.04857,"percentile":0.91808}],"risk":1.4571,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-3477","description":"The (a) imagearc and (b) imagefilledarc functions in GD Graphics Library (libgd) before 2.0.35 allow attackers to cause a denial of service (CPU consumption) via a large (1) start or (2) end angle degree value."},"relatedVulnerabilities":[{"id":"CVE-2007-3477","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-3477","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-3477","date":"2026-10-08","epss":0.04857,"percentile":0.91808}],"urls":["ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/gd-2.0.35-i486-1_slack11.0.tgz","http://bugs.libgd.org/?do=details&task_id=74","http://bugs.libgd.org/?do=details&task_id=92","http://fedoranews.org/updates/FEDORA-2007-205.shtml","http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052848.html","http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052854.html","http://osvdb.org/42062","http://secunia.com/advisories/25860","http://secunia.com/advisories/26272","http://secunia.com/advisories/26390","http://secunia.com/advisories/26415","http://secunia.com/advisories/26467","http://secunia.com/advisories/26663","http://secunia.com/advisories/26766","http://secunia.com/advisories/26856","http://secunia.com/advisories/30168","http://secunia.com/advisories/31168","http://secunia.com/advisories/42813","http://security.gentoo.org/glsa/glsa-200708-05.xml","http://security.gentoo.org/glsa/glsa-200711-34.xml","http://security.gentoo.org/glsa/glsa-200805-13.xml","http://www.debian.org/security/2008/dsa-1613","http://www.libgd.org/ReleaseNote020035","http://www.mandriva.com/security/advisories?name=MDKSA-2007:153","http://www.mandriva.com/security/advisories?name=MDKSA-2007:164","http://www.novell.com/linux/security/advisories/2007_15_sr.html","http://www.redhat.com/archives/fedora-package-announce/2007-September/msg00311.html","http://www.securityfocus.com/archive/1/478796/100/0/threaded","http://www.securityfocus.com/bid/24651","http://www.trustix.org/errata/2007/0024/","http://www.vupen.com/english/advisories/2011/0022","https://bugzilla.redhat.com/show_bug.cgi?id=277421","https://issues.rpath.com/browse/RPL-1643"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-3477","description":"The (a) imagearc and (b) imagefilledarc functions in GD Graphics Library (libgd) before 2.0.35 allow attackers to cause a denial of service (CPU consumption) via a large (1) start or (2) end angle degree value."}]},{"artifact":{"id":"218765409402dcb0","cpes":["cpe:2.3:a:libwmflite-0.2-7:libwmflite-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite-0.2-7:libwmflite_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite_0.2_7:libwmflite-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite_0.2_7:libwmflite_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite-0.2:libwmflite-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite-0.2:libwmflite_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite_0.2:libwmflite-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite_0.2:libwmflite_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite:libwmflite-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite:libwmflite_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*"],"name":"libwmflite-0.2-7","purl":"pkg:deb/debian/libwmflite-0.2-7@0.2.12-5.1?arch=amd64&distro=debian-12.15&upstream=libwmf","type":"deb","version":"0.2.12-5.1","language":"","licenses":["AGPL-3","GD","ISC","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libwmflite-0.2-7/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libwmflite-0.2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libwmflite-0.2-7:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libwmflite-0.2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libwmf"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-3477","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libwmf","version":"0.2.12-5.1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2007-3477","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-3477","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-3477","date":"2026-10-08","epss":0.04857,"percentile":0.91808}],"risk":1.4571,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-3477","description":"The (a) imagearc and (b) imagefilledarc functions in GD Graphics Library (libgd) before 2.0.35 allow attackers to cause a denial of service (CPU consumption) via a large (1) start or (2) end angle degree value."},"relatedVulnerabilities":[{"id":"CVE-2007-3477","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-3477","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-3477","date":"2026-10-08","epss":0.04857,"percentile":0.91808}],"urls":["ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/gd-2.0.35-i486-1_slack11.0.tgz","http://bugs.libgd.org/?do=details&task_id=74","http://bugs.libgd.org/?do=details&task_id=92","http://fedoranews.org/updates/FEDORA-2007-205.shtml","http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052848.html","http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052854.html","http://osvdb.org/42062","http://secunia.com/advisories/25860","http://secunia.com/advisories/26272","http://secunia.com/advisories/26390","http://secunia.com/advisories/26415","http://secunia.com/advisories/26467","http://secunia.com/advisories/26663","http://secunia.com/advisories/26766","http://secunia.com/advisories/26856","http://secunia.com/advisories/30168","http://secunia.com/advisories/31168","http://secunia.com/advisories/42813","http://security.gentoo.org/glsa/glsa-200708-05.xml","http://security.gentoo.org/glsa/glsa-200711-34.xml","http://security.gentoo.org/glsa/glsa-200805-13.xml","http://www.debian.org/security/2008/dsa-1613","http://www.libgd.org/ReleaseNote020035","http://www.mandriva.com/security/advisories?name=MDKSA-2007:153","http://www.mandriva.com/security/advisories?name=MDKSA-2007:164","http://www.novell.com/linux/security/advisories/2007_15_sr.html","http://www.redhat.com/archives/fedora-package-announce/2007-September/msg00311.html","http://www.securityfocus.com/archive/1/478796/100/0/threaded","http://www.securityfocus.com/bid/24651","http://www.trustix.org/errata/2007/0024/","http://www.vupen.com/english/advisories/2011/0022","https://bugzilla.redhat.com/show_bug.cgi?id=277421","https://issues.rpath.com/browse/RPL-1643"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-3477","description":"The (a) imagearc and (b) imagefilledarc functions in GD Graphics Library (libgd) before 2.0.35 allow attackers to cause a denial of service (CPU consumption) via a large (1) start or (2) end angle degree value."}]},{"artifact":{"id":"692b9197d4b21a92","cpes":["cpe:2.3:a:libldap-2.5-0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5-0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5_0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5_0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"],"name":"libldap-2.5-0","purl":"pkg:deb/debian/libldap-2.5-0@2.5.13%2Bdfsg-5?arch=amd64&distro=debian-12.15&upstream=openldap","type":"deb","version":"2.5.13+dfsg-5","language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.5-0/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/libldap-2.5-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.5-0:amd64.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/libldap-2.5-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-2953","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openldap","version":"2.5.13+dfsg-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-2953","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-2953","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-2953","cwe":"CWE-476","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2023-2953","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-2953","date":"2026-10-08","epss":0.0193,"percentile":0.7939}],"risk":1.4475000000000002,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-2953","description":"A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function."},"relatedVulnerabilities":[{"id":"CVE-2023-2953","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-2953","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-2953","cwe":"CWE-476","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2023-2953","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-2953","date":"2026-10-08","epss":0.0193,"percentile":0.7939}],"urls":["http://seclists.org/fulldisclosure/2023/Jul/47","http://seclists.org/fulldisclosure/2023/Jul/48","http://seclists.org/fulldisclosure/2023/Jul/52","https://access.redhat.com/security/cve/CVE-2023-2953","https://bugs.openldap.org/show_bug.cgi?id=9904","https://security.netapp.com/advisory/ntap-20230703-0005/","https://support.apple.com/kb/HT213843","https://support.apple.com/kb/HT213844","https://support.apple.com/kb/HT213845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-2953","description":"A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function."}]},{"artifact":{"id":"35095459163cc193","cpes":["cpe:2.3:a:libtiff-dev:libtiff-dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libtiff-dev:libtiff_dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libtiff_dev:libtiff-dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libtiff_dev:libtiff_dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libtiff:libtiff-dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libtiff:libtiff_dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"name":"libtiff-dev","purl":"pkg:deb/debian/libtiff-dev@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","type":"deb","version":"4.5.0-6+deb12u4","language":"","licenses":["Hylafax"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libtiff-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libtiff-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"tiff"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-52355","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-52355","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-52355","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-52355","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-52355","date":"2026-10-08","epss":0.01829,"percentile":0.78201}],"risk":1.37175,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-52355","description":"An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB."},"relatedVulnerabilities":[{"id":"CVE-2023-52355","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-52355","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-52355","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-52355","date":"2026-10-08","epss":0.01829,"percentile":0.78201}],"urls":["https://access.redhat.com/errata/RHSA-2025:20801","https://access.redhat.com/errata/RHSA-2025:21994","https://access.redhat.com/errata/RHSA-2025:23078","https://access.redhat.com/errata/RHSA-2025:23079","https://access.redhat.com/errata/RHSA-2025:23080","https://access.redhat.com/errata/RHSA-2026:3461","https://access.redhat.com/errata/RHSA-2026:3462","https://access.redhat.com/errata/RHSA-2026:41892","https://access.redhat.com/errata/RHSA-2026:43537","https://access.redhat.com/errata/RHSA-2026:49671","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2023-52355","https://bugzilla.redhat.com/show_bug.cgi?id=2251326","https://gitlab.com/libtiff/libtiff/-/issues/621"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-52355","description":"An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB."}]},{"artifact":{"id":"d41dc3f05b6fab73","cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"name":"libtiff6","purl":"pkg:deb/debian/libtiff6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","type":"deb","version":"4.5.0-6+deb12u4","language":"","licenses":["Hylafax"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"tiff"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-52355","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-52355","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-52355","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-52355","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-52355","date":"2026-10-08","epss":0.01829,"percentile":0.78201}],"risk":1.37175,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-52355","description":"An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB."},"relatedVulnerabilities":[{"id":"CVE-2023-52355","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-52355","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-52355","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-52355","date":"2026-10-08","epss":0.01829,"percentile":0.78201}],"urls":["https://access.redhat.com/errata/RHSA-2025:20801","https://access.redhat.com/errata/RHSA-2025:21994","https://access.redhat.com/errata/RHSA-2025:23078","https://access.redhat.com/errata/RHSA-2025:23079","https://access.redhat.com/errata/RHSA-2025:23080","https://access.redhat.com/errata/RHSA-2026:3461","https://access.redhat.com/errata/RHSA-2026:3462","https://access.redhat.com/errata/RHSA-2026:41892","https://access.redhat.com/errata/RHSA-2026:43537","https://access.redhat.com/errata/RHSA-2026:49671","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2023-52355","https://bugzilla.redhat.com/show_bug.cgi?id=2251326","https://gitlab.com/libtiff/libtiff/-/issues/621"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-52355","description":"An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB."}]},{"artifact":{"id":"05a611224dadb719","cpes":["cpe:2.3:a:libtiffxx6:libtiffxx6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"name":"libtiffxx6","purl":"pkg:deb/debian/libtiffxx6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","type":"deb","version":"4.5.0-6+deb12u4","language":"","licenses":["Hylafax"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiffxx6/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libtiffxx6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiffxx6:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libtiffxx6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"tiff"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-52355","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-52355","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-52355","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-52355","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-52355","date":"2026-10-08","epss":0.01829,"percentile":0.78201}],"risk":1.37175,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-52355","description":"An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB."},"relatedVulnerabilities":[{"id":"CVE-2023-52355","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-52355","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-52355","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-52355","date":"2026-10-08","epss":0.01829,"percentile":0.78201}],"urls":["https://access.redhat.com/errata/RHSA-2025:20801","https://access.redhat.com/errata/RHSA-2025:21994","https://access.redhat.com/errata/RHSA-2025:23078","https://access.redhat.com/errata/RHSA-2025:23079","https://access.redhat.com/errata/RHSA-2025:23080","https://access.redhat.com/errata/RHSA-2026:3461","https://access.redhat.com/errata/RHSA-2026:3462","https://access.redhat.com/errata/RHSA-2026:41892","https://access.redhat.com/errata/RHSA-2026:43537","https://access.redhat.com/errata/RHSA-2026:49671","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2023-52355","https://bugzilla.redhat.com/show_bug.cgi?id=2251326","https://gitlab.com/libtiff/libtiff/-/issues/621"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-52355","description":"An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB."}]},{"artifact":{"id":"e593bea3ea25c1a5","cpes":["cpe:2.3:a:libharfbuzz0b:libharfbuzz0b:6.0.0\\+dfsg-3:*:*:*:*:*:*:*"],"name":"libharfbuzz0b","purl":"pkg:deb/debian/libharfbuzz0b@6.0.0%2Bdfsg-3?arch=amd64&distro=debian-12.15&upstream=harfbuzz","type":"deb","version":"6.0.0+dfsg-3","language":"","licenses":["Apache-2.0","CC0-1.0","Expat","FSFAP","FSFUL","FSFULLR","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","LGPL-2.1+","MIT","Monotype","OFL-1.1","UFL-1.0","Unicode"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libharfbuzz0b/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libharfbuzz0b/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libharfbuzz0b:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libharfbuzz0b:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"harfbuzz"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-25193","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"harfbuzz","version":"6.0.0+dfsg-3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-25193","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-25193","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-25193","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-25193","date":"2026-10-08","epss":0.01812,"percentile":0.77984}],"risk":1.3590000000000002,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-25193","description":"hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks."},"relatedVulnerabilities":[{"id":"CVE-2023-25193","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-25193","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-25193","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-25193","date":"2026-10-08","epss":0.01812,"percentile":0.77984}],"urls":["https://chromium.googlesource.com/chromium/src/+/e1f324aa681af54101c1f2d173d92adb80e37088/DEPS#361","https://github.com/harfbuzz/harfbuzz/blob/2822b589bc837fae6f66233e2cf2eef0f6ce8470/src/hb-ot-layout-gsubgpos.hh","https://github.com/harfbuzz/harfbuzz/commit/85be877925ddbf34f74a1229f3ca1716bb6170dc","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KWCHWSICWVZSAXP2YAXM65JC2GR53547/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZ5M2GSAIHFPLHYJXUPQ2QDJCLWXUGO3/","https://security.netapp.com/advisory/ntap-20230725-0006/","https://openjdk.org/groups/vulnerability/advisories/2023-07-18","https://www.oracle.com/security-alerts/cpujul2023.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-25193","description":"hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks."}]},{"artifact":{"id":"57bc3e079dc33e92","cpes":["cpe:2.3:a:libbluetooth-dev:libbluetooth-dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth-dev:libbluetooth_dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth_dev:libbluetooth-dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth_dev:libbluetooth_dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth:libbluetooth-dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth:libbluetooth_dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*"],"name":"libbluetooth-dev","purl":"pkg:deb/debian/libbluetooth-dev@5.66-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=bluez","type":"deb","version":"5.66-1+deb12u2","language":"","licenses":["Apache-2.0","BSD-2-clause","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libbluetooth-dev/copyright","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/usr/share/doc/libbluetooth-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbluetooth-dev:amd64.md5sums","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/info/libbluetooth-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bluez"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-44431","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"bluez","version":"5.66-1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-44431","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8,"impactScore":5.9,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-44431","cwe":"CWE-121","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2023-44431","date":"2026-10-08","epss":0.01563,"percentile":0.74524}],"risk":1.211325,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-44431","description":"BlueZ Audio Profile AVRCP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device.  The specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-19909."},"relatedVulnerabilities":[{"id":"CVE-2023-44431","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8,"impactScore":5.9,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"zdi-disclosures@trendmicro.com","vector":"CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.9,"exploitabilityScore":1.2},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-44431","cwe":"CWE-121","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2023-44431","date":"2026-10-08","epss":0.01563,"percentile":0.74524}],"urls":["https://www.zerodayinitiative.com/advisories/ZDI-23-1900/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-44431","description":"BlueZ Audio Profile AVRCP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device.\n\nThe specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-19909."}]},{"artifact":{"id":"818aff19ee069170","cpes":["cpe:2.3:a:libbluetooth3:libbluetooth3:5.66-1\\+deb12u2:*:*:*:*:*:*:*"],"name":"libbluetooth3","purl":"pkg:deb/debian/libbluetooth3@5.66-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=bluez","type":"deb","version":"5.66-1+deb12u2","language":"","licenses":["Apache-2.0","BSD-2-clause","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libbluetooth3/copyright","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/usr/share/doc/libbluetooth3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbluetooth3:amd64.md5sums","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/info/libbluetooth3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bluez"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-44431","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"bluez","version":"5.66-1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-44431","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8,"impactScore":5.9,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-44431","cwe":"CWE-121","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2023-44431","date":"2026-10-08","epss":0.01563,"percentile":0.74524}],"risk":1.211325,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-44431","description":"BlueZ Audio Profile AVRCP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device.  The specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-19909."},"relatedVulnerabilities":[{"id":"CVE-2023-44431","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8,"impactScore":5.9,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"zdi-disclosures@trendmicro.com","vector":"CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.9,"exploitabilityScore":1.2},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-44431","cwe":"CWE-121","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2023-44431","date":"2026-10-08","epss":0.01563,"percentile":0.74524}],"urls":["https://www.zerodayinitiative.com/advisories/ZDI-23-1900/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-44431","description":"BlueZ Audio Profile AVRCP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device.\n\nThe specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-19909."}]},{"artifact":{"id":"ac9f96c95674631f","cpes":["cpe:2.3:a:libopenexr-3-1-30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1-30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-3-1-30","purl":"pkg:deb/debian/libopenexr-3-1-30@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-3-1-30/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-3-1-30/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-5841","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-5841","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-5841","cwe":"CWE-122","type":"Secondary","source":"cve@takeonme.org"},{"cve":"CVE-2023-5841","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-5841","date":"2026-10-08","epss":0.01248,"percentile":0.68453}],"risk":1.12944,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-5841","description":"Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library."},"relatedVulnerabilities":[{"id":"CVE-2023-5841","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-5841","cwe":"CWE-122","type":"Secondary","source":"cve@takeonme.org"},{"cve":"CVE-2023-5841","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-5841","date":"2026-10-08","epss":0.01248,"percentile":0.68453}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LSB6DB5LAKGPLRXEF5HDNGUMT7GIFT2C/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XWMINVKQLSUHECXBSQMZFCSDRIHFOJJI/","https://takeonme.org/cves/CVE-2023-5841.html","http://seclists.org/fulldisclosure/2024/Sep/32","http://seclists.org/fulldisclosure/2024/Sep/34","http://seclists.org/fulldisclosure/2024/Sep/36"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-5841","description":"Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library."}]},{"artifact":{"id":"229cdd73859abf63","cpes":["cpe:2.3:a:libopenexr-dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-dev","purl":"pkg:deb/debian/libopenexr-dev@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.list"}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-5841","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-5841","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-5841","cwe":"CWE-122","type":"Secondary","source":"cve@takeonme.org"},{"cve":"CVE-2023-5841","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-5841","date":"2026-10-08","epss":0.01248,"percentile":0.68453}],"risk":1.12944,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-5841","description":"Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library."},"relatedVulnerabilities":[{"id":"CVE-2023-5841","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-5841","cwe":"CWE-122","type":"Secondary","source":"cve@takeonme.org"},{"cve":"CVE-2023-5841","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-5841","date":"2026-10-08","epss":0.01248,"percentile":0.68453}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LSB6DB5LAKGPLRXEF5HDNGUMT7GIFT2C/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XWMINVKQLSUHECXBSQMZFCSDRIHFOJJI/","https://takeonme.org/cves/CVE-2023-5841.html","http://seclists.org/fulldisclosure/2024/Sep/32","http://seclists.org/fulldisclosure/2024/Sep/34","http://seclists.org/fulldisclosure/2024/Sep/36"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-5841","description":"Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library."}]},{"artifact":{"id":"6f138bead18d0d6b","cpes":["cpe:2.3:a:libaom3:libaom3:3.6.0-1\\+deb12u3:*:*:*:*:*:*:*"],"name":"libaom3","purl":"pkg:deb/debian/libaom3@3.6.0-1%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=aom","type":"deb","version":"3.6.0-1+deb12u3","language":"","licenses":["BSD-2-Clause","BSD-2-clause","BSD-3-clause","Expat","ISC","public-domain-md5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libaom3/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libaom3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libaom3:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libaom3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"aom"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-6879","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"aom","version":"3.6.0-1+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-6879","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6879","cwe":"CWE-20","type":"Secondary","source":"cve-coordination@google.com"},{"cve":"CVE-2023-6879","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-6879","date":"2026-10-08","epss":0.01175,"percentile":0.66618}],"risk":1.1045,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-6879","description":"Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc()."},"relatedVulnerabilities":[{"id":"CVE-2023-6879","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9,"impactScore":6.1,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6879","cwe":"CWE-20","type":"Secondary","source":"cve-coordination@google.com"},{"cve":"CVE-2023-6879","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-6879","date":"2026-10-08","epss":0.01175,"percentile":0.66618}],"urls":["https://aomedia.googlesource.com/aom/+/refs/tags/v3.7.1","https://crbug.com/aomedia/3491","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AYONA2XSNFMXLAW4IHLFI5UVV3QRNG5K/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D6C2HN4T2S6GYNTAUXLH45LQZHK7QPHP/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6879","description":"Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc()."}]},{"artifact":{"id":"57bc3e079dc33e92","cpes":["cpe:2.3:a:libbluetooth-dev:libbluetooth-dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth-dev:libbluetooth_dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth_dev:libbluetooth-dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth_dev:libbluetooth_dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth:libbluetooth-dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth:libbluetooth_dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*"],"name":"libbluetooth-dev","purl":"pkg:deb/debian/libbluetooth-dev@5.66-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=bluez","type":"deb","version":"5.66-1+deb12u2","language":"","licenses":["Apache-2.0","BSD-2-clause","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libbluetooth-dev/copyright","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/usr/share/doc/libbluetooth-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbluetooth-dev:amd64.md5sums","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/info/libbluetooth-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bluez"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-51596","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"bluez","version":"5.66-1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-51596","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"zdi-disclosures@trendmicro.com","vector":"CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.9,"exploitabilityScore":1.2},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-51596","cwe":"CWE-122","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2023-51596","date":"2026-10-08","epss":0.01506,"percentile":0.73595}],"risk":1.09938,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-51596","description":"BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious Bluetooth device.  The specific flaw exists within the handling of the Phone Book Access profile. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20939."},"relatedVulnerabilities":[{"id":"CVE-2023-51596","cvss":[{"type":"Secondary","source":"zdi-disclosures@trendmicro.com","vector":"CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.9,"exploitabilityScore":1.2},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-51596","cwe":"CWE-122","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2023-51596","date":"2026-10-08","epss":0.01506,"percentile":0.73595}],"urls":["https://www.zerodayinitiative.com/advisories/ZDI-23-1902/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-51596","description":"BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious Bluetooth device.\n\nThe specific flaw exists within the handling of the Phone Book Access profile. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20939."}]},{"artifact":{"id":"818aff19ee069170","cpes":["cpe:2.3:a:libbluetooth3:libbluetooth3:5.66-1\\+deb12u2:*:*:*:*:*:*:*"],"name":"libbluetooth3","purl":"pkg:deb/debian/libbluetooth3@5.66-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=bluez","type":"deb","version":"5.66-1+deb12u2","language":"","licenses":["Apache-2.0","BSD-2-clause","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libbluetooth3/copyright","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/usr/share/doc/libbluetooth3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbluetooth3:amd64.md5sums","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/info/libbluetooth3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bluez"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-51596","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"bluez","version":"5.66-1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-51596","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"zdi-disclosures@trendmicro.com","vector":"CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.9,"exploitabilityScore":1.2},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-51596","cwe":"CWE-122","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2023-51596","date":"2026-10-08","epss":0.01506,"percentile":0.73595}],"risk":1.09938,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-51596","description":"BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious Bluetooth device.  The specific flaw exists within the handling of the Phone Book Access profile. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20939."},"relatedVulnerabilities":[{"id":"CVE-2023-51596","cvss":[{"type":"Secondary","source":"zdi-disclosures@trendmicro.com","vector":"CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.9,"exploitabilityScore":1.2},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-51596","cwe":"CWE-122","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2023-51596","date":"2026-10-08","epss":0.01506,"percentile":0.73595}],"urls":["https://www.zerodayinitiative.com/advisories/ZDI-23-1902/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-51596","description":"BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious Bluetooth device.\n\nThe specific flaw exists within the handling of the Phone Book Access profile. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20939."}]},{"artifact":{"id":"d82af4e74abd89bc","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","type":"deb","version":"1:9.2p1-2+deb12u10","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-6110","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-6110","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-6110","cwe":"CWE-838","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-6110","cwe":"CWE-838","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-6110","date":"2026-10-08","epss":0.20906,"percentile":0.97507}],"risk":1.0453000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-6110","description":"In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred."},"relatedVulnerabilities":[{"id":"CVE-2019-6110","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":5.2,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:N","metrics":{"baseScore":4,"impactScore":5,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":5.2,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-6110","cwe":"CWE-838","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-6110","cwe":"CWE-838","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-6110","date":"2026-10-08","epss":0.20906,"percentile":0.97507}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf","https://cvsweb.openbsd.org/src/usr.bin/ssh/progressmeter.c","https://cvsweb.openbsd.org/src/usr.bin/ssh/scp.c","https://security.gentoo.org/glsa/201903-16","https://security.netapp.com/advisory/ntap-20190213-0001/","https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt","https://www.exploit-db.com/exploits/46193/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-6110","description":"In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred."}]},{"artifact":{"id":"35095459163cc193","cpes":["cpe:2.3:a:libtiff-dev:libtiff-dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libtiff-dev:libtiff_dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libtiff_dev:libtiff-dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libtiff_dev:libtiff_dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libtiff:libtiff-dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libtiff:libtiff_dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"name":"libtiff-dev","purl":"pkg:deb/debian/libtiff-dev@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","type":"deb","version":"4.5.0-6+deb12u4","language":"","licenses":["Hylafax"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libtiff-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libtiff-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"tiff"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-6277","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-6277","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6277","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-6277","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-6277","date":"2026-10-08","epss":0.0181,"percentile":0.77958}],"risk":1.04075,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-6277","description":"An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB."},"relatedVulnerabilities":[{"id":"CVE-2023-6277","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6277","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-6277","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-6277","date":"2026-10-08","epss":0.0181,"percentile":0.77958}],"urls":["https://access.redhat.com/security/cve/CVE-2023-6277","https://bugzilla.redhat.com/show_bug.cgi?id=2251311","https://gitlab.com/libtiff/libtiff/-/issues/614","https://gitlab.com/libtiff/libtiff/-/merge_requests/545","http://seclists.org/fulldisclosure/2024/Jul/16","http://seclists.org/fulldisclosure/2024/Jul/17","http://seclists.org/fulldisclosure/2024/Jul/18","http://seclists.org/fulldisclosure/2024/Jul/19","http://seclists.org/fulldisclosure/2024/Jul/20","http://seclists.org/fulldisclosure/2024/Jul/21","http://seclists.org/fulldisclosure/2024/Jul/22","http://seclists.org/fulldisclosure/2024/Jul/23","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WJIN6DTSL3VODZUGWEUXLEL5DR53EZMV/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y7ZGN2MZXJ6E57W3L4YBM3ZPAU3T7T5C/","https://security.netapp.com/advisory/ntap-20240119-0002/","https://support.apple.com/kb/HT214116","https://support.apple.com/kb/HT214117","https://support.apple.com/kb/HT214118","https://support.apple.com/kb/HT214119","https://support.apple.com/kb/HT214120","https://support.apple.com/kb/HT214122","https://support.apple.com/kb/HT214123","https://support.apple.com/kb/HT214124"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6277","description":"An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB."}]},{"artifact":{"id":"d41dc3f05b6fab73","cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"name":"libtiff6","purl":"pkg:deb/debian/libtiff6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","type":"deb","version":"4.5.0-6+deb12u4","language":"","licenses":["Hylafax"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"tiff"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-6277","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-6277","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6277","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-6277","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-6277","date":"2026-10-08","epss":0.0181,"percentile":0.77958}],"risk":1.04075,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-6277","description":"An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB."},"relatedVulnerabilities":[{"id":"CVE-2023-6277","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6277","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-6277","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-6277","date":"2026-10-08","epss":0.0181,"percentile":0.77958}],"urls":["https://access.redhat.com/security/cve/CVE-2023-6277","https://bugzilla.redhat.com/show_bug.cgi?id=2251311","https://gitlab.com/libtiff/libtiff/-/issues/614","https://gitlab.com/libtiff/libtiff/-/merge_requests/545","http://seclists.org/fulldisclosure/2024/Jul/16","http://seclists.org/fulldisclosure/2024/Jul/17","http://seclists.org/fulldisclosure/2024/Jul/18","http://seclists.org/fulldisclosure/2024/Jul/19","http://seclists.org/fulldisclosure/2024/Jul/20","http://seclists.org/fulldisclosure/2024/Jul/21","http://seclists.org/fulldisclosure/2024/Jul/22","http://seclists.org/fulldisclosure/2024/Jul/23","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WJIN6DTSL3VODZUGWEUXLEL5DR53EZMV/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y7ZGN2MZXJ6E57W3L4YBM3ZPAU3T7T5C/","https://security.netapp.com/advisory/ntap-20240119-0002/","https://support.apple.com/kb/HT214116","https://support.apple.com/kb/HT214117","https://support.apple.com/kb/HT214118","https://support.apple.com/kb/HT214119","https://support.apple.com/kb/HT214120","https://support.apple.com/kb/HT214122","https://support.apple.com/kb/HT214123","https://support.apple.com/kb/HT214124"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6277","description":"An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB."}]},{"artifact":{"id":"05a611224dadb719","cpes":["cpe:2.3:a:libtiffxx6:libtiffxx6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"name":"libtiffxx6","purl":"pkg:deb/debian/libtiffxx6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","type":"deb","version":"4.5.0-6+deb12u4","language":"","licenses":["Hylafax"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiffxx6/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libtiffxx6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiffxx6:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libtiffxx6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"tiff"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-6277","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-6277","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6277","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-6277","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-6277","date":"2026-10-08","epss":0.0181,"percentile":0.77958}],"risk":1.04075,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-6277","description":"An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB."},"relatedVulnerabilities":[{"id":"CVE-2023-6277","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6277","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-6277","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-6277","date":"2026-10-08","epss":0.0181,"percentile":0.77958}],"urls":["https://access.redhat.com/security/cve/CVE-2023-6277","https://bugzilla.redhat.com/show_bug.cgi?id=2251311","https://gitlab.com/libtiff/libtiff/-/issues/614","https://gitlab.com/libtiff/libtiff/-/merge_requests/545","http://seclists.org/fulldisclosure/2024/Jul/16","http://seclists.org/fulldisclosure/2024/Jul/17","http://seclists.org/fulldisclosure/2024/Jul/18","http://seclists.org/fulldisclosure/2024/Jul/19","http://seclists.org/fulldisclosure/2024/Jul/20","http://seclists.org/fulldisclosure/2024/Jul/21","http://seclists.org/fulldisclosure/2024/Jul/22","http://seclists.org/fulldisclosure/2024/Jul/23","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WJIN6DTSL3VODZUGWEUXLEL5DR53EZMV/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y7ZGN2MZXJ6E57W3L4YBM3ZPAU3T7T5C/","https://security.netapp.com/advisory/ntap-20240119-0002/","https://support.apple.com/kb/HT214116","https://support.apple.com/kb/HT214117","https://support.apple.com/kb/HT214118","https://support.apple.com/kb/HT214119","https://support.apple.com/kb/HT214120","https://support.apple.com/kb/HT214122","https://support.apple.com/kb/HT214123","https://support.apple.com/kb/HT214124"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6277","description":"An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"risk":1.01325,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"risk":1.01325,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"risk":1.01325,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"risk":1.01325,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"f7e49c1a6279cc8f","cpes":["cpe:2.3:a:libglib2.0-0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-0","purl":"pkg:deb/debian/libglib2.0-0@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-0/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58016","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58016","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58016","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58016","date":"2026-10-08","epss":0.00993,"percentile":0.61445}],"risk":0.898665,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58016","description":"A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-58016","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58016","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58016","date":"2026-10-08","epss":0.00993,"percentile":0.61445}],"urls":["https://access.redhat.com/errata/RHSA-2026:42063","https://access.redhat.com/errata/RHSA-2026:42089","https://access.redhat.com/errata/RHSA-2026:42090","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:51175","https://access.redhat.com/errata/RHSA-2026:51176","https://access.redhat.com/errata/RHSA-2026:51177","https://access.redhat.com/errata/RHSA-2026:51181","https://access.redhat.com/errata/RHSA-2026:51182","https://access.redhat.com/errata/RHSA-2026:51183","https://access.redhat.com/errata/RHSA-2026:51184","https://access.redhat.com/errata/RHSA-2026:51185","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-58016","https://bugzilla.redhat.com/show_bug.cgi?id=2492257","https://gitlab.gnome.org/GNOME/glib/-/issues/3932"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58016","description":"A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service."}]},{"artifact":{"id":"757dc53367620c75","cpes":["cpe:2.3:a:libglib2.0-bin:libglib2.0-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-bin:libglib2.0_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_bin:libglib2.0-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_bin:libglib2.0_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-bin","purl":"pkg:deb/debian/libglib2.0-bin@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-bin/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-bin.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-bin.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-bin.list"}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58016","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58016","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58016","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58016","date":"2026-10-08","epss":0.00993,"percentile":0.61445}],"risk":0.898665,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58016","description":"A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-58016","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58016","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58016","date":"2026-10-08","epss":0.00993,"percentile":0.61445}],"urls":["https://access.redhat.com/errata/RHSA-2026:42063","https://access.redhat.com/errata/RHSA-2026:42089","https://access.redhat.com/errata/RHSA-2026:42090","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:51175","https://access.redhat.com/errata/RHSA-2026:51176","https://access.redhat.com/errata/RHSA-2026:51177","https://access.redhat.com/errata/RHSA-2026:51181","https://access.redhat.com/errata/RHSA-2026:51182","https://access.redhat.com/errata/RHSA-2026:51183","https://access.redhat.com/errata/RHSA-2026:51184","https://access.redhat.com/errata/RHSA-2026:51185","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-58016","https://bugzilla.redhat.com/show_bug.cgi?id=2492257","https://gitlab.gnome.org/GNOME/glib/-/issues/3932"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58016","description":"A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service."}]},{"artifact":{"id":"f3f80a402f7cbc1b","cpes":["cpe:2.3:a:libglib2.0-data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-data","purl":"pkg:deb/debian/libglib2.0-data@2.74.6-2%2Bdeb12u9?arch=all&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-data/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-data.list"}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58016","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58016","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58016","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58016","date":"2026-10-08","epss":0.00993,"percentile":0.61445}],"risk":0.898665,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58016","description":"A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-58016","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58016","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58016","date":"2026-10-08","epss":0.00993,"percentile":0.61445}],"urls":["https://access.redhat.com/errata/RHSA-2026:42063","https://access.redhat.com/errata/RHSA-2026:42089","https://access.redhat.com/errata/RHSA-2026:42090","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:51175","https://access.redhat.com/errata/RHSA-2026:51176","https://access.redhat.com/errata/RHSA-2026:51177","https://access.redhat.com/errata/RHSA-2026:51181","https://access.redhat.com/errata/RHSA-2026:51182","https://access.redhat.com/errata/RHSA-2026:51183","https://access.redhat.com/errata/RHSA-2026:51184","https://access.redhat.com/errata/RHSA-2026:51185","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-58016","https://bugzilla.redhat.com/show_bug.cgi?id=2492257","https://gitlab.gnome.org/GNOME/glib/-/issues/3932"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58016","description":"A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service."}]},{"artifact":{"id":"17127afcd14d4e5d","cpes":["cpe:2.3:a:libglib2.0-dev:libglib2.0-dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev:libglib2.0_dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0-dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0_dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-dev","purl":"pkg:deb/debian/libglib2.0-dev@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58016","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58016","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58016","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58016","date":"2026-10-08","epss":0.00993,"percentile":0.61445}],"risk":0.898665,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58016","description":"A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-58016","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58016","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58016","date":"2026-10-08","epss":0.00993,"percentile":0.61445}],"urls":["https://access.redhat.com/errata/RHSA-2026:42063","https://access.redhat.com/errata/RHSA-2026:42089","https://access.redhat.com/errata/RHSA-2026:42090","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:51175","https://access.redhat.com/errata/RHSA-2026:51176","https://access.redhat.com/errata/RHSA-2026:51177","https://access.redhat.com/errata/RHSA-2026:51181","https://access.redhat.com/errata/RHSA-2026:51182","https://access.redhat.com/errata/RHSA-2026:51183","https://access.redhat.com/errata/RHSA-2026:51184","https://access.redhat.com/errata/RHSA-2026:51185","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-58016","https://bugzilla.redhat.com/show_bug.cgi?id=2492257","https://gitlab.gnome.org/GNOME/glib/-/issues/3932"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58016","description":"A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service."}]},{"artifact":{"id":"b56f6def3e8bd4f6","cpes":["cpe:2.3:a:libglib2.0-dev-bin:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev-bin:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev_bin:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev_bin:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-dev-bin","purl":"pkg:deb/debian/libglib2.0-dev-bin@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-dev-bin/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.list"},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.postinst"},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.prerm"}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58016","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58016","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58016","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58016","date":"2026-10-08","epss":0.00993,"percentile":0.61445}],"risk":0.898665,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58016","description":"A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-58016","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58016","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58016","date":"2026-10-08","epss":0.00993,"percentile":0.61445}],"urls":["https://access.redhat.com/errata/RHSA-2026:42063","https://access.redhat.com/errata/RHSA-2026:42089","https://access.redhat.com/errata/RHSA-2026:42090","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:51175","https://access.redhat.com/errata/RHSA-2026:51176","https://access.redhat.com/errata/RHSA-2026:51177","https://access.redhat.com/errata/RHSA-2026:51181","https://access.redhat.com/errata/RHSA-2026:51182","https://access.redhat.com/errata/RHSA-2026:51183","https://access.redhat.com/errata/RHSA-2026:51184","https://access.redhat.com/errata/RHSA-2026:51185","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-58016","https://bugzilla.redhat.com/show_bug.cgi?id=2492257","https://gitlab.gnome.org/GNOME/glib/-/issues/3932"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58016","description":"A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service."}]},{"artifact":{"id":"9e40126b989ece04","cpes":["cpe:2.3:a:libtasn1-6:libtasn1-6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1-6:libtasn1_6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1_6:libtasn1-6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1_6:libtasn1_6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1:libtasn1-6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1:libtasn1_6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*"],"name":"libtasn1-6","purl":"pkg:deb/debian/libtasn1-6@4.19.0-2%2Bdeb12u1?arch=amd64&distro=debian-12.15","type":"deb","version":"4.19.0-2+deb12u1","language":"","licenses":["sha256:572ad60ad184d8f52c6dc66d83a61a68f137db560b3452ce00588c9ecf128a65"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtasn1-6/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libtasn1-6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtasn1-6:amd64.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libtasn1-6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-13151","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libtasn1-6","version":"4.19.0-2+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-13151","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-13151","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-13151","date":"2026-10-08","epss":0.01175,"percentile":0.66615}],"risk":0.8812500000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-13151","description":"Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string."},"relatedVulnerabilities":[{"id":"CVE-2025-13151","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-13151","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-13151","date":"2026-10-08","epss":0.01175,"percentile":0.66615}],"urls":["https://gitlab.com/gnutls/libtasn1","https://gitlab.com/gnutls/libtasn1/-/merge_requests/121","http://www.openwall.com/lists/oss-security/2026/01/08/5","https://www.kb.cert.org/vuls/id/271649"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-13151","description":"Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string."}]},{"artifact":{"id":"ebdf865d13d21735","cpes":["cpe:2.3:a:libwmf-0.2-7:libwmf-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf-0.2-7:libwmf_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf_0.2_7:libwmf-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf_0.2_7:libwmf_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf-0.2:libwmf-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf-0.2:libwmf_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf_0.2:libwmf-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf_0.2:libwmf_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf:libwmf-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf:libwmf_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*"],"name":"libwmf-0.2-7","purl":"pkg:deb/debian/libwmf-0.2-7@0.2.12-5.1?arch=amd64&distro=debian-12.15&upstream=libwmf","type":"deb","version":"0.2.12-5.1","language":"","licenses":["AGPL-3","GD","ISC","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libwmf-0.2-7/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libwmf-0.2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libwmf-0.2-7:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libwmf-0.2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libwmf"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-3476","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libwmf","version":"0.2.12-5.1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2007-3476","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-3476","cwe":"CWE-189","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-3476","date":"2026-10-08","epss":0.02455,"percentile":0.83925}],"risk":0.7364999999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-3476","description":"Array index error in gd_gif_in.c in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash and heap corruption) via large color index values in crafted image data, which results in a segmentation fault."},"relatedVulnerabilities":[{"id":"CVE-2007-3476","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-3476","cwe":"CWE-189","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-3476","date":"2026-10-08","epss":0.02455,"percentile":0.83925}],"urls":["ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/gd-2.0.35-i486-1_slack11.0.tgz","http://bugs.libgd.org/?do=details&task_id=87","http://fedoranews.org/updates/FEDORA-2007-205.shtml","http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052848.html","http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052854.html","http://osvdb.org/37741","http://secunia.com/advisories/25860","http://secunia.com/advisories/26272","http://secunia.com/advisories/26390","http://secunia.com/advisories/26415","http://secunia.com/advisories/26467","http://secunia.com/advisories/26663","http://secunia.com/advisories/26766","http://secunia.com/advisories/26856","http://secunia.com/advisories/29157","http://secunia.com/advisories/30168","http://secunia.com/advisories/31168","http://secunia.com/advisories/42813","http://security.gentoo.org/glsa/glsa-200708-05.xml","http://security.gentoo.org/glsa/glsa-200711-34.xml","http://security.gentoo.org/glsa/glsa-200805-13.xml","http://www.debian.org/security/2008/dsa-1613","http://www.libgd.org/ReleaseNote020035","http://www.mandriva.com/security/advisories?name=MDKSA-2007:153","http://www.mandriva.com/security/advisories?name=MDKSA-2007:164","http://www.novell.com/linux/security/advisories/2007_15_sr.html","http://www.redhat.com/archives/fedora-package-announce/2007-September/msg00311.html","http://www.redhat.com/support/errata/RHSA-2008-0146.html","http://www.securityfocus.com/archive/1/478796/100/0/threaded","http://www.securityfocus.com/bid/24651","http://www.trustix.org/errata/2007/0024/","http://www.vupen.com/english/advisories/2011/0022","https://bugzilla.redhat.com/show_bug.cgi?id=277421","https://issues.rpath.com/browse/RPL-1643","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10348"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-3476","description":"Array index error in gd_gif_in.c in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash and heap corruption) via large color index values in crafted image data, which results in a segmentation fault."}]},{"artifact":{"id":"fefa72b1191e1443","cpes":["cpe:2.3:a:libwmf-dev:libwmf-dev:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf-dev:libwmf_dev:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf_dev:libwmf-dev:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf_dev:libwmf_dev:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf:libwmf-dev:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmf:libwmf_dev:0.2.12-5.1:*:*:*:*:*:*:*"],"name":"libwmf-dev","purl":"pkg:deb/debian/libwmf-dev@0.2.12-5.1?arch=amd64&distro=debian-12.15&upstream=libwmf","type":"deb","version":"0.2.12-5.1","language":"","licenses":["AGPL-3","GD","ISC","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libwmf-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libwmf-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libwmf-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libwmf-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libwmf-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libwmf-dev.list"},{"path":"/var/lib/dpkg/info/libwmf-dev.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libwmf-dev.preinst"}],"upstreams":[{"name":"libwmf"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-3476","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libwmf","version":"0.2.12-5.1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2007-3476","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-3476","cwe":"CWE-189","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-3476","date":"2026-10-08","epss":0.02455,"percentile":0.83925}],"risk":0.7364999999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-3476","description":"Array index error in gd_gif_in.c in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash and heap corruption) via large color index values in crafted image data, which results in a segmentation fault."},"relatedVulnerabilities":[{"id":"CVE-2007-3476","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-3476","cwe":"CWE-189","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-3476","date":"2026-10-08","epss":0.02455,"percentile":0.83925}],"urls":["ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/gd-2.0.35-i486-1_slack11.0.tgz","http://bugs.libgd.org/?do=details&task_id=87","http://fedoranews.org/updates/FEDORA-2007-205.shtml","http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052848.html","http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052854.html","http://osvdb.org/37741","http://secunia.com/advisories/25860","http://secunia.com/advisories/26272","http://secunia.com/advisories/26390","http://secunia.com/advisories/26415","http://secunia.com/advisories/26467","http://secunia.com/advisories/26663","http://secunia.com/advisories/26766","http://secunia.com/advisories/26856","http://secunia.com/advisories/29157","http://secunia.com/advisories/30168","http://secunia.com/advisories/31168","http://secunia.com/advisories/42813","http://security.gentoo.org/glsa/glsa-200708-05.xml","http://security.gentoo.org/glsa/glsa-200711-34.xml","http://security.gentoo.org/glsa/glsa-200805-13.xml","http://www.debian.org/security/2008/dsa-1613","http://www.libgd.org/ReleaseNote020035","http://www.mandriva.com/security/advisories?name=MDKSA-2007:153","http://www.mandriva.com/security/advisories?name=MDKSA-2007:164","http://www.novell.com/linux/security/advisories/2007_15_sr.html","http://www.redhat.com/archives/fedora-package-announce/2007-September/msg00311.html","http://www.redhat.com/support/errata/RHSA-2008-0146.html","http://www.securityfocus.com/archive/1/478796/100/0/threaded","http://www.securityfocus.com/bid/24651","http://www.trustix.org/errata/2007/0024/","http://www.vupen.com/english/advisories/2011/0022","https://bugzilla.redhat.com/show_bug.cgi?id=277421","https://issues.rpath.com/browse/RPL-1643","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10348"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-3476","description":"Array index error in gd_gif_in.c in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash and heap corruption) via large color index values in crafted image data, which results in a segmentation fault."}]},{"artifact":{"id":"218765409402dcb0","cpes":["cpe:2.3:a:libwmflite-0.2-7:libwmflite-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite-0.2-7:libwmflite_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite_0.2_7:libwmflite-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite_0.2_7:libwmflite_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite-0.2:libwmflite-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite-0.2:libwmflite_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite_0.2:libwmflite-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite_0.2:libwmflite_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite:libwmflite-0.2-7:0.2.12-5.1:*:*:*:*:*:*:*","cpe:2.3:a:libwmflite:libwmflite_0.2_7:0.2.12-5.1:*:*:*:*:*:*:*"],"name":"libwmflite-0.2-7","purl":"pkg:deb/debian/libwmflite-0.2-7@0.2.12-5.1?arch=amd64&distro=debian-12.15&upstream=libwmf","type":"deb","version":"0.2.12-5.1","language":"","licenses":["AGPL-3","GD","ISC","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libwmflite-0.2-7/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libwmflite-0.2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libwmflite-0.2-7:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libwmflite-0.2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libwmf"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-3476","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libwmf","version":"0.2.12-5.1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2007-3476","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-3476","cwe":"CWE-189","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-3476","date":"2026-10-08","epss":0.02455,"percentile":0.83925}],"risk":0.7364999999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-3476","description":"Array index error in gd_gif_in.c in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash and heap corruption) via large color index values in crafted image data, which results in a segmentation fault."},"relatedVulnerabilities":[{"id":"CVE-2007-3476","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-3476","cwe":"CWE-189","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-3476","date":"2026-10-08","epss":0.02455,"percentile":0.83925}],"urls":["ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/gd-2.0.35-i486-1_slack11.0.tgz","http://bugs.libgd.org/?do=details&task_id=87","http://fedoranews.org/updates/FEDORA-2007-205.shtml","http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052848.html","http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052854.html","http://osvdb.org/37741","http://secunia.com/advisories/25860","http://secunia.com/advisories/26272","http://secunia.com/advisories/26390","http://secunia.com/advisories/26415","http://secunia.com/advisories/26467","http://secunia.com/advisories/26663","http://secunia.com/advisories/26766","http://secunia.com/advisories/26856","http://secunia.com/advisories/29157","http://secunia.com/advisories/30168","http://secunia.com/advisories/31168","http://secunia.com/advisories/42813","http://security.gentoo.org/glsa/glsa-200708-05.xml","http://security.gentoo.org/glsa/glsa-200711-34.xml","http://security.gentoo.org/glsa/glsa-200805-13.xml","http://www.debian.org/security/2008/dsa-1613","http://www.libgd.org/ReleaseNote020035","http://www.mandriva.com/security/advisories?name=MDKSA-2007:153","http://www.mandriva.com/security/advisories?name=MDKSA-2007:164","http://www.novell.com/linux/security/advisories/2007_15_sr.html","http://www.redhat.com/archives/fedora-package-announce/2007-September/msg00311.html","http://www.redhat.com/support/errata/RHSA-2008-0146.html","http://www.securityfocus.com/archive/1/478796/100/0/threaded","http://www.securityfocus.com/bid/24651","http://www.trustix.org/errata/2007/0024/","http://www.vupen.com/english/advisories/2011/0022","https://bugzilla.redhat.com/show_bug.cgi?id=277421","https://issues.rpath.com/browse/RPL-1643","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10348"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-3476","description":"Array index error in gd_gif_in.c in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash and heap corruption) via large color index values in crafted image data, which results in a segmentation fault."}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-19931","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19931","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"risk":0.70218,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection."},"relatedVulnerabilities":[{"id":"CVE-2026-19931","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"urls":["https://curl.se/docs/CVE-2026-19931.html","https://curl.se/docs/CVE-2026-19931.json","https://hackerone.com/reports/3923520"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\npreviously authenticated connection."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19931","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19931","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"risk":0.70218,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection."},"relatedVulnerabilities":[{"id":"CVE-2026-19931","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"urls":["https://curl.se/docs/CVE-2026-19931.html","https://curl.se/docs/CVE-2026-19931.json","https://hackerone.com/reports/3923520"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\npreviously authenticated connection."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19931","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19931","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"risk":0.70218,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection."},"relatedVulnerabilities":[{"id":"CVE-2026-19931","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"urls":["https://curl.se/docs/CVE-2026-19931.html","https://curl.se/docs/CVE-2026-19931.json","https://hackerone.com/reports/3923520"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\npreviously authenticated connection."}]},{"artifact":{"id":"610d5f28e0c6125d","cpes":["cpe:2.3:a:libcurl4-openssl-dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl-dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4-openssl-dev","purl":"pkg:deb/debian/libcurl4-openssl-dev@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4-openssl-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libcurl4-openssl-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19931","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19931","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"risk":0.70218,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection."},"relatedVulnerabilities":[{"id":"CVE-2026-19931","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"urls":["https://curl.se/docs/CVE-2026-19931.html","https://curl.se/docs/CVE-2026-19931.json","https://hackerone.com/reports/3923520"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\npreviously authenticated connection."}]},{"artifact":{"id":"f7e49c1a6279cc8f","cpes":["cpe:2.3:a:libglib2.0-0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-0","purl":"pkg:deb/debian/libglib2.0-0@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-0/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58015","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58015","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58015","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-58015","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-58015","date":"2026-10-08","epss":0.00908,"percentile":0.58707}],"risk":0.681,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58015","description":"A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash."},"relatedVulnerabilities":[{"id":"CVE-2026-58015","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58015","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-58015","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-58015","date":"2026-10-08","epss":0.00908,"percentile":0.58707}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:66357","https://access.redhat.com/errata/RHSA-2026:70646","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58015","https://bugzilla.redhat.com/show_bug.cgi?id=2492256","https://gitlab.gnome.org/GNOME/glib/-/issues/3931"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58015","description":"A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash."}]},{"artifact":{"id":"757dc53367620c75","cpes":["cpe:2.3:a:libglib2.0-bin:libglib2.0-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-bin:libglib2.0_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_bin:libglib2.0-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_bin:libglib2.0_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-bin","purl":"pkg:deb/debian/libglib2.0-bin@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-bin/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-bin.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-bin.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-bin.list"}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58015","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58015","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58015","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-58015","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-58015","date":"2026-10-08","epss":0.00908,"percentile":0.58707}],"risk":0.681,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58015","description":"A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash."},"relatedVulnerabilities":[{"id":"CVE-2026-58015","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58015","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-58015","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-58015","date":"2026-10-08","epss":0.00908,"percentile":0.58707}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:66357","https://access.redhat.com/errata/RHSA-2026:70646","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58015","https://bugzilla.redhat.com/show_bug.cgi?id=2492256","https://gitlab.gnome.org/GNOME/glib/-/issues/3931"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58015","description":"A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash."}]},{"artifact":{"id":"f3f80a402f7cbc1b","cpes":["cpe:2.3:a:libglib2.0-data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-data","purl":"pkg:deb/debian/libglib2.0-data@2.74.6-2%2Bdeb12u9?arch=all&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-data/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-data.list"}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58015","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58015","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58015","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-58015","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-58015","date":"2026-10-08","epss":0.00908,"percentile":0.58707}],"risk":0.681,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58015","description":"A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash."},"relatedVulnerabilities":[{"id":"CVE-2026-58015","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58015","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-58015","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-58015","date":"2026-10-08","epss":0.00908,"percentile":0.58707}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:66357","https://access.redhat.com/errata/RHSA-2026:70646","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58015","https://bugzilla.redhat.com/show_bug.cgi?id=2492256","https://gitlab.gnome.org/GNOME/glib/-/issues/3931"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58015","description":"A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash."}]},{"artifact":{"id":"17127afcd14d4e5d","cpes":["cpe:2.3:a:libglib2.0-dev:libglib2.0-dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev:libglib2.0_dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0-dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0_dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-dev","purl":"pkg:deb/debian/libglib2.0-dev@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58015","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58015","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58015","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-58015","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-58015","date":"2026-10-08","epss":0.00908,"percentile":0.58707}],"risk":0.681,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58015","description":"A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash."},"relatedVulnerabilities":[{"id":"CVE-2026-58015","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58015","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-58015","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-58015","date":"2026-10-08","epss":0.00908,"percentile":0.58707}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:66357","https://access.redhat.com/errata/RHSA-2026:70646","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58015","https://bugzilla.redhat.com/show_bug.cgi?id=2492256","https://gitlab.gnome.org/GNOME/glib/-/issues/3931"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58015","description":"A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash."}]},{"artifact":{"id":"b56f6def3e8bd4f6","cpes":["cpe:2.3:a:libglib2.0-dev-bin:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev-bin:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev_bin:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev_bin:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-dev-bin","purl":"pkg:deb/debian/libglib2.0-dev-bin@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-dev-bin/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.list"},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.postinst"},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.prerm"}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58015","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58015","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58015","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-58015","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-58015","date":"2026-10-08","epss":0.00908,"percentile":0.58707}],"risk":0.681,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58015","description":"A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash."},"relatedVulnerabilities":[{"id":"CVE-2026-58015","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58015","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-58015","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-58015","date":"2026-10-08","epss":0.00908,"percentile":0.58707}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:66357","https://access.redhat.com/errata/RHSA-2026:70646","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58015","https://bugzilla.redhat.com/show_bug.cgi?id=2492256","https://gitlab.gnome.org/GNOME/glib/-/issues/3931"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58015","description":"A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5450","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5450","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"risk":0.6749200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."},"relatedVulnerabilities":[{"id":"CVE-2026-5450","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"urls":["https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."}]},{"artifact":{"id":"05457b2d3472913c","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5450","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5450","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"risk":0.6749200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."},"relatedVulnerabilities":[{"id":"CVE-2026-5450","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"urls":["https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5450","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5450","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"risk":0.6749200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."},"relatedVulnerabilities":[{"id":"CVE-2026-5450","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"urls":["https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."}]},{"artifact":{"id":"be9fcdc16d52ab8f","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5450","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5450","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"risk":0.6749200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."},"relatedVulnerabilities":[{"id":"CVE-2026-5450","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"urls":["https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."}]},{"artifact":{"id":"f7e49c1a6279cc8f","cpes":["cpe:2.3:a:libglib2.0-0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-0","purl":"pkg:deb/debian/libglib2.0-0@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-0/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58010","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58010","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"risk":0.6696049999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58010","description":"A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-58010","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58010","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58010","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58010","https://bugzilla.redhat.com/show_bug.cgi?id=2492243","https://gitlab.gnome.org/GNOME/glib/-/issues/3915"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58010","description":"A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary."}]},{"artifact":{"id":"f7e49c1a6279cc8f","cpes":["cpe:2.3:a:libglib2.0-0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-0","purl":"pkg:deb/debian/libglib2.0-0@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-0/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58012","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58012","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58012","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58012","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"risk":0.6696049999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58012","description":"A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-58012","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58012","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58012","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58012","https://bugzilla.redhat.com/show_bug.cgi?id=2492247","https://gitlab.gnome.org/GNOME/glib/-/issues/3918"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58012","description":"A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary."}]},{"artifact":{"id":"f7e49c1a6279cc8f","cpes":["cpe:2.3:a:libglib2.0-0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-0","purl":"pkg:deb/debian/libglib2.0-0@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-0/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58013","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58013","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58013","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"risk":0.6696049999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58013","description":"A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-58013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58013","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58013","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58013","https://bugzilla.redhat.com/show_bug.cgi?id=2492248","https://gitlab.gnome.org/GNOME/glib/-/issues/3925"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58013","description":"A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary."}]},{"artifact":{"id":"757dc53367620c75","cpes":["cpe:2.3:a:libglib2.0-bin:libglib2.0-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-bin:libglib2.0_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_bin:libglib2.0-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_bin:libglib2.0_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-bin","purl":"pkg:deb/debian/libglib2.0-bin@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-bin/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-bin.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-bin.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-bin.list"}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58010","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58010","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"risk":0.6696049999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58010","description":"A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-58010","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58010","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58010","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58010","https://bugzilla.redhat.com/show_bug.cgi?id=2492243","https://gitlab.gnome.org/GNOME/glib/-/issues/3915"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58010","description":"A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary."}]},{"artifact":{"id":"757dc53367620c75","cpes":["cpe:2.3:a:libglib2.0-bin:libglib2.0-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-bin:libglib2.0_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_bin:libglib2.0-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_bin:libglib2.0_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-bin","purl":"pkg:deb/debian/libglib2.0-bin@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-bin/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-bin.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-bin.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-bin.list"}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58012","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58012","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58012","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58012","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"risk":0.6696049999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58012","description":"A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-58012","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58012","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58012","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58012","https://bugzilla.redhat.com/show_bug.cgi?id=2492247","https://gitlab.gnome.org/GNOME/glib/-/issues/3918"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58012","description":"A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary."}]},{"artifact":{"id":"757dc53367620c75","cpes":["cpe:2.3:a:libglib2.0-bin:libglib2.0-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-bin:libglib2.0_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_bin:libglib2.0-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_bin:libglib2.0_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-bin","purl":"pkg:deb/debian/libglib2.0-bin@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-bin/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-bin.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-bin.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-bin.list"}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58013","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58013","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58013","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"risk":0.6696049999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58013","description":"A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-58013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58013","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58013","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58013","https://bugzilla.redhat.com/show_bug.cgi?id=2492248","https://gitlab.gnome.org/GNOME/glib/-/issues/3925"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58013","description":"A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary."}]},{"artifact":{"id":"f3f80a402f7cbc1b","cpes":["cpe:2.3:a:libglib2.0-data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-data","purl":"pkg:deb/debian/libglib2.0-data@2.74.6-2%2Bdeb12u9?arch=all&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-data/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-data.list"}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58010","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58010","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"risk":0.6696049999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58010","description":"A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-58010","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58010","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58010","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58010","https://bugzilla.redhat.com/show_bug.cgi?id=2492243","https://gitlab.gnome.org/GNOME/glib/-/issues/3915"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58010","description":"A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary."}]},{"artifact":{"id":"f3f80a402f7cbc1b","cpes":["cpe:2.3:a:libglib2.0-data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-data","purl":"pkg:deb/debian/libglib2.0-data@2.74.6-2%2Bdeb12u9?arch=all&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-data/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-data.list"}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58012","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58012","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58012","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58012","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"risk":0.6696049999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58012","description":"A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-58012","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58012","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58012","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58012","https://bugzilla.redhat.com/show_bug.cgi?id=2492247","https://gitlab.gnome.org/GNOME/glib/-/issues/3918"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58012","description":"A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary."}]},{"artifact":{"id":"f3f80a402f7cbc1b","cpes":["cpe:2.3:a:libglib2.0-data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-data","purl":"pkg:deb/debian/libglib2.0-data@2.74.6-2%2Bdeb12u9?arch=all&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-data/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-data.list"}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58013","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58013","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58013","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"risk":0.6696049999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58013","description":"A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-58013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58013","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58013","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58013","https://bugzilla.redhat.com/show_bug.cgi?id=2492248","https://gitlab.gnome.org/GNOME/glib/-/issues/3925"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58013","description":"A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary."}]},{"artifact":{"id":"17127afcd14d4e5d","cpes":["cpe:2.3:a:libglib2.0-dev:libglib2.0-dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev:libglib2.0_dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0-dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0_dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-dev","purl":"pkg:deb/debian/libglib2.0-dev@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58010","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58010","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"risk":0.6696049999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58010","description":"A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-58010","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58010","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58010","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58010","https://bugzilla.redhat.com/show_bug.cgi?id=2492243","https://gitlab.gnome.org/GNOME/glib/-/issues/3915"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58010","description":"A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary."}]},{"artifact":{"id":"17127afcd14d4e5d","cpes":["cpe:2.3:a:libglib2.0-dev:libglib2.0-dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev:libglib2.0_dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0-dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0_dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-dev","purl":"pkg:deb/debian/libglib2.0-dev@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58012","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58012","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58012","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58012","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"risk":0.6696049999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58012","description":"A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-58012","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58012","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58012","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58012","https://bugzilla.redhat.com/show_bug.cgi?id=2492247","https://gitlab.gnome.org/GNOME/glib/-/issues/3918"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58012","description":"A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary."}]},{"artifact":{"id":"17127afcd14d4e5d","cpes":["cpe:2.3:a:libglib2.0-dev:libglib2.0-dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev:libglib2.0_dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0-dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0_dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-dev","purl":"pkg:deb/debian/libglib2.0-dev@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58013","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58013","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58013","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"risk":0.6696049999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58013","description":"A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-58013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58013","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58013","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58013","https://bugzilla.redhat.com/show_bug.cgi?id=2492248","https://gitlab.gnome.org/GNOME/glib/-/issues/3925"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58013","description":"A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary."}]},{"artifact":{"id":"b56f6def3e8bd4f6","cpes":["cpe:2.3:a:libglib2.0-dev-bin:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev-bin:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev_bin:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev_bin:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-dev-bin","purl":"pkg:deb/debian/libglib2.0-dev-bin@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-dev-bin/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.list"},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.postinst"},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.prerm"}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58010","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58010","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"risk":0.6696049999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58010","description":"A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-58010","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58010","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58010","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58010","https://bugzilla.redhat.com/show_bug.cgi?id=2492243","https://gitlab.gnome.org/GNOME/glib/-/issues/3915"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58010","description":"A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary."}]},{"artifact":{"id":"b56f6def3e8bd4f6","cpes":["cpe:2.3:a:libglib2.0-dev-bin:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev-bin:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev_bin:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev_bin:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-dev-bin","purl":"pkg:deb/debian/libglib2.0-dev-bin@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-dev-bin/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.list"},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.postinst"},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.prerm"}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58012","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58012","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58012","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58012","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"risk":0.6696049999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58012","description":"A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-58012","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58012","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58012","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58012","https://bugzilla.redhat.com/show_bug.cgi?id=2492247","https://gitlab.gnome.org/GNOME/glib/-/issues/3918"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58012","description":"A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary."}]},{"artifact":{"id":"b56f6def3e8bd4f6","cpes":["cpe:2.3:a:libglib2.0-dev-bin:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev-bin:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev_bin:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev_bin:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-dev-bin","purl":"pkg:deb/debian/libglib2.0-dev-bin@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-dev-bin/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.list"},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.postinst"},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.prerm"}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58013","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58013","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58013","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"risk":0.6696049999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58013","description":"A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-58013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58013","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58013","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58013","https://bugzilla.redhat.com/show_bug.cgi?id=2492248","https://gitlab.gnome.org/GNOME/glib/-/issues/3925"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58013","description":"A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary."}]},{"artifact":{"id":"d82af4e74abd89bc","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","type":"deb","version":"1:9.2p1-2+deb12u10","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-15778","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2020-15778","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-15778","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-15778","cwe":"CWE-78","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-15778","date":"2026-10-08","epss":0.12996,"percentile":0.96239}],"risk":0.6498,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2020-15778","description":"scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of \"anomalous argument transfers\" because that could \"stand a great chance of breaking existing workflows.\""},"relatedVulnerabilities":[{"id":"CVE-2020-15778","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.6},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-15778","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-15778","cwe":"CWE-78","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-15778","date":"2026-10-08","epss":0.12996,"percentile":0.96239}],"urls":["https://access.redhat.com/errata/RHSA-2024:3166","https://github.com/cpandya2909/CVE-2020-15778/","https://news.ycombinator.com/item?id=25005567","https://security.gentoo.org/glsa/202212-06","https://security.netapp.com/advisory/ntap-20200731-0007/","https://www.openssh.com/security.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-15778","description":"scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of \"anomalous argument transfers\" because that could \"stand a great chance of breaking existing workflows.\""}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-11856","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11856","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"risk":0.6467200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`."},"relatedVulnerabilities":[{"id":"CVE-2026-11856","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"urls":["https://curl.se/docs/CVE-2026-11856.html","https://curl.se/docs/CVE-2026-11856.json","https://hackerone.com/reports/3793260"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Authorization:` header field meant for `hostA`,\nto `hostB`."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11856","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11856","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"risk":0.6467200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`."},"relatedVulnerabilities":[{"id":"CVE-2026-11856","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"urls":["https://curl.se/docs/CVE-2026-11856.html","https://curl.se/docs/CVE-2026-11856.json","https://hackerone.com/reports/3793260"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Authorization:` header field meant for `hostA`,\nto `hostB`."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11856","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11856","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"risk":0.6467200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`."},"relatedVulnerabilities":[{"id":"CVE-2026-11856","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"urls":["https://curl.se/docs/CVE-2026-11856.html","https://curl.se/docs/CVE-2026-11856.json","https://hackerone.com/reports/3793260"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Authorization:` header field meant for `hostA`,\nto `hostB`."}]},{"artifact":{"id":"610d5f28e0c6125d","cpes":["cpe:2.3:a:libcurl4-openssl-dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl-dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4-openssl-dev","purl":"pkg:deb/debian/libcurl4-openssl-dev@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4-openssl-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libcurl4-openssl-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11856","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11856","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"risk":0.6467200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`."},"relatedVulnerabilities":[{"id":"CVE-2026-11856","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"urls":["https://curl.se/docs/CVE-2026-11856.html","https://curl.se/docs/CVE-2026-11856.json","https://hackerone.com/reports/3793260"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Authorization:` header field meant for `hostA`,\nto `hostB`."}]},{"artifact":{"id":"ac9f96c95674631f","cpes":["cpe:2.3:a:libopenexr-3-1-30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1-30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-3-1-30","purl":"pkg:deb/debian/libopenexr-3-1-30@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-3-1-30/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-3-1-30/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42216","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-42216","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42216","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42216","cwe":"CWE-130","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42216","date":"2026-10-08","epss":0.00712,"percentile":0.52165}],"risk":0.6443599999999999,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42216","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next string is expected to begin with a 2-byte prefix length. The code reads stringList[i][0] and stringList[i][1] without checking that the current string has at least two bytes. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11."},"relatedVulnerabilities":[{"id":"CVE-2026-42216","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42216","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42216","cwe":"CWE-130","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42216","date":"2026-10-08","epss":0.00712,"percentile":0.52165}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-65j8-95g9-jgj4","https://access.redhat.com/errata/RHSA-2026:38498","https://access.redhat.com/errata/RHSA-2026:38499","https://access.redhat.com/errata/RHSA-2026:39024","https://access.redhat.com/errata/RHSA-2026:39025","https://access.redhat.com/errata/RHSA-2026:39026","https://access.redhat.com/errata/RHSA-2026:39027","https://access.redhat.com/security/cve/CVE-2026-42216","https://bugzilla.redhat.com/show_bug.cgi?id=2467633","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42216.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42216","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next string is expected to begin with a 2-byte prefix length. The code reads stringList[i][0] and stringList[i][1] without checking that the current string has at least two bytes. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11."}]},{"artifact":{"id":"229cdd73859abf63","cpes":["cpe:2.3:a:libopenexr-dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-dev","purl":"pkg:deb/debian/libopenexr-dev@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.list"}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42216","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-42216","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42216","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42216","cwe":"CWE-130","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42216","date":"2026-10-08","epss":0.00712,"percentile":0.52165}],"risk":0.6443599999999999,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42216","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next string is expected to begin with a 2-byte prefix length. The code reads stringList[i][0] and stringList[i][1] without checking that the current string has at least two bytes. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11."},"relatedVulnerabilities":[{"id":"CVE-2026-42216","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42216","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42216","cwe":"CWE-130","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42216","date":"2026-10-08","epss":0.00712,"percentile":0.52165}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-65j8-95g9-jgj4","https://access.redhat.com/errata/RHSA-2026:38498","https://access.redhat.com/errata/RHSA-2026:38499","https://access.redhat.com/errata/RHSA-2026:39024","https://access.redhat.com/errata/RHSA-2026:39025","https://access.redhat.com/errata/RHSA-2026:39026","https://access.redhat.com/errata/RHSA-2026:39027","https://access.redhat.com/security/cve/CVE-2026-42216","https://bugzilla.redhat.com/show_bug.cgi?id=2467633","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42216.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42216","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next string is expected to begin with a 2-byte prefix length. The code reads stringList[i][0] and stringList[i][1] without checking that the current string has at least two bytes. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11."}]},{"artifact":{"id":"be12828c4e3c1a16","cpes":["cpe:2.3:a:libcairo-gobject2:libcairo-gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo-gobject2:libcairo_gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_gobject2:libcairo-gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_gobject2:libcairo_gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo:libcairo-gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo:libcairo_gobject2:1.16.0-7:*:*:*:*:*:*:*"],"name":"libcairo-gobject2","purl":"pkg:deb/debian/libcairo-gobject2@1.16.0-7?arch=amd64&distro=debian-12.15&upstream=cairo","type":"deb","version":"1.16.0-7","language":"","licenses":["sha256:408fb9e704e875cd42d432e7c9b3b378f568e3c89db2b5c5ef3d11c025319574"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcairo-gobject2/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libcairo-gobject2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcairo-gobject2:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libcairo-gobject2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cairo"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-6462","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cairo","version":"1.16.0-7"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-6462","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-6462","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6462","date":"2026-10-08","epss":0.02124,"percentile":0.81339}],"risk":0.6371999999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-6462","description":"An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized."},"relatedVulnerabilities":[{"id":"CVE-2019-6462","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-6462","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6462","date":"2026-10-08","epss":0.02124,"percentile":0.81339}],"urls":["https://github.com/TeamSeri0us/pocs/tree/master/gerbv","https://gitlab.freedesktop.org/cairo/cairo/issues/353","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-6462","description":"An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized."}]},{"artifact":{"id":"d150a0acc96f6751","cpes":["cpe:2.3:a:libcairo-script-interpreter2:libcairo-script-interpreter2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo-script-interpreter2:libcairo_script_interpreter2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_script_interpreter2:libcairo-script-interpreter2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_script_interpreter2:libcairo_script_interpreter2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo-script:libcairo-script-interpreter2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo-script:libcairo_script_interpreter2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_script:libcairo-script-interpreter2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_script:libcairo_script_interpreter2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo:libcairo-script-interpreter2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo:libcairo_script_interpreter2:1.16.0-7:*:*:*:*:*:*:*"],"name":"libcairo-script-interpreter2","purl":"pkg:deb/debian/libcairo-script-interpreter2@1.16.0-7?arch=amd64&distro=debian-12.15&upstream=cairo","type":"deb","version":"1.16.0-7","language":"","licenses":["sha256:408fb9e704e875cd42d432e7c9b3b378f568e3c89db2b5c5ef3d11c025319574"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcairo-script-interpreter2/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libcairo-script-interpreter2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcairo-script-interpreter2:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libcairo-script-interpreter2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cairo"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-6462","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cairo","version":"1.16.0-7"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-6462","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-6462","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6462","date":"2026-10-08","epss":0.02124,"percentile":0.81339}],"risk":0.6371999999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-6462","description":"An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized."},"relatedVulnerabilities":[{"id":"CVE-2019-6462","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-6462","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6462","date":"2026-10-08","epss":0.02124,"percentile":0.81339}],"urls":["https://github.com/TeamSeri0us/pocs/tree/master/gerbv","https://gitlab.freedesktop.org/cairo/cairo/issues/353","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-6462","description":"An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized."}]},{"artifact":{"id":"28d5ccf8758a4075","cpes":["cpe:2.3:a:libcairo2:libcairo2:1.16.0-7:*:*:*:*:*:*:*"],"name":"libcairo2","purl":"pkg:deb/debian/libcairo2@1.16.0-7?arch=amd64&distro=debian-12.15&upstream=cairo","type":"deb","version":"1.16.0-7","language":"","licenses":["sha256:408fb9e704e875cd42d432e7c9b3b378f568e3c89db2b5c5ef3d11c025319574"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcairo2/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libcairo2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcairo2:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libcairo2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cairo"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-6462","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cairo","version":"1.16.0-7"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-6462","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-6462","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6462","date":"2026-10-08","epss":0.02124,"percentile":0.81339}],"risk":0.6371999999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-6462","description":"An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized."},"relatedVulnerabilities":[{"id":"CVE-2019-6462","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-6462","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6462","date":"2026-10-08","epss":0.02124,"percentile":0.81339}],"urls":["https://github.com/TeamSeri0us/pocs/tree/master/gerbv","https://gitlab.freedesktop.org/cairo/cairo/issues/353","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-6462","description":"An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized."}]},{"artifact":{"id":"685e5753b38233fa","cpes":["cpe:2.3:a:libcairo2-dev:libcairo2-dev:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo2-dev:libcairo2_dev:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo2_dev:libcairo2-dev:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo2_dev:libcairo2_dev:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo2:libcairo2-dev:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo2:libcairo2_dev:1.16.0-7:*:*:*:*:*:*:*"],"name":"libcairo2-dev","purl":"pkg:deb/debian/libcairo2-dev@1.16.0-7?arch=amd64&distro=debian-12.15&upstream=cairo","type":"deb","version":"1.16.0-7","language":"","licenses":["sha256:408fb9e704e875cd42d432e7c9b3b378f568e3c89db2b5c5ef3d11c025319574"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcairo2-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libcairo2-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcairo2-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libcairo2-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cairo"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-6462","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cairo","version":"1.16.0-7"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-6462","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-6462","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6462","date":"2026-10-08","epss":0.02124,"percentile":0.81339}],"risk":0.6371999999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-6462","description":"An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized."},"relatedVulnerabilities":[{"id":"CVE-2019-6462","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-6462","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6462","date":"2026-10-08","epss":0.02124,"percentile":0.81339}],"urls":["https://github.com/TeamSeri0us/pocs/tree/master/gerbv","https://gitlab.freedesktop.org/cairo/cairo/issues/353","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-6462","description":"An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized."}]},{"artifact":{"id":"be12828c4e3c1a16","cpes":["cpe:2.3:a:libcairo-gobject2:libcairo-gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo-gobject2:libcairo_gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_gobject2:libcairo-gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_gobject2:libcairo_gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo:libcairo-gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo:libcairo_gobject2:1.16.0-7:*:*:*:*:*:*:*"],"name":"libcairo-gobject2","purl":"pkg:deb/debian/libcairo-gobject2@1.16.0-7?arch=amd64&distro=debian-12.15&upstream=cairo","type":"deb","version":"1.16.0-7","language":"","licenses":["sha256:408fb9e704e875cd42d432e7c9b3b378f568e3c89db2b5c5ef3d11c025319574"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcairo-gobject2/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libcairo-gobject2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcairo-gobject2:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libcairo-gobject2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cairo"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-6461","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cairo","version":"1.16.0-7"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-6461","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-6461","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6461","date":"2026-10-08","epss":0.021,"percentile":0.81133}],"risk":0.63,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-6461","description":"An issue was discovered in cairo 1.16.0. There is an assertion problem in the function _cairo_arc_in_direction in the file cairo-arc.c."},"relatedVulnerabilities":[{"id":"CVE-2019-6461","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-6461","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6461","date":"2026-10-08","epss":0.021,"percentile":0.81133}],"urls":["https://github.com/TeamSeri0us/pocs/tree/master/gerbv","https://gitlab.freedesktop.org/cairo/cairo/issues/352","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-6461","description":"An issue was discovered in cairo 1.16.0. There is an assertion problem in the function _cairo_arc_in_direction in the file cairo-arc.c."}]},{"artifact":{"id":"d150a0acc96f6751","cpes":["cpe:2.3:a:libcairo-script-interpreter2:libcairo-script-interpreter2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo-script-interpreter2:libcairo_script_interpreter2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_script_interpreter2:libcairo-script-interpreter2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_script_interpreter2:libcairo_script_interpreter2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo-script:libcairo-script-interpreter2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo-script:libcairo_script_interpreter2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_script:libcairo-script-interpreter2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_script:libcairo_script_interpreter2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo:libcairo-script-interpreter2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo:libcairo_script_interpreter2:1.16.0-7:*:*:*:*:*:*:*"],"name":"libcairo-script-interpreter2","purl":"pkg:deb/debian/libcairo-script-interpreter2@1.16.0-7?arch=amd64&distro=debian-12.15&upstream=cairo","type":"deb","version":"1.16.0-7","language":"","licenses":["sha256:408fb9e704e875cd42d432e7c9b3b378f568e3c89db2b5c5ef3d11c025319574"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcairo-script-interpreter2/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libcairo-script-interpreter2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcairo-script-interpreter2:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libcairo-script-interpreter2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cairo"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-6461","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cairo","version":"1.16.0-7"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-6461","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-6461","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6461","date":"2026-10-08","epss":0.021,"percentile":0.81133}],"risk":0.63,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-6461","description":"An issue was discovered in cairo 1.16.0. There is an assertion problem in the function _cairo_arc_in_direction in the file cairo-arc.c."},"relatedVulnerabilities":[{"id":"CVE-2019-6461","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-6461","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6461","date":"2026-10-08","epss":0.021,"percentile":0.81133}],"urls":["https://github.com/TeamSeri0us/pocs/tree/master/gerbv","https://gitlab.freedesktop.org/cairo/cairo/issues/352","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-6461","description":"An issue was discovered in cairo 1.16.0. There is an assertion problem in the function _cairo_arc_in_direction in the file cairo-arc.c."}]},{"artifact":{"id":"28d5ccf8758a4075","cpes":["cpe:2.3:a:libcairo2:libcairo2:1.16.0-7:*:*:*:*:*:*:*"],"name":"libcairo2","purl":"pkg:deb/debian/libcairo2@1.16.0-7?arch=amd64&distro=debian-12.15&upstream=cairo","type":"deb","version":"1.16.0-7","language":"","licenses":["sha256:408fb9e704e875cd42d432e7c9b3b378f568e3c89db2b5c5ef3d11c025319574"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcairo2/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libcairo2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcairo2:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libcairo2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cairo"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-6461","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cairo","version":"1.16.0-7"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-6461","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-6461","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6461","date":"2026-10-08","epss":0.021,"percentile":0.81133}],"risk":0.63,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-6461","description":"An issue was discovered in cairo 1.16.0. There is an assertion problem in the function _cairo_arc_in_direction in the file cairo-arc.c."},"relatedVulnerabilities":[{"id":"CVE-2019-6461","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-6461","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6461","date":"2026-10-08","epss":0.021,"percentile":0.81133}],"urls":["https://github.com/TeamSeri0us/pocs/tree/master/gerbv","https://gitlab.freedesktop.org/cairo/cairo/issues/352","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-6461","description":"An issue was discovered in cairo 1.16.0. There is an assertion problem in the function _cairo_arc_in_direction in the file cairo-arc.c."}]},{"artifact":{"id":"685e5753b38233fa","cpes":["cpe:2.3:a:libcairo2-dev:libcairo2-dev:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo2-dev:libcairo2_dev:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo2_dev:libcairo2-dev:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo2_dev:libcairo2_dev:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo2:libcairo2-dev:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo2:libcairo2_dev:1.16.0-7:*:*:*:*:*:*:*"],"name":"libcairo2-dev","purl":"pkg:deb/debian/libcairo2-dev@1.16.0-7?arch=amd64&distro=debian-12.15&upstream=cairo","type":"deb","version":"1.16.0-7","language":"","licenses":["sha256:408fb9e704e875cd42d432e7c9b3b378f568e3c89db2b5c5ef3d11c025319574"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcairo2-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libcairo2-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcairo2-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libcairo2-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cairo"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-6461","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cairo","version":"1.16.0-7"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-6461","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-6461","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6461","date":"2026-10-08","epss":0.021,"percentile":0.81133}],"risk":0.63,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-6461","description":"An issue was discovered in cairo 1.16.0. There is an assertion problem in the function _cairo_arc_in_direction in the file cairo-arc.c."},"relatedVulnerabilities":[{"id":"CVE-2019-6461","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-6461","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6461","date":"2026-10-08","epss":0.021,"percentile":0.81133}],"urls":["https://github.com/TeamSeri0us/pocs/tree/master/gerbv","https://gitlab.freedesktop.org/cairo/cairo/issues/352","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-6461","description":"An issue was discovered in cairo 1.16.0. There is an assertion problem in the function _cairo_arc_in_direction in the file cairo-arc.c."}]},{"artifact":{"id":"6dec48f68a6dce02","cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"libheif1","purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","type":"deb","version":"1.15.1-1+deb12u1","language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libheif"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-32740","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-32740","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32740","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-32740","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32740","date":"2026-10-08","epss":0.00759,"percentile":0.53835}],"risk":0.618585,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-32740","description":"libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write 64 bytes of fully attacker-controlled data past the end of a chroma plane heap allocation by crafting a HEIF/AVIF file with a 1×4 grid of odd-height tiles. The overflow is triggered during normal image decoding with default build configuration. The written bytes are chroma (Cb/Cr) pixel values from the attacking tile, giving the attacker full control over the overflow content. This issue has been fixed in version 1.22.0."},"relatedVulnerabilities":[{"id":"CVE-2026-32740","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32740","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-32740","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32740","date":"2026-10-08","epss":0.00759,"percentile":0.53835}],"urls":["https://github.com/strukturag/libheif/releases/tag/v1.22.0","https://github.com/strukturag/libheif/security/advisories/GHSA-frfr-f3vg-2g6j","https://access.redhat.com/security/cve/CVE-2026-32740","https://bugzilla.redhat.com/show_bug.cgi?id=2479969","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32740.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32740","description":"libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write 64 bytes of fully attacker-controlled data past the end of a chroma plane heap allocation by crafting a HEIF/AVIF file with a 1×4 grid of odd-height tiles. The overflow is triggered during normal image decoding with default build configuration. The written bytes are chroma (Cb/Cr) pixel values from the attacking tile, giving the attacker full control over the overflow content. This issue has been fixed in version 1.22.0."}]},{"artifact":{"id":"ac9f96c95674631f","cpes":["cpe:2.3:a:libopenexr-3-1-30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1-30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-3-1-30","purl":"pkg:deb/debian/libopenexr-3-1-30@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-3-1-30/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-3-1-30/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42217","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-42217","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42217","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-42217","date":"2026-10-08","epss":0.00657,"percentile":0.49896}],"risk":0.61758,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42217","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, readVariableLengthInteger() decodes a variable-length integer from untrusted EXR input without bounding the shift count. After enough continuation bytes, the code executes a left shift by 70 on a 64-bit value, which is undefined behavior. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11."},"relatedVulnerabilities":[{"id":"CVE-2026-42217","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42217","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-42217","date":"2026-10-08","epss":0.00657,"percentile":0.49896}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/21eaa33bcbbb0c83a5fc42f6b6d65b70a996e63c","https://github.com/AcademySoftwareFoundation/openexr/pull/2378","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-3c67-4wwp-w52m"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42217","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, readVariableLengthInteger() decodes a variable-length integer from untrusted EXR input without bounding the shift count. After enough continuation bytes, the code executes a left shift by 70 on a 64-bit value, which is undefined behavior. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11."}]},{"artifact":{"id":"229cdd73859abf63","cpes":["cpe:2.3:a:libopenexr-dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-dev","purl":"pkg:deb/debian/libopenexr-dev@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.list"}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42217","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-42217","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42217","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-42217","date":"2026-10-08","epss":0.00657,"percentile":0.49896}],"risk":0.61758,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42217","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, readVariableLengthInteger() decodes a variable-length integer from untrusted EXR input without bounding the shift count. After enough continuation bytes, the code executes a left shift by 70 on a 64-bit value, which is undefined behavior. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11."},"relatedVulnerabilities":[{"id":"CVE-2026-42217","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42217","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-42217","date":"2026-10-08","epss":0.00657,"percentile":0.49896}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/21eaa33bcbbb0c83a5fc42f6b6d65b70a996e63c","https://github.com/AcademySoftwareFoundation/openexr/pull/2378","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-3c67-4wwp-w52m"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42217","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, readVariableLengthInteger() decodes a variable-length integer from untrusted EXR input without bounding the shift count. After enough continuation bytes, the code executes a left shift by 70 on a 64-bit value, which is undefined behavior. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11."}]},{"artifact":{"id":"ef5a5a7d880f3e73","cpes":["cpe:2.3:a:wget:wget:1.21.3-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"wget","purl":"pkg:deb/debian/wget@1.21.3-1%2Bdeb12u1?arch=amd64&distro=debian-12.15","type":"deb","version":"1.21.3-1+deb12u1","language":"","licenses":["sha256:c58cb5a2d94f35f0e9b0f1a038d48b73477aa12782ff17328c21d8a86f5f99d5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/wget/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/wget/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.conffiles","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/wget.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/wget.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.list","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/wget.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-10524","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"wget","version":"1.21.3-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2024-10524","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"reefs@jfrog.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":3.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10524","cwe":"CWE-918","type":"Secondary","source":"reefs@jfrog.com"}],"epss":[{"cve":"CVE-2024-10524","date":"2026-10-08","epss":0.01071,"percentile":0.63827}],"risk":0.615825,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-10524","description":"Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host."},"relatedVulnerabilities":[{"id":"CVE-2024-10524","cvss":[{"type":"Secondary","source":"reefs@jfrog.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":3.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10524","cwe":"CWE-918","type":"Secondary","source":"reefs@jfrog.com"}],"epss":[{"cve":"CVE-2024-10524","date":"2026-10-08","epss":0.01071,"percentile":0.63827}],"urls":["https://git.savannah.gnu.org/cgit/wget.git/commit/?id=c419542d956a2607bbce5df64b9d378a8588d778","https://jfrog.com/blog/cve-2024-10524-wget-zero-day-vulnerability/","https://seclists.org/oss-sec/2024/q4/107","http://www.openwall.com/lists/oss-security/2024/11/18/6","https://security.netapp.com/advisory/ntap-20250321-0007/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10524","description":"Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host."}]},{"artifact":{"id":"ef5a5a7d880f3e73","cpes":["cpe:2.3:a:wget:wget:1.21.3-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"wget","purl":"pkg:deb/debian/wget@1.21.3-1%2Bdeb12u1?arch=amd64&distro=debian-12.15","type":"deb","version":"1.21.3-1+deb12u1","language":"","licenses":["sha256:c58cb5a2d94f35f0e9b0f1a038d48b73477aa12782ff17328c21d8a86f5f99d5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/wget/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/wget/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.conffiles","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/wget.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/wget.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.list","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/wget.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-31879","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"wget","version":"1.21.3-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2021-31879","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-31879","cwe":"CWE-601","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-31879","date":"2026-10-08","epss":0.01104,"percentile":0.64746}],"risk":0.6127199999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2021-31879","description":"GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007."},"relatedVulnerabilities":[{"id":"CVE-2021-31879","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-31879","cwe":"CWE-601","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-31879","date":"2026-10-08","epss":0.01104,"percentile":0.64746}],"urls":["https://mail.gnu.org/archive/html/bug-wget/2021-02/msg00002.html","https://security.netapp.com/advisory/ntap-20210618-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-31879","description":"GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007."}]},{"artifact":{"id":"f7e49c1a6279cc8f","cpes":["cpe:2.3:a:libglib2.0-0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-0","purl":"pkg:deb/debian/libglib2.0-0@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-0/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58011","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58011","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58011","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58011","date":"2026-10-08","epss":0.00816,"percentile":0.55788}],"risk":0.6120000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58011","description":"A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-58011","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58011","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58011","date":"2026-10-08","epss":0.00816,"percentile":0.55788}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58011","https://bugzilla.redhat.com/show_bug.cgi?id=2492245","https://gitlab.gnome.org/GNOME/glib/-/issues/3917","https://gitlab.gnome.org/GNOME/glib/-/work_items/3917"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58011","description":"A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service."}]},{"artifact":{"id":"757dc53367620c75","cpes":["cpe:2.3:a:libglib2.0-bin:libglib2.0-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-bin:libglib2.0_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_bin:libglib2.0-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_bin:libglib2.0_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-bin","purl":"pkg:deb/debian/libglib2.0-bin@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-bin/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-bin.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-bin.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-bin.list"}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58011","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58011","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58011","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58011","date":"2026-10-08","epss":0.00816,"percentile":0.55788}],"risk":0.6120000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58011","description":"A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-58011","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58011","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58011","date":"2026-10-08","epss":0.00816,"percentile":0.55788}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58011","https://bugzilla.redhat.com/show_bug.cgi?id=2492245","https://gitlab.gnome.org/GNOME/glib/-/issues/3917","https://gitlab.gnome.org/GNOME/glib/-/work_items/3917"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58011","description":"A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service."}]},{"artifact":{"id":"f3f80a402f7cbc1b","cpes":["cpe:2.3:a:libglib2.0-data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-data","purl":"pkg:deb/debian/libglib2.0-data@2.74.6-2%2Bdeb12u9?arch=all&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-data/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-data.list"}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58011","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58011","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58011","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58011","date":"2026-10-08","epss":0.00816,"percentile":0.55788}],"risk":0.6120000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58011","description":"A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-58011","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58011","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58011","date":"2026-10-08","epss":0.00816,"percentile":0.55788}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58011","https://bugzilla.redhat.com/show_bug.cgi?id=2492245","https://gitlab.gnome.org/GNOME/glib/-/issues/3917","https://gitlab.gnome.org/GNOME/glib/-/work_items/3917"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58011","description":"A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service."}]},{"artifact":{"id":"17127afcd14d4e5d","cpes":["cpe:2.3:a:libglib2.0-dev:libglib2.0-dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev:libglib2.0_dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0-dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0_dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-dev","purl":"pkg:deb/debian/libglib2.0-dev@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58011","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58011","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58011","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58011","date":"2026-10-08","epss":0.00816,"percentile":0.55788}],"risk":0.6120000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58011","description":"A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-58011","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58011","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58011","date":"2026-10-08","epss":0.00816,"percentile":0.55788}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58011","https://bugzilla.redhat.com/show_bug.cgi?id=2492245","https://gitlab.gnome.org/GNOME/glib/-/issues/3917","https://gitlab.gnome.org/GNOME/glib/-/work_items/3917"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58011","description":"A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service."}]},{"artifact":{"id":"b56f6def3e8bd4f6","cpes":["cpe:2.3:a:libglib2.0-dev-bin:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev-bin:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev_bin:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev_bin:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-dev-bin","purl":"pkg:deb/debian/libglib2.0-dev-bin@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-dev-bin/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.list"},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.postinst"},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.prerm"}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58011","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58011","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58011","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58011","date":"2026-10-08","epss":0.00816,"percentile":0.55788}],"risk":0.6120000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58011","description":"A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-58011","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58011","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58011","date":"2026-10-08","epss":0.00816,"percentile":0.55788}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58011","https://bugzilla.redhat.com/show_bug.cgi?id=2492245","https://gitlab.gnome.org/GNOME/glib/-/issues/3917","https://gitlab.gnome.org/GNOME/glib/-/work_items/3917"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58011","description":"A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service."}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"risk":0.5982050000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set \"super cookies\" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains."},"relatedVulnerabilities":[{"id":"CVE-2026-8924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"urls":["https://curl.se/docs/CVE-2026-8924.html","https://curl.se/docs/CVE-2026-8924.json","https://hackerone.com/reports/3733905"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n\"super cookies\" that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"risk":0.5982050000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set \"super cookies\" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains."},"relatedVulnerabilities":[{"id":"CVE-2026-8924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"urls":["https://curl.se/docs/CVE-2026-8924.html","https://curl.se/docs/CVE-2026-8924.json","https://hackerone.com/reports/3733905"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n\"super cookies\" that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"risk":0.5982050000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set \"super cookies\" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains."},"relatedVulnerabilities":[{"id":"CVE-2026-8924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"urls":["https://curl.se/docs/CVE-2026-8924.html","https://curl.se/docs/CVE-2026-8924.json","https://hackerone.com/reports/3733905"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n\"super cookies\" that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains."}]},{"artifact":{"id":"610d5f28e0c6125d","cpes":["cpe:2.3:a:libcurl4-openssl-dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl-dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4-openssl-dev","purl":"pkg:deb/debian/libcurl4-openssl-dev@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4-openssl-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libcurl4-openssl-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"risk":0.5982050000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set \"super cookies\" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains."},"relatedVulnerabilities":[{"id":"CVE-2026-8924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"urls":["https://curl.se/docs/CVE-2026-8924.html","https://curl.se/docs/CVE-2026-8924.json","https://hackerone.com/reports/3733905"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n\"super cookies\" that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains."}]},{"artifact":{"id":"ac9f96c95674631f","cpes":["cpe:2.3:a:libopenexr-3-1-30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1-30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-3-1-30","purl":"pkg:deb/debian/libopenexr-3-1-30@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-3-1-30/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-3-1-30/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-41142","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-41142","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41142","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41142","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-41142","date":"2026-10-08","epss":0.0073,"percentile":0.52843}],"risk":0.5949500000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-41142","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, there is an integer overflow in ImageChannel::resize that leads to heap OOB write via OpenEXRUtil public API. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11."},"relatedVulnerabilities":[{"id":"CVE-2026-41142","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41142","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41142","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-41142","date":"2026-10-08","epss":0.0073,"percentile":0.52843}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/0592ee539f33c122c90f09238579b902d838afb4","https://github.com/AcademySoftwareFoundation/openexr/pull/2367","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-m25w-72cj-q6mg","https://access.redhat.com/errata/RHSA-2026:38498","https://access.redhat.com/errata/RHSA-2026:38499","https://access.redhat.com/errata/RHSA-2026:39024","https://access.redhat.com/errata/RHSA-2026:39025","https://access.redhat.com/errata/RHSA-2026:39026","https://access.redhat.com/errata/RHSA-2026:39027","https://access.redhat.com/security/cve/CVE-2026-41142","https://bugzilla.redhat.com/show_bug.cgi?id=2467623","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41142.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41142","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, there is an integer overflow in ImageChannel::resize that leads to heap OOB write via OpenEXRUtil public API. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11."}]},{"artifact":{"id":"229cdd73859abf63","cpes":["cpe:2.3:a:libopenexr-dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-dev","purl":"pkg:deb/debian/libopenexr-dev@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.list"}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-41142","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-41142","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41142","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41142","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-41142","date":"2026-10-08","epss":0.0073,"percentile":0.52843}],"risk":0.5949500000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-41142","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, there is an integer overflow in ImageChannel::resize that leads to heap OOB write via OpenEXRUtil public API. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11."},"relatedVulnerabilities":[{"id":"CVE-2026-41142","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41142","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41142","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-41142","date":"2026-10-08","epss":0.0073,"percentile":0.52843}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/0592ee539f33c122c90f09238579b902d838afb4","https://github.com/AcademySoftwareFoundation/openexr/pull/2367","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-m25w-72cj-q6mg","https://access.redhat.com/errata/RHSA-2026:38498","https://access.redhat.com/errata/RHSA-2026:38499","https://access.redhat.com/errata/RHSA-2026:39024","https://access.redhat.com/errata/RHSA-2026:39025","https://access.redhat.com/errata/RHSA-2026:39026","https://access.redhat.com/errata/RHSA-2026:39027","https://access.redhat.com/security/cve/CVE-2026-41142","https://bugzilla.redhat.com/show_bug.cgi?id=2467623","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41142.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41142","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, there is an integer overflow in ImageChannel::resize that leads to heap OOB write via OpenEXRUtil public API. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11."}]},{"artifact":{"id":"f7e49c1a6279cc8f","cpes":["cpe:2.3:a:libglib2.0-0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-0","purl":"pkg:deb/debian/libglib2.0-0@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-0/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58014","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58014","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":8.6,"impactScore":4.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58014","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58014","date":"2026-10-08","epss":0.00722,"percentile":0.52535}],"risk":0.58121,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58014","description":"A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-58014","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":8.6,"impactScore":4.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58014","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58014","date":"2026-10-08","epss":0.00722,"percentile":0.52535}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:66357","https://access.redhat.com/errata/RHSA-2026:70586","https://access.redhat.com/errata/RHSA-2026:70646","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73851","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58014","https://bugzilla.redhat.com/show_bug.cgi?id=2492255","https://gitlab.gnome.org/GNOME/glib/-/issues/3930"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58014","description":"A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary."}]},{"artifact":{"id":"757dc53367620c75","cpes":["cpe:2.3:a:libglib2.0-bin:libglib2.0-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-bin:libglib2.0_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_bin:libglib2.0-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_bin:libglib2.0_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-bin","purl":"pkg:deb/debian/libglib2.0-bin@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-bin/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-bin.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-bin.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-bin.list"}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58014","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58014","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":8.6,"impactScore":4.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58014","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58014","date":"2026-10-08","epss":0.00722,"percentile":0.52535}],"risk":0.58121,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58014","description":"A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-58014","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":8.6,"impactScore":4.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58014","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58014","date":"2026-10-08","epss":0.00722,"percentile":0.52535}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:66357","https://access.redhat.com/errata/RHSA-2026:70586","https://access.redhat.com/errata/RHSA-2026:70646","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73851","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58014","https://bugzilla.redhat.com/show_bug.cgi?id=2492255","https://gitlab.gnome.org/GNOME/glib/-/issues/3930"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58014","description":"A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary."}]},{"artifact":{"id":"f3f80a402f7cbc1b","cpes":["cpe:2.3:a:libglib2.0-data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-data","purl":"pkg:deb/debian/libglib2.0-data@2.74.6-2%2Bdeb12u9?arch=all&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-data/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-data.list"}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58014","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58014","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":8.6,"impactScore":4.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58014","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58014","date":"2026-10-08","epss":0.00722,"percentile":0.52535}],"risk":0.58121,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58014","description":"A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-58014","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":8.6,"impactScore":4.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58014","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58014","date":"2026-10-08","epss":0.00722,"percentile":0.52535}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:66357","https://access.redhat.com/errata/RHSA-2026:70586","https://access.redhat.com/errata/RHSA-2026:70646","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73851","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58014","https://bugzilla.redhat.com/show_bug.cgi?id=2492255","https://gitlab.gnome.org/GNOME/glib/-/issues/3930"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58014","description":"A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary."}]},{"artifact":{"id":"17127afcd14d4e5d","cpes":["cpe:2.3:a:libglib2.0-dev:libglib2.0-dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev:libglib2.0_dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0-dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0_dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-dev","purl":"pkg:deb/debian/libglib2.0-dev@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58014","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58014","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":8.6,"impactScore":4.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58014","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58014","date":"2026-10-08","epss":0.00722,"percentile":0.52535}],"risk":0.58121,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58014","description":"A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-58014","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":8.6,"impactScore":4.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58014","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58014","date":"2026-10-08","epss":0.00722,"percentile":0.52535}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:66357","https://access.redhat.com/errata/RHSA-2026:70586","https://access.redhat.com/errata/RHSA-2026:70646","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73851","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58014","https://bugzilla.redhat.com/show_bug.cgi?id=2492255","https://gitlab.gnome.org/GNOME/glib/-/issues/3930"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58014","description":"A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary."}]},{"artifact":{"id":"b56f6def3e8bd4f6","cpes":["cpe:2.3:a:libglib2.0-dev-bin:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev-bin:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev_bin:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev_bin:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-dev-bin","purl":"pkg:deb/debian/libglib2.0-dev-bin@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-dev-bin/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.list"},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.postinst"},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.prerm"}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58014","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58014","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":8.6,"impactScore":4.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58014","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58014","date":"2026-10-08","epss":0.00722,"percentile":0.52535}],"risk":0.58121,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58014","description":"A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-58014","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":8.6,"impactScore":4.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58014","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58014","date":"2026-10-08","epss":0.00722,"percentile":0.52535}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:66357","https://access.redhat.com/errata/RHSA-2026:70586","https://access.redhat.com/errata/RHSA-2026:70646","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73851","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58014","https://bugzilla.redhat.com/show_bug.cgi?id=2492255","https://gitlab.gnome.org/GNOME/glib/-/issues/3930"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58014","description":"A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary."}]},{"artifact":{"id":"57bc3e079dc33e92","cpes":["cpe:2.3:a:libbluetooth-dev:libbluetooth-dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth-dev:libbluetooth_dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth_dev:libbluetooth-dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth_dev:libbluetooth_dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth:libbluetooth-dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth:libbluetooth_dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*"],"name":"libbluetooth-dev","purl":"pkg:deb/debian/libbluetooth-dev@5.66-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=bluez","type":"deb","version":"5.66-1+deb12u2","language":"","licenses":["Apache-2.0","BSD-2-clause","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libbluetooth-dev/copyright","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/usr/share/doc/libbluetooth-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbluetooth-dev:amd64.md5sums","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/info/libbluetooth-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bluez"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-51594","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"bluez","version":"5.66-1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-51594","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.7,"impactScore":3.6,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-51594","cwe":"CWE-125","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2023-51594","date":"2026-10-08","epss":0.01071,"percentile":0.63826}],"risk":0.5729850000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-51594","description":"BlueZ OBEX Library Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious Bluetooth device.  The specific flaw exists within the handling of OBEX protocol parameters. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-20937."},"relatedVulnerabilities":[{"id":"CVE-2023-51594","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.7,"impactScore":3.6,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"zdi-disclosures@trendmicro.com","vector":"CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.6,"impactScore":1.5,"exploitabilityScore":1.2},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-51594","cwe":"CWE-125","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2023-51594","date":"2026-10-08","epss":0.01071,"percentile":0.63826}],"urls":["https://www.zerodayinitiative.com/advisories/ZDI-23-1901/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-51594","description":"BlueZ OBEX Library Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious Bluetooth device.\n\nThe specific flaw exists within the handling of OBEX protocol parameters. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-20937."}]},{"artifact":{"id":"818aff19ee069170","cpes":["cpe:2.3:a:libbluetooth3:libbluetooth3:5.66-1\\+deb12u2:*:*:*:*:*:*:*"],"name":"libbluetooth3","purl":"pkg:deb/debian/libbluetooth3@5.66-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=bluez","type":"deb","version":"5.66-1+deb12u2","language":"","licenses":["Apache-2.0","BSD-2-clause","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libbluetooth3/copyright","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/usr/share/doc/libbluetooth3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbluetooth3:amd64.md5sums","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/info/libbluetooth3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bluez"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-51594","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"bluez","version":"5.66-1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-51594","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.7,"impactScore":3.6,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-51594","cwe":"CWE-125","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2023-51594","date":"2026-10-08","epss":0.01071,"percentile":0.63826}],"risk":0.5729850000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-51594","description":"BlueZ OBEX Library Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious Bluetooth device.  The specific flaw exists within the handling of OBEX protocol parameters. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-20937."},"relatedVulnerabilities":[{"id":"CVE-2023-51594","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.7,"impactScore":3.6,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"zdi-disclosures@trendmicro.com","vector":"CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.6,"impactScore":1.5,"exploitabilityScore":1.2},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-51594","cwe":"CWE-125","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2023-51594","date":"2026-10-08","epss":0.01071,"percentile":0.63826}],"urls":["https://www.zerodayinitiative.com/advisories/ZDI-23-1901/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-51594","description":"BlueZ OBEX Library Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious Bluetooth device.\n\nThe specific flaw exists within the handling of OBEX protocol parameters. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-20937."}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-10536","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-10536","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-08","epss":0.00598,"percentile":0.46964}],"risk":0.5621200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation."},"relatedVulnerabilities":[{"id":"CVE-2026-10536","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-08","epss":0.00598,"percentile":0.46964}],"urls":["https://curl.se/docs/CVE-2026-10536.html","https://curl.se/docs/CVE-2026-10536.json","https://hackerone.com/reports/3751697"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application\nconfigures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or\n`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and\nfinally terminates the handle with `curl_easy_cleanup()`. During this final\ncleanup phase, libcurl attempts to access and modify an internal structure\nthat was already freed during the reset operation."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-10536","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-10536","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-08","epss":0.00598,"percentile":0.46964}],"risk":0.5621200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation."},"relatedVulnerabilities":[{"id":"CVE-2026-10536","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-08","epss":0.00598,"percentile":0.46964}],"urls":["https://curl.se/docs/CVE-2026-10536.html","https://curl.se/docs/CVE-2026-10536.json","https://hackerone.com/reports/3751697"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application\nconfigures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or\n`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and\nfinally terminates the handle with `curl_easy_cleanup()`. During this final\ncleanup phase, libcurl attempts to access and modify an internal structure\nthat was already freed during the reset operation."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-10536","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-10536","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-08","epss":0.00598,"percentile":0.46964}],"risk":0.5621200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation."},"relatedVulnerabilities":[{"id":"CVE-2026-10536","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-08","epss":0.00598,"percentile":0.46964}],"urls":["https://curl.se/docs/CVE-2026-10536.html","https://curl.se/docs/CVE-2026-10536.json","https://hackerone.com/reports/3751697"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application\nconfigures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or\n`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and\nfinally terminates the handle with `curl_easy_cleanup()`. During this final\ncleanup phase, libcurl attempts to access and modify an internal structure\nthat was already freed during the reset operation."}]},{"artifact":{"id":"610d5f28e0c6125d","cpes":["cpe:2.3:a:libcurl4-openssl-dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl-dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4-openssl-dev","purl":"pkg:deb/debian/libcurl4-openssl-dev@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4-openssl-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libcurl4-openssl-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-10536","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-10536","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-08","epss":0.00598,"percentile":0.46964}],"risk":0.5621200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation."},"relatedVulnerabilities":[{"id":"CVE-2026-10536","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-08","epss":0.00598,"percentile":0.46964}],"urls":["https://curl.se/docs/CVE-2026-10536.html","https://curl.se/docs/CVE-2026-10536.json","https://hackerone.com/reports/3751697"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application\nconfigures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or\n`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and\nfinally terminates the handle with `curl_easy_cleanup()`. During this final\ncleanup phase, libcurl attempts to access and modify an internal structure\nthat was already freed during the reset operation."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11972","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.561275,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."},"relatedVulnerabilities":[{"id":"CVE-2026-11972","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11972","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.561275,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."},"relatedVulnerabilities":[{"id":"CVE-2026-11972","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11972","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.561275,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."},"relatedVulnerabilities":[{"id":"CVE-2026-11972","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11972","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.561275,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."},"relatedVulnerabilities":[{"id":"CVE-2026-11972","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."}]},{"artifact":{"id":"6f138bead18d0d6b","cpes":["cpe:2.3:a:libaom3:libaom3:3.6.0-1\\+deb12u3:*:*:*:*:*:*:*"],"name":"libaom3","purl":"pkg:deb/debian/libaom3@3.6.0-1%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=aom","type":"deb","version":"3.6.0-1+deb12u3","language":"","licenses":["BSD-2-Clause","BSD-2-clause","BSD-3-clause","Expat","ISC","public-domain-md5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libaom3/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libaom3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libaom3:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libaom3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"aom"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-39616","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"aom","version":"3.6.0-1+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-39616","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39616","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-39616","date":"2026-10-08","epss":0.00738,"percentile":0.53126}],"risk":0.5535,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-39616","description":"AOMedia v3.0.0 to v3.5.0 was discovered to contain an invalid read memory access via the component assign_frame_buffer_p in av1/common/av1_common_int.h."},"relatedVulnerabilities":[{"id":"CVE-2023-39616","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39616","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-39616","date":"2026-10-08","epss":0.00738,"percentile":0.53126}],"urls":["https://bugs.chromium.org/p/aomedia/issues/detail?id=3372#c3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-39616","description":"AOMedia v3.0.0 to v3.5.0 was discovered to contain an invalid read memory access via the component assign_frame_buffer_p in av1/common/av1_common_int.h."}]},{"artifact":{"id":"ac9f96c95674631f","cpes":["cpe:2.3:a:libopenexr-3-1-30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1-30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-3-1-30","purl":"pkg:deb/debian/libopenexr-3-1-30@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-3-1-30/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-3-1-30/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34545","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-34545","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34545","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34545","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34545","cwe":"CWE-1284","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-34545","date":"2026-10-08","epss":0.00745,"percentile":0.53375}],"risk":0.5513,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34545","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.7, an attacker providing a crafted .exr file with HTJ2K compression and a channel width of 32768 can write controlled data beyond the output heap buffer in any application that decodes EXR images. The write primitive is 2 bytes per overflow iteration or 4 bytes (by another path), repeating for each additional pixel past the overflow point. In this context, a heap write overflow can lead to remote code execution on systems. This issue has been patched in version 3.4.7."},"relatedVulnerabilities":[{"id":"CVE-2026-34545","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34545","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34545","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34545","cwe":"CWE-1284","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-34545","date":"2026-10-08","epss":0.00745,"percentile":0.53375}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/3827998f5c041d6a94c6af24bbb363daa669e4b3","https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.7","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-ghfj-fx47-wg97","https://access.redhat.com/security/cve/CVE-2026-34545","https://bugzilla.redhat.com/show_bug.cgi?id=2454139","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34545.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34545","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.7, an attacker providing a crafted .exr file with HTJ2K compression and a channel width of 32768 can write controlled data beyond the output heap buffer in any application that decodes EXR images. The write primitive is 2 bytes per overflow iteration or 4 bytes (by another path), repeating for each additional pixel past the overflow point. In this context, a heap write overflow can lead to remote code execution on systems. This issue has been patched in version 3.4.7."}]},{"artifact":{"id":"229cdd73859abf63","cpes":["cpe:2.3:a:libopenexr-dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-dev","purl":"pkg:deb/debian/libopenexr-dev@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.list"}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34545","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-34545","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34545","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34545","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34545","cwe":"CWE-1284","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-34545","date":"2026-10-08","epss":0.00745,"percentile":0.53375}],"risk":0.5513,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34545","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.7, an attacker providing a crafted .exr file with HTJ2K compression and a channel width of 32768 can write controlled data beyond the output heap buffer in any application that decodes EXR images. The write primitive is 2 bytes per overflow iteration or 4 bytes (by another path), repeating for each additional pixel past the overflow point. In this context, a heap write overflow can lead to remote code execution on systems. This issue has been patched in version 3.4.7."},"relatedVulnerabilities":[{"id":"CVE-2026-34545","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34545","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34545","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34545","cwe":"CWE-1284","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-34545","date":"2026-10-08","epss":0.00745,"percentile":0.53375}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/3827998f5c041d6a94c6af24bbb363daa669e4b3","https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.7","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-ghfj-fx47-wg97","https://access.redhat.com/security/cve/CVE-2026-34545","https://bugzilla.redhat.com/show_bug.cgi?id=2454139","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34545.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34545","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.7, an attacker providing a crafted .exr file with HTJ2K compression and a channel width of 32768 can write controlled data beyond the output heap buffer in any application that decodes EXR images. The write primitive is 2 bytes per overflow iteration or 4 bytes (by another path), repeating for each additional pixel past the overflow point. In this context, a heap write overflow can lead to remote code execution on systems. This issue has been patched in version 3.4.7."}]},{"artifact":{"id":"aff0821f961165d7","cpes":["cpe:2.3:a:libncurses-dev:libncurses-dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncurses-dev:libncurses_dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncurses_dev:libncurses-dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncurses_dev:libncurses_dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncurses:libncurses-dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncurses:libncurses_dev:6.4-4:*:*:*:*:*:*:*"],"name":"libncurses-dev","purl":"pkg:deb/debian/libncurses-dev@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libncurses-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libncurses-dev:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libncurses-dev/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-50495","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"risk":0.54855,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."},"relatedVulnerabilities":[{"id":"CVE-2023-50495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."}]},{"artifact":{"id":"9d88525499877381","cpes":["cpe:2.3:a:libncurses5-dev:libncurses5-dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncurses5-dev:libncurses5_dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncurses5_dev:libncurses5-dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncurses5_dev:libncurses5_dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncurses5:libncurses5-dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncurses5:libncurses5_dev:6.4-4:*:*:*:*:*:*:*"],"name":"libncurses5-dev","purl":"pkg:deb/debian/libncurses5-dev@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libncurses5-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libncurses5-dev:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libncurses5-dev/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-50495","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"risk":0.54855,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."},"relatedVulnerabilities":[{"id":"CVE-2023-50495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."}]},{"artifact":{"id":"45ca0a14113d5717","cpes":["cpe:2.3:a:libncurses6:libncurses6:6.4-4:*:*:*:*:*:*:*"],"name":"libncurses6","purl":"pkg:deb/debian/libncurses6@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libncurses6:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libncurses6:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libncurses6/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-50495","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"risk":0.54855,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."},"relatedVulnerabilities":[{"id":"CVE-2023-50495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."}]},{"artifact":{"id":"b44a1de54805a03c","cpes":["cpe:2.3:a:libncursesw5-dev:libncursesw5-dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncursesw5-dev:libncursesw5_dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncursesw5_dev:libncursesw5-dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncursesw5_dev:libncursesw5_dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncursesw5:libncursesw5-dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncursesw5:libncursesw5_dev:6.4-4:*:*:*:*:*:*:*"],"name":"libncursesw5-dev","purl":"pkg:deb/debian/libncursesw5-dev@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libncursesw5-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libncursesw5-dev:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libncursesw5-dev/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-50495","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"risk":0.54855,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."},"relatedVulnerabilities":[{"id":"CVE-2023-50495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."}]},{"artifact":{"id":"2b3a2ba7a41a0529","cpes":["cpe:2.3:a:libncursesw6:libncursesw6:6.4-4:*:*:*:*:*:*:*"],"name":"libncursesw6","purl":"pkg:deb/debian/libncursesw6@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libncursesw6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-50495","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"risk":0.54855,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."},"relatedVulnerabilities":[{"id":"CVE-2023-50495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."}]},{"artifact":{"id":"a6231fb14cfeaaac","cpes":["cpe:2.3:a:libtinfo6:libtinfo6:6.4-4:*:*:*:*:*:*:*"],"name":"libtinfo6","purl":"pkg:deb/debian/libtinfo6@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libtinfo6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-50495","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"risk":0.54855,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."},"relatedVulnerabilities":[{"id":"CVE-2023-50495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."}]},{"artifact":{"id":"ec73073218fd031a","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.4-4:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/debian/ncurses-base@6.4-4?arch=all&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-50495","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"risk":0.54855,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."},"relatedVulnerabilities":[{"id":"CVE-2023-50495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."}]},{"artifact":{"id":"c5b18ac268f2ccdf","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.4-4:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/debian/ncurses-bin@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-50495","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"risk":0.54855,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."},"relatedVulnerabilities":[{"id":"CVE-2023-50495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."}]},{"artifact":{"id":"be12828c4e3c1a16","cpes":["cpe:2.3:a:libcairo-gobject2:libcairo-gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo-gobject2:libcairo_gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_gobject2:libcairo-gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_gobject2:libcairo_gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo:libcairo-gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo:libcairo_gobject2:1.16.0-7:*:*:*:*:*:*:*"],"name":"libcairo-gobject2","purl":"pkg:deb/debian/libcairo-gobject2@1.16.0-7?arch=amd64&distro=debian-12.15&upstream=cairo","type":"deb","version":"1.16.0-7","language":"","licenses":["sha256:408fb9e704e875cd42d432e7c9b3b378f568e3c89db2b5c5ef3d11c025319574"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcairo-gobject2/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libcairo-gobject2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcairo-gobject2:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libcairo-gobject2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cairo"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-7475","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cairo","version":"1.16.0-7"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2017-7475","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-7475","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-7475","date":"2026-10-08","epss":0.01824,"percentile":0.78145}],"risk":0.5471999999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-7475","description":"Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash."},"relatedVulnerabilities":[{"id":"CVE-2017-7475","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-7475","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-7475","date":"2026-10-08","epss":0.01824,"percentile":0.78145}],"urls":["http://seclists.org/oss-sec/2017/q2/151","https://bugs.freedesktop.org/show_bug.cgi?id=100763","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7475","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-7475","description":"Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash."}]},{"artifact":{"id":"d150a0acc96f6751","cpes":["cpe:2.3:a:libcairo-script-interpreter2:libcairo-script-interpreter2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo-script-interpreter2:libcairo_script_interpreter2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_script_interpreter2:libcairo-script-interpreter2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_script_interpreter2:libcairo_script_interpreter2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo-script:libcairo-script-interpreter2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo-script:libcairo_script_interpreter2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_script:libcairo-script-interpreter2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_script:libcairo_script_interpreter2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo:libcairo-script-interpreter2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo:libcairo_script_interpreter2:1.16.0-7:*:*:*:*:*:*:*"],"name":"libcairo-script-interpreter2","purl":"pkg:deb/debian/libcairo-script-interpreter2@1.16.0-7?arch=amd64&distro=debian-12.15&upstream=cairo","type":"deb","version":"1.16.0-7","language":"","licenses":["sha256:408fb9e704e875cd42d432e7c9b3b378f568e3c89db2b5c5ef3d11c025319574"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcairo-script-interpreter2/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libcairo-script-interpreter2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcairo-script-interpreter2:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libcairo-script-interpreter2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cairo"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-7475","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cairo","version":"1.16.0-7"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2017-7475","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-7475","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-7475","date":"2026-10-08","epss":0.01824,"percentile":0.78145}],"risk":0.5471999999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-7475","description":"Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash."},"relatedVulnerabilities":[{"id":"CVE-2017-7475","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-7475","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-7475","date":"2026-10-08","epss":0.01824,"percentile":0.78145}],"urls":["http://seclists.org/oss-sec/2017/q2/151","https://bugs.freedesktop.org/show_bug.cgi?id=100763","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7475","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-7475","description":"Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash."}]},{"artifact":{"id":"28d5ccf8758a4075","cpes":["cpe:2.3:a:libcairo2:libcairo2:1.16.0-7:*:*:*:*:*:*:*"],"name":"libcairo2","purl":"pkg:deb/debian/libcairo2@1.16.0-7?arch=amd64&distro=debian-12.15&upstream=cairo","type":"deb","version":"1.16.0-7","language":"","licenses":["sha256:408fb9e704e875cd42d432e7c9b3b378f568e3c89db2b5c5ef3d11c025319574"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcairo2/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libcairo2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcairo2:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libcairo2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cairo"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-7475","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cairo","version":"1.16.0-7"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2017-7475","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-7475","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-7475","date":"2026-10-08","epss":0.01824,"percentile":0.78145}],"risk":0.5471999999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-7475","description":"Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash."},"relatedVulnerabilities":[{"id":"CVE-2017-7475","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-7475","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-7475","date":"2026-10-08","epss":0.01824,"percentile":0.78145}],"urls":["http://seclists.org/oss-sec/2017/q2/151","https://bugs.freedesktop.org/show_bug.cgi?id=100763","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7475","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-7475","description":"Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash."}]},{"artifact":{"id":"685e5753b38233fa","cpes":["cpe:2.3:a:libcairo2-dev:libcairo2-dev:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo2-dev:libcairo2_dev:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo2_dev:libcairo2-dev:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo2_dev:libcairo2_dev:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo2:libcairo2-dev:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo2:libcairo2_dev:1.16.0-7:*:*:*:*:*:*:*"],"name":"libcairo2-dev","purl":"pkg:deb/debian/libcairo2-dev@1.16.0-7?arch=amd64&distro=debian-12.15&upstream=cairo","type":"deb","version":"1.16.0-7","language":"","licenses":["sha256:408fb9e704e875cd42d432e7c9b3b378f568e3c89db2b5c5ef3d11c025319574"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcairo2-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libcairo2-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcairo2-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libcairo2-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cairo"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-7475","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cairo","version":"1.16.0-7"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2017-7475","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-7475","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-7475","date":"2026-10-08","epss":0.01824,"percentile":0.78145}],"risk":0.5471999999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-7475","description":"Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash."},"relatedVulnerabilities":[{"id":"CVE-2017-7475","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-7475","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-7475","date":"2026-10-08","epss":0.01824,"percentile":0.78145}],"urls":["http://seclists.org/oss-sec/2017/q2/151","https://bugs.freedesktop.org/show_bug.cgi?id=100763","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7475","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-7475","description":"Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash."}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-18924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"risk":0.52852,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process."},"relatedVulnerabilities":[{"id":"CVE-2026-18924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"urls":["https://curl.se/docs/CVE-2026-18924.html","https://curl.se/docs/CVE-2026-18924.json","https://hackerone.com/reports/3916059"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-18924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"risk":0.52852,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process."},"relatedVulnerabilities":[{"id":"CVE-2026-18924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"urls":["https://curl.se/docs/CVE-2026-18924.html","https://curl.se/docs/CVE-2026-18924.json","https://hackerone.com/reports/3916059"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-18924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"risk":0.52852,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process."},"relatedVulnerabilities":[{"id":"CVE-2026-18924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"urls":["https://curl.se/docs/CVE-2026-18924.html","https://curl.se/docs/CVE-2026-18924.json","https://hackerone.com/reports/3916059"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process."}]},{"artifact":{"id":"610d5f28e0c6125d","cpes":["cpe:2.3:a:libcurl4-openssl-dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl-dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4-openssl-dev","purl":"pkg:deb/debian/libcurl4-openssl-dev@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4-openssl-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libcurl4-openssl-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-18924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"risk":0.52852,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process."},"relatedVulnerabilities":[{"id":"CVE-2026-18924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"urls":["https://curl.se/docs/CVE-2026-18924.html","https://curl.se/docs/CVE-2026-18924.json","https://hackerone.com/reports/3916059"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process."}]},{"artifact":{"id":"b280459d31091296","cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*"],"name":"libopenjp2-7","purl":"pkg:deb/debian/libopenjp2-7@2.5.0-2%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=openjpeg2","type":"deb","version":"2.5.0-2+deb12u3","language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjpeg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-6988","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjpeg2","version":"2.5.0-2+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-6988","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-6988","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6988","date":"2026-10-08","epss":0.01724,"percentile":0.76824}],"risk":0.5172,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-6988","description":"An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a denial of service (attempted excessive memory allocation) in opj_calloc in openjp2/opj_malloc.c, when called from opj_tcd_init_tile in openjp2/tcd.c, as demonstrated by the 64-bit opj_decompress."},"relatedVulnerabilities":[{"id":"CVE-2019-6988","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-6988","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6988","date":"2026-10-08","epss":0.01724,"percentile":0.76824}],"urls":["http://www.securityfocus.com/bid/106785","https://github.com/uclouvain/openjpeg/issues/1178"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-6988","description":"An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a denial of service (attempted excessive memory allocation) in opj_calloc in openjp2/opj_malloc.c, when called from opj_tcd_init_tile in openjp2/tcd.c, as demonstrated by the 64-bit opj_decompress."}]},{"artifact":{"id":"29b0a2eb864a8178","cpes":["cpe:2.3:a:libopenjp2-7-dev:libopenjp2-7-dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7-dev:libopenjp2_7_dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7_dev:libopenjp2-7-dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7_dev:libopenjp2_7_dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2-7-dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7_dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7-dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7_dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7-dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7_dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*"],"name":"libopenjp2-7-dev","purl":"pkg:deb/debian/libopenjp2-7-dev@2.5.0-2%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=openjpeg2","type":"deb","version":"2.5.0-2+deb12u3","language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenjp2-7-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenjp2-7-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjpeg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-6988","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjpeg2","version":"2.5.0-2+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-6988","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-6988","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6988","date":"2026-10-08","epss":0.01724,"percentile":0.76824}],"risk":0.5172,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-6988","description":"An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a denial of service (attempted excessive memory allocation) in opj_calloc in openjp2/opj_malloc.c, when called from opj_tcd_init_tile in openjp2/tcd.c, as demonstrated by the 64-bit opj_decompress."},"relatedVulnerabilities":[{"id":"CVE-2019-6988","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-6988","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6988","date":"2026-10-08","epss":0.01724,"percentile":0.76824}],"urls":["http://www.securityfocus.com/bid/106785","https://github.com/uclouvain/openjpeg/issues/1178"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-6988","description":"An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a denial of service (attempted excessive memory allocation) in opj_calloc in openjp2/opj_malloc.c, when called from opj_tcd_init_tile in openjp2/tcd.c, as demonstrated by the 64-bit opj_decompress."}]},{"artifact":{"id":"6dec48f68a6dce02","cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"libheif1","purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","type":"deb","version":"1.15.1-1+deb12u1","language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libheif"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-32882","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-32882","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32882","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-32882","cwe":"CWE-125","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32882","date":"2026-10-08","epss":0.00708,"percentile":0.52011}],"risk":0.51684,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-32882","description":"libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in HeifPixelImage::overlay() in libheif/pixelimage.cc. When compositing an overlay image (iovl) whose child image has a different bit depth for the alpha channel than for the color channels, the function indexes into the alpha plane using the color channel stride (in_stride) instead of the previously retrieved alpha_stride, causing reads past the end of the alpha buffer (up to 3,123 bytes for a 100×50 image with 10-bit color and 8-bit alpha). A crafted HEIF file can exploit this to cause a denial of service (crash) or potentially disclose adjacent heap memory through leaked bytes embedded in the decoded output pixels. This issue has been fixed in versionThis issue has been fixed in version 1.22.0."},"relatedVulnerabilities":[{"id":"CVE-2026-32882","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32882","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-32882","cwe":"CWE-125","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32882","date":"2026-10-08","epss":0.00708,"percentile":0.52011}],"urls":["https://github.com/strukturag/libheif/releases/tag/v1.22.0","https://github.com/strukturag/libheif/security/advisories/GHSA-hg7q-rjr2-8x46","https://access.redhat.com/security/cve/CVE-2026-32882","https://bugzilla.redhat.com/show_bug.cgi?id=2480000","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32882.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32882","description":"libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in HeifPixelImage::overlay() in libheif/pixelimage.cc. When compositing an overlay image (iovl) whose child image has a different bit depth for the alpha channel than for the color channels, the function indexes into the alpha plane using the color channel stride (in_stride) instead of the previously retrieved alpha_stride, causing reads past the end of the alpha buffer (up to 3,123 bytes for a 100×50 image with 10-bit color and 8-bit alpha). A crafted HEIF file can exploit this to cause a denial of service (crash) or potentially disclose adjacent heap memory through leaked bytes embedded in the decoded output pixels. This issue has been fixed in versionThis issue has been fixed in version 1.22.0."}]},{"artifact":{"id":"57bc3e079dc33e92","cpes":["cpe:2.3:a:libbluetooth-dev:libbluetooth-dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth-dev:libbluetooth_dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth_dev:libbluetooth-dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth_dev:libbluetooth_dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth:libbluetooth-dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth:libbluetooth_dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*"],"name":"libbluetooth-dev","purl":"pkg:deb/debian/libbluetooth-dev@5.66-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=bluez","type":"deb","version":"5.66-1+deb12u2","language":"","licenses":["Apache-2.0","BSD-2-clause","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libbluetooth-dev/copyright","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/usr/share/doc/libbluetooth-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbluetooth-dev:amd64.md5sums","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/info/libbluetooth-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bluez"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-51580","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"bluez","version":"5.66-1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-51580","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.7,"impactScore":3.6,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-51580","cwe":"CWE-125","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2023-51580","date":"2026-10-08","epss":0.00956,"percentile":0.60236}],"risk":0.51146,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-51580","description":"BlueZ Audio Profile AVRCP avrcp_parse_attribute_list Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device.  The specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-20852."},"relatedVulnerabilities":[{"id":"CVE-2023-51580","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.7,"impactScore":3.6,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"zdi-disclosures@trendmicro.com","vector":"CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":5.4,"impactScore":4.3,"exploitabilityScore":1.2},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-51580","cwe":"CWE-125","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2023-51580","date":"2026-10-08","epss":0.00956,"percentile":0.60236}],"urls":["https://www.zerodayinitiative.com/advisories/ZDI-23-1903/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-51580","description":"BlueZ Audio Profile AVRCP avrcp_parse_attribute_list Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device.\n\nThe specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-20852."}]},{"artifact":{"id":"818aff19ee069170","cpes":["cpe:2.3:a:libbluetooth3:libbluetooth3:5.66-1\\+deb12u2:*:*:*:*:*:*:*"],"name":"libbluetooth3","purl":"pkg:deb/debian/libbluetooth3@5.66-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=bluez","type":"deb","version":"5.66-1+deb12u2","language":"","licenses":["Apache-2.0","BSD-2-clause","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libbluetooth3/copyright","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/usr/share/doc/libbluetooth3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbluetooth3:amd64.md5sums","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/info/libbluetooth3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bluez"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-51580","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"bluez","version":"5.66-1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-51580","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.7,"impactScore":3.6,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-51580","cwe":"CWE-125","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2023-51580","date":"2026-10-08","epss":0.00956,"percentile":0.60236}],"risk":0.51146,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-51580","description":"BlueZ Audio Profile AVRCP avrcp_parse_attribute_list Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device.  The specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-20852."},"relatedVulnerabilities":[{"id":"CVE-2023-51580","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.7,"impactScore":3.6,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"zdi-disclosures@trendmicro.com","vector":"CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":5.4,"impactScore":4.3,"exploitabilityScore":1.2},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-51580","cwe":"CWE-125","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2023-51580","date":"2026-10-08","epss":0.00956,"percentile":0.60236}],"urls":["https://www.zerodayinitiative.com/advisories/ZDI-23-1903/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-51580","description":"BlueZ Audio Profile AVRCP avrcp_parse_attribute_list Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device.\n\nThe specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-20852."}]},{"artifact":{"id":"6dec48f68a6dce02","cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"libheif1","purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","type":"deb","version":"1.15.1-1+deb12u1","language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libheif"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-50142","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-50142","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-50142","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-50142","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-50142","date":"2026-10-08","epss":0.00655,"percentile":0.49827}],"risk":0.49125,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50142","description":"libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.0, a crafted HEIF sequence accepted by heif_context_read_from_memory() with the msf1 sequence brand can cause unbounded heap allocation. In libheif/sequences/seq_boxes.cc, Box_stsz::parse() applies max_sequence_frames only to variable-size samples, so fixed-size mode accepts an attacker-controlled sample_count without a bound. In libheif/sequences/track.cc, Track::load() also adds current_sample_idx and samples_per_chunk in 32-bit arithmetic, allowing the consistency check to be bypassed by wraparound. The resulting values reach the Chunk::Chunk() allocation path, which can consume gigabytes of memory and crash or stall the process through memory exhaustion. This issue is fixed in version 1.23.0."},"relatedVulnerabilities":[{"id":"CVE-2026-50142","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-50142","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-50142","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-50142","date":"2026-10-08","epss":0.00655,"percentile":0.49827}],"urls":["https://github.com/strukturag/libheif/commit/a6caa38f7a70d66dc9caec2a7bfe20935b32c622","https://github.com/strukturag/libheif/releases/tag/v1.23.0","https://github.com/strukturag/libheif/security/advisories/GHSA-jvmp-j3cw-84mh"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50142","description":"libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.0, a crafted HEIF sequence accepted by heif_context_read_from_memory() with the msf1 sequence brand can cause unbounded heap allocation. In libheif/sequences/seq_boxes.cc, Box_stsz::parse() applies max_sequence_frames only to variable-size samples, so fixed-size mode accepts an attacker-controlled sample_count without a bound. In libheif/sequences/track.cc, Track::load() also adds current_sample_idx and samples_per_chunk in 32-bit arithmetic, allowing the consistency check to be bypassed by wraparound. The resulting values reach the Chunk::Chunk() allocation path, which can consume gigabytes of memory and crash or stall the process through memory exhaustion. This issue is fixed in version 1.23.0."}]},{"artifact":{"id":"35095459163cc193","cpes":["cpe:2.3:a:libtiff-dev:libtiff-dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libtiff-dev:libtiff_dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libtiff_dev:libtiff-dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libtiff_dev:libtiff_dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libtiff:libtiff-dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libtiff:libtiff_dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"name":"libtiff-dev","purl":"pkg:deb/debian/libtiff-dev@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","type":"deb","version":"4.5.0-6+deb12u4","language":"","licenses":["Hylafax"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libtiff-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libtiff-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"tiff"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-52490","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-52490","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-52490","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-52490","date":"2026-10-08","epss":0.0051,"percentile":0.41671}],"risk":0.47940000000000005,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-52490","description":"An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c"},"relatedVulnerabilities":[{"id":"CVE-2026-52490","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-52490","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-52490","date":"2026-10-08","epss":0.0051,"percentile":0.41671}],"urls":["https://gist.github.com/okyfh/122c2d72e991a78c8af80a3af3be8671","https://gitlab.com/libtiff/libtiff/-/work_items/846"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-52490","description":"An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c"}]},{"artifact":{"id":"d41dc3f05b6fab73","cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"name":"libtiff6","purl":"pkg:deb/debian/libtiff6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","type":"deb","version":"4.5.0-6+deb12u4","language":"","licenses":["Hylafax"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"tiff"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-52490","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-52490","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-52490","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-52490","date":"2026-10-08","epss":0.0051,"percentile":0.41671}],"risk":0.47940000000000005,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-52490","description":"An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c"},"relatedVulnerabilities":[{"id":"CVE-2026-52490","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-52490","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-52490","date":"2026-10-08","epss":0.0051,"percentile":0.41671}],"urls":["https://gist.github.com/okyfh/122c2d72e991a78c8af80a3af3be8671","https://gitlab.com/libtiff/libtiff/-/work_items/846"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-52490","description":"An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c"}]},{"artifact":{"id":"05a611224dadb719","cpes":["cpe:2.3:a:libtiffxx6:libtiffxx6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"name":"libtiffxx6","purl":"pkg:deb/debian/libtiffxx6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","type":"deb","version":"4.5.0-6+deb12u4","language":"","licenses":["Hylafax"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiffxx6/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libtiffxx6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiffxx6:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libtiffxx6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"tiff"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-52490","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-52490","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-52490","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-52490","date":"2026-10-08","epss":0.0051,"percentile":0.41671}],"risk":0.47940000000000005,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-52490","description":"An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c"},"relatedVulnerabilities":[{"id":"CVE-2026-52490","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-52490","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-52490","date":"2026-10-08","epss":0.0051,"percentile":0.41671}],"urls":["https://gist.github.com/okyfh/122c2d72e991a78c8af80a3af3be8671","https://gitlab.com/libtiff/libtiff/-/work_items/846"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-52490","description":"An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c"}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15308","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15308","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-08","epss":0.00637,"percentile":0.48908}],"risk":0.47774999999999995,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15308","description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data."},"relatedVulnerabilities":[{"id":"CVE-2026-15308","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-08","epss":0.00637,"percentile":0.48908}],"urls":["https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9","https://github.com/python/cpython/commit/1e7956f1a722df9aabc509c30f8fbdc3a2b4fdc7","https://github.com/python/cpython/commit/785df8f743800661961528970f8598edcd291c14","https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced","https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606","https://github.com/python/cpython/commit/c2390b9376e35a701ed3acc597b8fc87546c9b00","https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd","https://github.com/python/cpython/issues/153030","https://github.com/python/cpython/pull/153031","https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/","http://www.openwall.com/lists/oss-security/2026/07/09/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15308","description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU\ndenial-of-service through repeated unterminated markup declarations when\nprocessing uncontrolled data."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15308","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15308","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-08","epss":0.00637,"percentile":0.48908}],"risk":0.47774999999999995,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15308","description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data."},"relatedVulnerabilities":[{"id":"CVE-2026-15308","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-08","epss":0.00637,"percentile":0.48908}],"urls":["https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9","https://github.com/python/cpython/commit/1e7956f1a722df9aabc509c30f8fbdc3a2b4fdc7","https://github.com/python/cpython/commit/785df8f743800661961528970f8598edcd291c14","https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced","https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606","https://github.com/python/cpython/commit/c2390b9376e35a701ed3acc597b8fc87546c9b00","https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd","https://github.com/python/cpython/issues/153030","https://github.com/python/cpython/pull/153031","https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/","http://www.openwall.com/lists/oss-security/2026/07/09/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15308","description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU\ndenial-of-service through repeated unterminated markup declarations when\nprocessing uncontrolled data."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-15308","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15308","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-08","epss":0.00637,"percentile":0.48908}],"risk":0.47774999999999995,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15308","description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data."},"relatedVulnerabilities":[{"id":"CVE-2026-15308","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-08","epss":0.00637,"percentile":0.48908}],"urls":["https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9","https://github.com/python/cpython/commit/1e7956f1a722df9aabc509c30f8fbdc3a2b4fdc7","https://github.com/python/cpython/commit/785df8f743800661961528970f8598edcd291c14","https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced","https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606","https://github.com/python/cpython/commit/c2390b9376e35a701ed3acc597b8fc87546c9b00","https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd","https://github.com/python/cpython/issues/153030","https://github.com/python/cpython/pull/153031","https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/","http://www.openwall.com/lists/oss-security/2026/07/09/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15308","description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU\ndenial-of-service through repeated unterminated markup declarations when\nprocessing uncontrolled data."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15308","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15308","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-08","epss":0.00637,"percentile":0.48908}],"risk":0.47774999999999995,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15308","description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data."},"relatedVulnerabilities":[{"id":"CVE-2026-15308","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-08","epss":0.00637,"percentile":0.48908}],"urls":["https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9","https://github.com/python/cpython/commit/1e7956f1a722df9aabc509c30f8fbdc3a2b4fdc7","https://github.com/python/cpython/commit/785df8f743800661961528970f8598edcd291c14","https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced","https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606","https://github.com/python/cpython/commit/c2390b9376e35a701ed3acc597b8fc87546c9b00","https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd","https://github.com/python/cpython/issues/153030","https://github.com/python/cpython/pull/153031","https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/","http://www.openwall.com/lists/oss-security/2026/07/09/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15308","description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU\ndenial-of-service through repeated unterminated markup declarations when\nprocessing uncontrolled data."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9669","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-9669","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-9669","date":"2026-10-08","epss":0.00605,"percentile":0.47336}],"risk":0.47492499999999993,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9669","description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data."},"relatedVulnerabilities":[{"id":"CVE-2026-9669","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-9669","date":"2026-10-08","epss":0.00605,"percentile":0.47336}],"urls":["https://github.com/python/cpython/commit/157a5df8cb5d82b33f918a7489e72ce95ceb12b6","https://github.com/python/cpython/commit/1ba6135eae75ad8413413caeeedb56ae72320636","https://github.com/python/cpython/commit/5755d0f083949ff3c5bf3a37e673e24e306b036e","https://github.com/python/cpython/commit/619a12b2e545391dc436b3af79dda22337382a6f","https://github.com/python/cpython/commit/938ec030e90c5e53f1faac6fab1643f14e4f4a79","https://github.com/python/cpython/commit/991e6cf86496718c4ef00b362d640e00cb5c85b2","https://github.com/python/cpython/commit/d3ca26983dfbccdf609f24ff5877dc3118e4702d","https://github.com/python/cpython/issues/150599","https://github.com/python/cpython/pull/150600","https://mail.python.org/archives/list/security-announce@python.org/thread/DBJZETMGUIFK7DVUWMOXHD3Z6IX2QPSX/","http://www.openwall.com/lists/oss-security/2026/06/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9669","description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9669","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-9669","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-9669","date":"2026-10-08","epss":0.00605,"percentile":0.47336}],"risk":0.47492499999999993,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9669","description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data."},"relatedVulnerabilities":[{"id":"CVE-2026-9669","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-9669","date":"2026-10-08","epss":0.00605,"percentile":0.47336}],"urls":["https://github.com/python/cpython/commit/157a5df8cb5d82b33f918a7489e72ce95ceb12b6","https://github.com/python/cpython/commit/1ba6135eae75ad8413413caeeedb56ae72320636","https://github.com/python/cpython/commit/5755d0f083949ff3c5bf3a37e673e24e306b036e","https://github.com/python/cpython/commit/619a12b2e545391dc436b3af79dda22337382a6f","https://github.com/python/cpython/commit/938ec030e90c5e53f1faac6fab1643f14e4f4a79","https://github.com/python/cpython/commit/991e6cf86496718c4ef00b362d640e00cb5c85b2","https://github.com/python/cpython/commit/d3ca26983dfbccdf609f24ff5877dc3118e4702d","https://github.com/python/cpython/issues/150599","https://github.com/python/cpython/pull/150600","https://mail.python.org/archives/list/security-announce@python.org/thread/DBJZETMGUIFK7DVUWMOXHD3Z6IX2QPSX/","http://www.openwall.com/lists/oss-security/2026/06/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9669","description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-9669","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-9669","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-9669","date":"2026-10-08","epss":0.00605,"percentile":0.47336}],"risk":0.47492499999999993,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9669","description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data."},"relatedVulnerabilities":[{"id":"CVE-2026-9669","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-9669","date":"2026-10-08","epss":0.00605,"percentile":0.47336}],"urls":["https://github.com/python/cpython/commit/157a5df8cb5d82b33f918a7489e72ce95ceb12b6","https://github.com/python/cpython/commit/1ba6135eae75ad8413413caeeedb56ae72320636","https://github.com/python/cpython/commit/5755d0f083949ff3c5bf3a37e673e24e306b036e","https://github.com/python/cpython/commit/619a12b2e545391dc436b3af79dda22337382a6f","https://github.com/python/cpython/commit/938ec030e90c5e53f1faac6fab1643f14e4f4a79","https://github.com/python/cpython/commit/991e6cf86496718c4ef00b362d640e00cb5c85b2","https://github.com/python/cpython/commit/d3ca26983dfbccdf609f24ff5877dc3118e4702d","https://github.com/python/cpython/issues/150599","https://github.com/python/cpython/pull/150600","https://mail.python.org/archives/list/security-announce@python.org/thread/DBJZETMGUIFK7DVUWMOXHD3Z6IX2QPSX/","http://www.openwall.com/lists/oss-security/2026/06/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9669","description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9669","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-9669","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-9669","date":"2026-10-08","epss":0.00605,"percentile":0.47336}],"risk":0.47492499999999993,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9669","description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data."},"relatedVulnerabilities":[{"id":"CVE-2026-9669","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-9669","date":"2026-10-08","epss":0.00605,"percentile":0.47336}],"urls":["https://github.com/python/cpython/commit/157a5df8cb5d82b33f918a7489e72ce95ceb12b6","https://github.com/python/cpython/commit/1ba6135eae75ad8413413caeeedb56ae72320636","https://github.com/python/cpython/commit/5755d0f083949ff3c5bf3a37e673e24e306b036e","https://github.com/python/cpython/commit/619a12b2e545391dc436b3af79dda22337382a6f","https://github.com/python/cpython/commit/938ec030e90c5e53f1faac6fab1643f14e4f4a79","https://github.com/python/cpython/commit/991e6cf86496718c4ef00b362d640e00cb5c85b2","https://github.com/python/cpython/commit/d3ca26983dfbccdf609f24ff5877dc3118e4702d","https://github.com/python/cpython/issues/150599","https://github.com/python/cpython/pull/150600","https://mail.python.org/archives/list/security-announce@python.org/thread/DBJZETMGUIFK7DVUWMOXHD3Z6IX2QPSX/","http://www.openwall.com/lists/oss-security/2026/06/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9669","description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data."}]},{"artifact":{"id":"797a08aa0e653cc1","cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*"],"name":"libperl5.36","purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u4","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.47250000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.  Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.  Formatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"1abbc10047509a69","cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u4?arch=amd64&distro=debian-12.15","type":"deb","version":"5.36.0-7+deb12u4","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.47250000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.  Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.  Formatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"5a32e7d822381d5b","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u4","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.47250000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.  Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.  Formatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"ab813d7f861aa617","cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*"],"name":"perl-modules-5.36","purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u4?arch=all&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u4","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.47250000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.  Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.  Formatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"d82af4e74abd89bc","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","type":"deb","version":"1:9.2p1-2+deb12u10","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60000","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-60000","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60000","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60000","date":"2026-10-08","epss":0.00618,"percentile":0.47997}],"risk":0.4635,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60000","description":"sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication."},"relatedVulnerabilities":[{"id":"CVE-2026-60000","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60000","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60000","date":"2026-10-08","epss":0.00618,"percentile":0.47997}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60000","description":"sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication."}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8927","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8927","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"risk":0.4525,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`."},"relatedVulnerabilities":[{"id":"CVE-2026-8927","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"urls":["https://curl.se/docs/CVE-2026-8927.html","https://curl.se/docs/CVE-2026-8927.json","https://hackerone.com/reports/3744543"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8927","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8927","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"risk":0.4525,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`."},"relatedVulnerabilities":[{"id":"CVE-2026-8927","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"urls":["https://curl.se/docs/CVE-2026-8927.html","https://curl.se/docs/CVE-2026-8927.json","https://hackerone.com/reports/3744543"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8927","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8927","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"risk":0.4525,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`."},"relatedVulnerabilities":[{"id":"CVE-2026-8927","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"urls":["https://curl.se/docs/CVE-2026-8927.html","https://curl.se/docs/CVE-2026-8927.json","https://hackerone.com/reports/3744543"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`."}]},{"artifact":{"id":"610d5f28e0c6125d","cpes":["cpe:2.3:a:libcurl4-openssl-dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl-dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4-openssl-dev","purl":"pkg:deb/debian/libcurl4-openssl-dev@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4-openssl-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libcurl4-openssl-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8927","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8927","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"risk":0.4525,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`."},"relatedVulnerabilities":[{"id":"CVE-2026-8927","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"urls":["https://curl.se/docs/CVE-2026-8927.html","https://curl.se/docs/CVE-2026-8927.json","https://hackerone.com/reports/3744543"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69534","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-69534","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-69534","cwe":"CWE-617","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-69534","date":"2026-10-08","epss":0.00589,"percentile":0.46465}],"risk":0.44175000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69534","description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions."},"relatedVulnerabilities":[{"id":"CVE-2025-69534","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-69534","cwe":"CWE-617","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-69534","date":"2026-10-08","epss":0.00589,"percentile":0.46465}],"urls":["https://github.com/Python-Markdown/markdown","https://github.com/Python-Markdown/markdown/actions/runs/15736122892","https://github.com/Python-Markdown/markdown/issues/1534","http://www.openwall.com/lists/oss-security/2026/03/06/4","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:13508","https://access.redhat.com/errata/RHSA-2026:13512","https://access.redhat.com/errata/RHSA-2026:13826","https://access.redhat.com/errata/RHSA-2026:14835","https://access.redhat.com/errata/RHSA-2026:14873","https://access.redhat.com/errata/RHSA-2026:14874","https://access.redhat.com/errata/RHSA-2026:19155","https://access.redhat.com/errata/RHSA-2026:19366","https://access.redhat.com/errata/RHSA-2026:20674","https://access.redhat.com/errata/RHSA-2026:20676","https://access.redhat.com/errata/RHSA-2026:20677","https://access.redhat.com/errata/RHSA-2026:9742","https://access.redhat.com/security/cve/CVE-2025-69534","https://bugzilla.redhat.com/show_bug.cgi?id=2444839","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69534.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69534","description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69534","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-69534","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-69534","cwe":"CWE-617","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-69534","date":"2026-10-08","epss":0.00589,"percentile":0.46465}],"risk":0.44175000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69534","description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions."},"relatedVulnerabilities":[{"id":"CVE-2025-69534","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-69534","cwe":"CWE-617","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-69534","date":"2026-10-08","epss":0.00589,"percentile":0.46465}],"urls":["https://github.com/Python-Markdown/markdown","https://github.com/Python-Markdown/markdown/actions/runs/15736122892","https://github.com/Python-Markdown/markdown/issues/1534","http://www.openwall.com/lists/oss-security/2026/03/06/4","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:13508","https://access.redhat.com/errata/RHSA-2026:13512","https://access.redhat.com/errata/RHSA-2026:13826","https://access.redhat.com/errata/RHSA-2026:14835","https://access.redhat.com/errata/RHSA-2026:14873","https://access.redhat.com/errata/RHSA-2026:14874","https://access.redhat.com/errata/RHSA-2026:19155","https://access.redhat.com/errata/RHSA-2026:19366","https://access.redhat.com/errata/RHSA-2026:20674","https://access.redhat.com/errata/RHSA-2026:20676","https://access.redhat.com/errata/RHSA-2026:20677","https://access.redhat.com/errata/RHSA-2026:9742","https://access.redhat.com/security/cve/CVE-2025-69534","https://bugzilla.redhat.com/show_bug.cgi?id=2444839","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69534.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69534","description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-69534","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-69534","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-69534","cwe":"CWE-617","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-69534","date":"2026-10-08","epss":0.00589,"percentile":0.46465}],"risk":0.44175000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69534","description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions."},"relatedVulnerabilities":[{"id":"CVE-2025-69534","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-69534","cwe":"CWE-617","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-69534","date":"2026-10-08","epss":0.00589,"percentile":0.46465}],"urls":["https://github.com/Python-Markdown/markdown","https://github.com/Python-Markdown/markdown/actions/runs/15736122892","https://github.com/Python-Markdown/markdown/issues/1534","http://www.openwall.com/lists/oss-security/2026/03/06/4","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:13508","https://access.redhat.com/errata/RHSA-2026:13512","https://access.redhat.com/errata/RHSA-2026:13826","https://access.redhat.com/errata/RHSA-2026:14835","https://access.redhat.com/errata/RHSA-2026:14873","https://access.redhat.com/errata/RHSA-2026:14874","https://access.redhat.com/errata/RHSA-2026:19155","https://access.redhat.com/errata/RHSA-2026:19366","https://access.redhat.com/errata/RHSA-2026:20674","https://access.redhat.com/errata/RHSA-2026:20676","https://access.redhat.com/errata/RHSA-2026:20677","https://access.redhat.com/errata/RHSA-2026:9742","https://access.redhat.com/security/cve/CVE-2025-69534","https://bugzilla.redhat.com/show_bug.cgi?id=2444839","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69534.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69534","description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69534","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-69534","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-69534","cwe":"CWE-617","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-69534","date":"2026-10-08","epss":0.00589,"percentile":0.46465}],"risk":0.44175000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69534","description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions."},"relatedVulnerabilities":[{"id":"CVE-2025-69534","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-69534","cwe":"CWE-617","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-69534","date":"2026-10-08","epss":0.00589,"percentile":0.46465}],"urls":["https://github.com/Python-Markdown/markdown","https://github.com/Python-Markdown/markdown/actions/runs/15736122892","https://github.com/Python-Markdown/markdown/issues/1534","http://www.openwall.com/lists/oss-security/2026/03/06/4","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:13508","https://access.redhat.com/errata/RHSA-2026:13512","https://access.redhat.com/errata/RHSA-2026:13826","https://access.redhat.com/errata/RHSA-2026:14835","https://access.redhat.com/errata/RHSA-2026:14873","https://access.redhat.com/errata/RHSA-2026:14874","https://access.redhat.com/errata/RHSA-2026:19155","https://access.redhat.com/errata/RHSA-2026:19366","https://access.redhat.com/errata/RHSA-2026:20674","https://access.redhat.com/errata/RHSA-2026:20676","https://access.redhat.com/errata/RHSA-2026:20677","https://access.redhat.com/errata/RHSA-2026:9742","https://access.redhat.com/security/cve/CVE-2025-69534","https://bugzilla.redhat.com/show_bug.cgi?id=2444839","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69534.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69534","description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions."}]},{"artifact":{"id":"57bc3e079dc33e92","cpes":["cpe:2.3:a:libbluetooth-dev:libbluetooth-dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth-dev:libbluetooth_dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth_dev:libbluetooth-dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth_dev:libbluetooth_dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth:libbluetooth-dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth:libbluetooth_dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*"],"name":"libbluetooth-dev","purl":"pkg:deb/debian/libbluetooth-dev@5.66-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=bluez","type":"deb","version":"5.66-1+deb12u2","language":"","licenses":["Apache-2.0","BSD-2-clause","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libbluetooth-dev/copyright","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/usr/share/doc/libbluetooth-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbluetooth-dev:amd64.md5sums","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/info/libbluetooth-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bluez"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-51589","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"bluez","version":"5.66-1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-51589","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.7,"impactScore":3.6,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-51589","cwe":"CWE-125","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2023-51589","date":"2026-10-08","epss":0.00824,"percentile":0.56057}],"risk":0.44084000000000007,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-51589","description":"BlueZ Audio Profile AVRCP parse_media_element Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device.  The specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-20853."},"relatedVulnerabilities":[{"id":"CVE-2023-51589","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.7,"impactScore":3.6,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"zdi-disclosures@trendmicro.com","vector":"CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":5.4,"impactScore":4.3,"exploitabilityScore":1.2},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-51589","cwe":"CWE-125","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2023-51589","date":"2026-10-08","epss":0.00824,"percentile":0.56057}],"urls":["https://www.zerodayinitiative.com/advisories/ZDI-23-1904/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-51589","description":"BlueZ Audio Profile AVRCP parse_media_element Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device.\n\nThe specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-20853."}]},{"artifact":{"id":"818aff19ee069170","cpes":["cpe:2.3:a:libbluetooth3:libbluetooth3:5.66-1\\+deb12u2:*:*:*:*:*:*:*"],"name":"libbluetooth3","purl":"pkg:deb/debian/libbluetooth3@5.66-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=bluez","type":"deb","version":"5.66-1+deb12u2","language":"","licenses":["Apache-2.0","BSD-2-clause","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libbluetooth3/copyright","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/usr/share/doc/libbluetooth3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbluetooth3:amd64.md5sums","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/info/libbluetooth3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bluez"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-51589","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"bluez","version":"5.66-1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-51589","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.7,"impactScore":3.6,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-51589","cwe":"CWE-125","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2023-51589","date":"2026-10-08","epss":0.00824,"percentile":0.56057}],"risk":0.44084000000000007,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-51589","description":"BlueZ Audio Profile AVRCP parse_media_element Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device.  The specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-20853."},"relatedVulnerabilities":[{"id":"CVE-2023-51589","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.7,"impactScore":3.6,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"zdi-disclosures@trendmicro.com","vector":"CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":5.4,"impactScore":4.3,"exploitabilityScore":1.2},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-51589","cwe":"CWE-125","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2023-51589","date":"2026-10-08","epss":0.00824,"percentile":0.56057}],"urls":["https://www.zerodayinitiative.com/advisories/ZDI-23-1904/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-51589","description":"BlueZ Audio Profile AVRCP parse_media_element Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device.\n\nThe specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-20853."}]},{"artifact":{"id":"6dec48f68a6dce02","cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"libheif1","purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","type":"deb","version":"1.15.1-1+deb12u1","language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libheif"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-62292","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-62292","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-62292","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-62292","date":"2026-10-08","epss":0.00538,"percentile":0.43499}],"risk":0.43578,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-62292","description":"libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.1, a crafted uncompressed HEIF image using generic zlib unci full-item compression can crash an application that decodes an advertised tile with heif_image_handle_decode_image_tile(). In libheif/codecs/uncompressed/unc_decoder.cc, unc_decoder::fetch_tile_data() computes a large tile offset and unc_decoder::get_compressed_image_data_uncompressed() validates it with range_start_offset plus range_size. For the last advertised tile (4095, 4095), the addition can wrap to zero, bypass the bounds check, and pass an invalid source pointer and a one-terabyte length to memcpy. The observed result is an out-of-bounds read and process crash; opening the file alone does not trigger the issue because tile decoding is required. This issue is fixed in version 1.23.1."},"relatedVulnerabilities":[{"id":"CVE-2026-62292","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-62292","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-62292","date":"2026-10-08","epss":0.00538,"percentile":0.43499}],"urls":["https://github.com/strukturag/libheif/commit/089a809bf6bed1abae102d5e97b6bb8c4f53b515","https://github.com/strukturag/libheif/releases/tag/v1.23.1","https://github.com/strukturag/libheif/security/advisories/GHSA-73p7-m7gg-w2jv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-62292","description":"libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.1, a crafted uncompressed HEIF image using generic zlib unci full-item compression can crash an application that decodes an advertised tile with heif_image_handle_decode_image_tile(). In libheif/codecs/uncompressed/unc_decoder.cc, unc_decoder::fetch_tile_data() computes a large tile offset and unc_decoder::get_compressed_image_data_uncompressed() validates it with range_start_offset plus range_size. For the last advertised tile (4095, 4095), the addition can wrap to zero, bypass the bounds check, and pass an invalid source pointer and a one-terabyte length to memcpy. The observed result is an out-of-bounds read and process crash; opening the file alone does not trigger the issue because tile decoding is required. This issue is fixed in version 1.23.1."}]},{"artifact":{"id":"ac9f96c95674631f","cpes":["cpe:2.3:a:libopenexr-3-1-30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1-30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-3-1-30","purl":"pkg:deb/debian/libopenexr-3-1-30@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-3-1-30/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-3-1-30/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34588","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-34588","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34588","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34588","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34588","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34588","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-34588","date":"2026-10-08","epss":0.00567,"percentile":0.45276}],"risk":0.433755,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34588","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working wavelet pointer with signed 32-bit arithmetic. Because nx, ny, and wcount are int, a crafted EXR file can make this product overflow and wrap. The next channel then decodes from an incorrect address. The wavelet decode path operates in place, so this yields both out-of-bounds reads and out-of-bounds writes. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9."},"relatedVulnerabilities":[{"id":"CVE-2026-34588","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34588","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34588","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34588","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34588","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-34588","date":"2026-10-08","epss":0.00567,"percentile":0.45276}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.2.7","https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.3.9","https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.9","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-588r-cr5c-w6hf","https://access.redhat.com/errata/RHSA-2026:15887","https://access.redhat.com/errata/RHSA-2026:15888","https://access.redhat.com/errata/RHSA-2026:17656","https://access.redhat.com/errata/RHSA-2026:17658","https://access.redhat.com/errata/RHSA-2026:17659","https://access.redhat.com/errata/RHSA-2026:17660","https://access.redhat.com/errata/RHSA-2026:19146","https://access.redhat.com/errata/RHSA-2026:19359","https://access.redhat.com/errata/RHSA-2026:19587","https://access.redhat.com/errata/RHSA-2026:30078","https://access.redhat.com/errata/RHSA-2026:30087","https://access.redhat.com/errata/RHSA-2026:30088","https://access.redhat.com/errata/RHSA-2026:30089","https://access.redhat.com/security/cve/CVE-2026-34588","https://bugzilla.redhat.com/show_bug.cgi?id=2455408","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34588.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34588","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working wavelet pointer with signed 32-bit arithmetic. Because nx, ny, and wcount are int, a crafted EXR file can make this product overflow and wrap. The next channel then decodes from an incorrect address. The wavelet decode path operates in place, so this yields both out-of-bounds reads and out-of-bounds writes. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9."}]},{"artifact":{"id":"229cdd73859abf63","cpes":["cpe:2.3:a:libopenexr-dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-dev","purl":"pkg:deb/debian/libopenexr-dev@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.list"}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34588","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-34588","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34588","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34588","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34588","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34588","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-34588","date":"2026-10-08","epss":0.00567,"percentile":0.45276}],"risk":0.433755,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34588","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working wavelet pointer with signed 32-bit arithmetic. Because nx, ny, and wcount are int, a crafted EXR file can make this product overflow and wrap. The next channel then decodes from an incorrect address. The wavelet decode path operates in place, so this yields both out-of-bounds reads and out-of-bounds writes. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9."},"relatedVulnerabilities":[{"id":"CVE-2026-34588","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34588","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34588","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34588","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34588","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-34588","date":"2026-10-08","epss":0.00567,"percentile":0.45276}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.2.7","https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.3.9","https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.9","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-588r-cr5c-w6hf","https://access.redhat.com/errata/RHSA-2026:15887","https://access.redhat.com/errata/RHSA-2026:15888","https://access.redhat.com/errata/RHSA-2026:17656","https://access.redhat.com/errata/RHSA-2026:17658","https://access.redhat.com/errata/RHSA-2026:17659","https://access.redhat.com/errata/RHSA-2026:17660","https://access.redhat.com/errata/RHSA-2026:19146","https://access.redhat.com/errata/RHSA-2026:19359","https://access.redhat.com/errata/RHSA-2026:19587","https://access.redhat.com/errata/RHSA-2026:30078","https://access.redhat.com/errata/RHSA-2026:30087","https://access.redhat.com/errata/RHSA-2026:30088","https://access.redhat.com/errata/RHSA-2026:30089","https://access.redhat.com/security/cve/CVE-2026-34588","https://bugzilla.redhat.com/show_bug.cgi?id=2455408","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34588.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34588","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working wavelet pointer with signed 32-bit arithmetic. Because nx, ny, and wcount are int, a crafted EXR file can make this product overflow and wrap. The next channel then decodes from an incorrect address. The wavelet decode path operates in place, so this yields both out-of-bounds reads and out-of-bounds writes. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9."}]},{"artifact":{"id":"57bc3e079dc33e92","cpes":["cpe:2.3:a:libbluetooth-dev:libbluetooth-dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth-dev:libbluetooth_dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth_dev:libbluetooth-dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth_dev:libbluetooth_dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth:libbluetooth-dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth:libbluetooth_dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*"],"name":"libbluetooth-dev","purl":"pkg:deb/debian/libbluetooth-dev@5.66-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=bluez","type":"deb","version":"5.66-1+deb12u2","language":"","licenses":["Apache-2.0","BSD-2-clause","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libbluetooth-dev/copyright","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/usr/share/doc/libbluetooth-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbluetooth-dev:amd64.md5sums","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/info/libbluetooth-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bluez"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-51592","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"bluez","version":"5.66-1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-51592","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.7,"impactScore":3.6,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-51592","cwe":"CWE-125","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2023-51592","date":"2026-10-08","epss":0.00808,"percentile":0.55542}],"risk":0.43228000000000005,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-51592","description":"BlueZ Audio Profile AVRCP parse_media_folder Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device.  The specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-20854."},"relatedVulnerabilities":[{"id":"CVE-2023-51592","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.7,"impactScore":3.6,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"zdi-disclosures@trendmicro.com","vector":"CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":5.4,"impactScore":4.3,"exploitabilityScore":1.2},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-51592","cwe":"CWE-125","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2023-51592","date":"2026-10-08","epss":0.00808,"percentile":0.55542}],"urls":["https://www.zerodayinitiative.com/advisories/ZDI-23-1905/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-51592","description":"BlueZ Audio Profile AVRCP parse_media_folder Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device.\n\nThe specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-20854."}]},{"artifact":{"id":"818aff19ee069170","cpes":["cpe:2.3:a:libbluetooth3:libbluetooth3:5.66-1\\+deb12u2:*:*:*:*:*:*:*"],"name":"libbluetooth3","purl":"pkg:deb/debian/libbluetooth3@5.66-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=bluez","type":"deb","version":"5.66-1+deb12u2","language":"","licenses":["Apache-2.0","BSD-2-clause","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libbluetooth3/copyright","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/usr/share/doc/libbluetooth3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbluetooth3:amd64.md5sums","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/info/libbluetooth3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bluez"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-51592","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"bluez","version":"5.66-1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-51592","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.7,"impactScore":3.6,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-51592","cwe":"CWE-125","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2023-51592","date":"2026-10-08","epss":0.00808,"percentile":0.55542}],"risk":0.43228000000000005,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-51592","description":"BlueZ Audio Profile AVRCP parse_media_folder Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device.  The specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-20854."},"relatedVulnerabilities":[{"id":"CVE-2023-51592","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.7,"impactScore":3.6,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"zdi-disclosures@trendmicro.com","vector":"CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":5.4,"impactScore":4.3,"exploitabilityScore":1.2},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-51592","cwe":"CWE-125","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2023-51592","date":"2026-10-08","epss":0.00808,"percentile":0.55542}],"urls":["https://www.zerodayinitiative.com/advisories/ZDI-23-1905/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-51592","description":"BlueZ Audio Profile AVRCP parse_media_folder Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device.\n\nThe specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-20854."}]},{"artifact":{"id":"85369d5a3515d91a","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u4:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=expat","type":"deb","version":"2.5.0-1+deb12u4","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77214","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-77214","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"risk":0.430965,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77214","description":"libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives."},"relatedVulnerabilities":[{"id":"CVE-2026-77214","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"urls":["https://github.com/libexpat/libexpat/commit/13c5f63a7f1c52c2feee3b16a1134d4fb68e9ea0","https://github.com/libexpat/libexpat/pull/1393","https://www.vulncheck.com/advisories/libexpat-heap-buffer-over-read-in-xmlparse-c-via-xml-parsebuffer"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77214","description":"libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives."}]},{"artifact":{"id":"d7331d5da68fa7f9","cpes":["cpe:2.3:a:libexpat1-dev:libexpat1-dev:2.5.0-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1-dev:libexpat1_dev:2.5.0-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1-dev:2.5.0-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1_dev:2.5.0-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1-dev:2.5.0-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1_dev:2.5.0-1\\+deb12u4:*:*:*:*:*:*:*"],"name":"libexpat1-dev","purl":"pkg:deb/debian/libexpat1-dev@2.5.0-1%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=expat","type":"deb","version":"2.5.0-1+deb12u4","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libexpat1-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77214","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-77214","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"risk":0.430965,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77214","description":"libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives."},"relatedVulnerabilities":[{"id":"CVE-2026-77214","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"urls":["https://github.com/libexpat/libexpat/commit/13c5f63a7f1c52c2feee3b16a1134d4fb68e9ea0","https://github.com/libexpat/libexpat/pull/1393","https://www.vulncheck.com/advisories/libexpat-heap-buffer-over-read-in-xmlparse-c-via-xml-parsebuffer"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77214","description":"libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives."}]},{"artifact":{"id":"d82af4e74abd89bc","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","type":"deb","version":"1:9.2p1-2+deb12u10","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-2768","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2007-2768","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-2768","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-2768","date":"2026-10-08","epss":0.08615,"percentile":0.94971}],"risk":0.4307500000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-2768","description":"OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243."},"relatedVulnerabilities":[{"id":"CVE-2007-2768","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-2768","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-2768","date":"2026-10-08","epss":0.08615,"percentile":0.94971}],"urls":["http://archives.neohapsis.com/archives/fulldisclosure/2007-04/0635.html","http://www.osvdb.org/34601","https://security.netapp.com/advisory/ntap-20191107-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-2768","description":"OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243."}]},{"artifact":{"id":"aa527ab8cb576b14","cpes":["cpe:2.3:a:gzip:gzip:1.12-1:*:*:*:*:*:*:*"],"name":"gzip","purl":"pkg:deb/debian/gzip@1.12-1?arch=amd64&distro=debian-12.15","type":"deb","version":"1.12-1","language":"","licenses":["FSF-manpages","GFDL-1.3+-no-invariant","GFDL-3","GPL-3","GPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gzip/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/gzip/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/gzip.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.list","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/gzip.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-41992","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gzip","version":"1.12-1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-41992","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41992","cwe":"CWE-126","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-41992","date":"2026-10-08","epss":0.00564,"percentile":0.4513}],"risk":0.42300000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-41992","description":"GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation. By decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer.  This issue has been fixed in commits 63dbf6b3b9e6e781df1a6a64e609b10e23969681 and e7378c2d421be6a286922374425680bbe9ad8b7d."},"relatedVulnerabilities":[{"id":"CVE-2026-41992","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41992","cwe":"CWE-126","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-41992","date":"2026-10-08","epss":0.00564,"percentile":0.4513}],"urls":["https://cert.pl/en/posts/2026/04/CVE-2026-41991/","https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=63dbf6b3b9e6e781df1a6a64e609b10e23969681","https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=e7378c2d421be6a286922374425680bbe9ad8b7d","https://www.gnu.org/software/gzip/","http://www.openwall.com/lists/oss-security/2026/08/23/1","http://www.openwall.com/lists/oss-security/2026/08/25/1","http://www.openwall.com/lists/oss-security/2026/08/27/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41992","description":"GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation.\nBy decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer.\n\nThis issue has been fixed in commits 63dbf6b3b9e6e781df1a6a64e609b10e23969681 and e7378c2d421be6a286922374425680bbe9ad8b7d."}]},{"artifact":{"id":"acc529981c64331f","cpes":["cpe:2.3:a:patch:patch:2.7.6-7:*:*:*:*:*:*:*"],"name":"patch","purl":"pkg:deb/debian/patch@2.7.6-7?arch=amd64&distro=debian-12.15","type":"deb","version":"2.7.6-7","language":"","licenses":["sha256:8c70d7b0af209abe627c97cd21883931b891c820d0a4affcc10b789a23538a0d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/patch/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/patch/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/patch.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/patch.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-6951","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"patch","version":"2.7.6-7"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-6951","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-6951","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6951","date":"2026-10-08","epss":0.08359,"percentile":0.94832}],"risk":0.41795,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-6951","description":"An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_type function in pch.c, aka a \"mangled rename\" issue."},"relatedVulnerabilities":[{"id":"CVE-2018-6951","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-6951","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6951","date":"2026-10-08","epss":0.08359,"percentile":0.94832}],"urls":["http://www.securityfocus.com/bid/103044","https://git.savannah.gnu.org/cgit/patch.git/commit/?id=f290f48a621867084884bfff87f8093c15195e6a","https://savannah.gnu.org/bugs/index.php?53132","https://security.gentoo.org/glsa/201904-17","https://usn.ubuntu.com/3624-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-6951","description":"An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_type function in pch.c, aka a \"mangled rename\" issue."}]},{"artifact":{"id":"acc529981c64331f","cpes":["cpe:2.3:a:patch:patch:2.7.6-7:*:*:*:*:*:*:*"],"name":"patch","purl":"pkg:deb/debian/patch@2.7.6-7?arch=amd64&distro=debian-12.15","type":"deb","version":"2.7.6-7","language":"","licenses":["sha256:8c70d7b0af209abe627c97cd21883931b891c820d0a4affcc10b789a23538a0d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/patch/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/patch/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/patch.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/patch.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-6952","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"patch","version":"2.7.6-7"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-6952","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-6952","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6952","date":"2026-10-08","epss":0.0819,"percentile":0.94738}],"risk":0.40950000000000003,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-6952","description":"A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6."},"relatedVulnerabilities":[{"id":"CVE-2018-6952","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-6952","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6952","date":"2026-10-08","epss":0.0819,"percentile":0.94738}],"urls":["http://www.securityfocus.com/bid/103047","https://access.redhat.com/errata/RHSA-2019:2033","https://savannah.gnu.org/bugs/index.php?53133","https://security.gentoo.org/glsa/201904-17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-6952","description":"A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6."}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-6253","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6253","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6253","date":"2026-10-08","epss":0.0075,"percentile":0.53553}],"risk":0.40875,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6253","description":"curl might erroneously pass on credentials for a first proxy to a second proxy.  This can happen when the following conditions are true:  1. curl is setup to use specific different proxies for different URL schemes 2. the first proxy needs credentials 3. the second proxy uses no credentials 4. while using the first proxy (using say `http://`), curl is asked to follow    a redirect to a URL using another scheme (say `https://`), accessed using a    second, different, proxy"},"relatedVulnerabilities":[{"id":"CVE-2026-6253","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6253","date":"2026-10-08","epss":0.0075,"percentile":0.53553}],"urls":["https://curl.se/docs/CVE-2026-6253.html","https://curl.se/docs/CVE-2026-6253.json","https://hackerone.com/reports/3669637","http://www.openwall.com/lists/oss-security/2026/04/29/11"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6253","description":"curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy"}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6253","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6253","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6253","date":"2026-10-08","epss":0.0075,"percentile":0.53553}],"risk":0.40875,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6253","description":"curl might erroneously pass on credentials for a first proxy to a second proxy.  This can happen when the following conditions are true:  1. curl is setup to use specific different proxies for different URL schemes 2. the first proxy needs credentials 3. the second proxy uses no credentials 4. while using the first proxy (using say `http://`), curl is asked to follow    a redirect to a URL using another scheme (say `https://`), accessed using a    second, different, proxy"},"relatedVulnerabilities":[{"id":"CVE-2026-6253","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6253","date":"2026-10-08","epss":0.0075,"percentile":0.53553}],"urls":["https://curl.se/docs/CVE-2026-6253.html","https://curl.se/docs/CVE-2026-6253.json","https://hackerone.com/reports/3669637","http://www.openwall.com/lists/oss-security/2026/04/29/11"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6253","description":"curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy"}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6253","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6253","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6253","date":"2026-10-08","epss":0.0075,"percentile":0.53553}],"risk":0.40875,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6253","description":"curl might erroneously pass on credentials for a first proxy to a second proxy.  This can happen when the following conditions are true:  1. curl is setup to use specific different proxies for different URL schemes 2. the first proxy needs credentials 3. the second proxy uses no credentials 4. while using the first proxy (using say `http://`), curl is asked to follow    a redirect to a URL using another scheme (say `https://`), accessed using a    second, different, proxy"},"relatedVulnerabilities":[{"id":"CVE-2026-6253","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6253","date":"2026-10-08","epss":0.0075,"percentile":0.53553}],"urls":["https://curl.se/docs/CVE-2026-6253.html","https://curl.se/docs/CVE-2026-6253.json","https://hackerone.com/reports/3669637","http://www.openwall.com/lists/oss-security/2026/04/29/11"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6253","description":"curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy"}]},{"artifact":{"id":"610d5f28e0c6125d","cpes":["cpe:2.3:a:libcurl4-openssl-dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl-dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4-openssl-dev","purl":"pkg:deb/debian/libcurl4-openssl-dev@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4-openssl-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libcurl4-openssl-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6253","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6253","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6253","date":"2026-10-08","epss":0.0075,"percentile":0.53553}],"risk":0.40875,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6253","description":"curl might erroneously pass on credentials for a first proxy to a second proxy.  This can happen when the following conditions are true:  1. curl is setup to use specific different proxies for different URL schemes 2. the first proxy needs credentials 3. the second proxy uses no credentials 4. while using the first proxy (using say `http://`), curl is asked to follow    a redirect to a URL using another scheme (say `https://`), accessed using a    second, different, proxy"},"relatedVulnerabilities":[{"id":"CVE-2026-6253","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6253","date":"2026-10-08","epss":0.0075,"percentile":0.53553}],"urls":["https://curl.se/docs/CVE-2026-6253.html","https://curl.se/docs/CVE-2026-6253.json","https://hackerone.com/reports/3669637","http://www.openwall.com/lists/oss-security/2026/04/29/11"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6253","description":"curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy"}]},{"artifact":{"id":"d96162e7206cebef","cpes":["cpe:2.3:a:libdav1d6:libdav1d6:1.0.0-2\\+deb12u1:*:*:*:*:*:*:*"],"name":"libdav1d6","purl":"pkg:deb/debian/libdav1d6@1.0.0-2%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=dav1d","type":"deb","version":"1.0.0-2+deb12u1","language":"","licenses":["BSD-2-clause","ISC","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libdav1d6/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libdav1d6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libdav1d6:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libdav1d6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"dav1d"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-32570","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"dav1d","version":"1.0.0-2+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-32570","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-32570","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-32570","cwe":"CWE-362","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-32570","date":"2026-10-08","epss":0.00743,"percentile":0.53325}],"risk":0.40493500000000004,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-32570","description":"VideoLAN dav1d before 1.2.0 has a thread_task.c race condition that can lead to an application crash, related to dav1d_decode_frame_exit."},"relatedVulnerabilities":[{"id":"CVE-2023-32570","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-32570","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-32570","cwe":"CWE-362","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-32570","date":"2026-10-08","epss":0.00743,"percentile":0.53325}],"urls":["https://code.videolan.org/videolan/dav1d/-/commit/cf617fdae0b9bfabd27282854c8e81450d955efa","https://code.videolan.org/videolan/dav1d/-/tags/1.2.0","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3WGSO7UMOF4MVLQ5H6KIV7OG6ONS377B/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LXZ6CUNJFDJLCFOZHY2TIGMCAEITLCRP/","https://security.gentoo.org/glsa/202310-05"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-32570","description":"VideoLAN dav1d before 1.2.0 has a thread_task.c race condition that can lead to an application crash, related to dav1d_decode_frame_exit."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3276","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3276","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-3276","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.403975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3276","description":"unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms."},"relatedVulnerabilities":[{"id":"CVE-2026-3276","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-3276","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0","https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598","https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f","https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32","https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066","https://github.com/python/cpython/commit/d3ab945af25b28dfe13ac6cb40c124a01b33ce1f","https://github.com/python/cpython/commit/db744c0776c1d5dd11aaa70eff2a6993c408bacc","https://github.com/python/cpython/commit/e322a1857084d521f79f45181b776f62e6acfc2c","https://github.com/python/cpython/issues/149079","https://github.com/python/cpython/pull/149080","https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/","http://www.openwall.com/lists/oss-security/2026/06/03/15"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3276","description":"unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3276","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3276","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-3276","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.403975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3276","description":"unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms."},"relatedVulnerabilities":[{"id":"CVE-2026-3276","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-3276","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0","https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598","https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f","https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32","https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066","https://github.com/python/cpython/commit/d3ab945af25b28dfe13ac6cb40c124a01b33ce1f","https://github.com/python/cpython/commit/db744c0776c1d5dd11aaa70eff2a6993c408bacc","https://github.com/python/cpython/commit/e322a1857084d521f79f45181b776f62e6acfc2c","https://github.com/python/cpython/issues/149079","https://github.com/python/cpython/pull/149080","https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/","http://www.openwall.com/lists/oss-security/2026/06/03/15"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3276","description":"unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-3276","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3276","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-3276","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.403975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3276","description":"unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms."},"relatedVulnerabilities":[{"id":"CVE-2026-3276","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-3276","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0","https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598","https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f","https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32","https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066","https://github.com/python/cpython/commit/d3ab945af25b28dfe13ac6cb40c124a01b33ce1f","https://github.com/python/cpython/commit/db744c0776c1d5dd11aaa70eff2a6993c408bacc","https://github.com/python/cpython/commit/e322a1857084d521f79f45181b776f62e6acfc2c","https://github.com/python/cpython/issues/149079","https://github.com/python/cpython/pull/149080","https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/","http://www.openwall.com/lists/oss-security/2026/06/03/15"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3276","description":"unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3276","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3276","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-3276","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.403975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3276","description":"unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms."},"relatedVulnerabilities":[{"id":"CVE-2026-3276","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-3276","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0","https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598","https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f","https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32","https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066","https://github.com/python/cpython/commit/d3ab945af25b28dfe13ac6cb40c124a01b33ce1f","https://github.com/python/cpython/commit/db744c0776c1d5dd11aaa70eff2a6993c408bacc","https://github.com/python/cpython/commit/e322a1857084d521f79f45181b776f62e6acfc2c","https://github.com/python/cpython/issues/149079","https://github.com/python/cpython/pull/149080","https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/","http://www.openwall.com/lists/oss-security/2026/06/03/15"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3276","description":"unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-17084","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"risk":0.40370000000000006,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables  B.2 or B.3 correctly: the latest Unicode codepoint attributes were used  instead of the specified Unicode 3.2.0. This behavior would cause  mismatches when processing domain names using IDNA 2003 (the \"idna\"  codec) and the in_table_b2() function of the \"stringprep\" module. This  only affects domain names containing characters that were not previously  registered or had their Unicode attributes such as case-folding  behavior updated since Unicode 3.2.0."},"relatedVulnerabilities":[{"id":"CVE-2026-17084","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/69f92ebaec681e9149dfd70fd02d4ed52d2a6296","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/commit/c28b121a4f0b975937c8b5a1b4934bb361d84296","https://github.com/python/cpython/commit/c42790b34f634051750e5da340d17c7da19e4784","https://github.com/python/cpython/commit/d397a4979cfc80a8cd6c73838aa10e9c8cf5ef72","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-17084","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"risk":0.40370000000000006,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables  B.2 or B.3 correctly: the latest Unicode codepoint attributes were used  instead of the specified Unicode 3.2.0. This behavior would cause  mismatches when processing domain names using IDNA 2003 (the \"idna\"  codec) and the in_table_b2() function of the \"stringprep\" module. This  only affects domain names containing characters that were not previously  registered or had their Unicode attributes such as case-folding  behavior updated since Unicode 3.2.0."},"relatedVulnerabilities":[{"id":"CVE-2026-17084","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/69f92ebaec681e9149dfd70fd02d4ed52d2a6296","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/commit/c28b121a4f0b975937c8b5a1b4934bb361d84296","https://github.com/python/cpython/commit/c42790b34f634051750e5da340d17c7da19e4784","https://github.com/python/cpython/commit/d397a4979cfc80a8cd6c73838aa10e9c8cf5ef72","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-17084","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"risk":0.40370000000000006,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables  B.2 or B.3 correctly: the latest Unicode codepoint attributes were used  instead of the specified Unicode 3.2.0. This behavior would cause  mismatches when processing domain names using IDNA 2003 (the \"idna\"  codec) and the in_table_b2() function of the \"stringprep\" module. This  only affects domain names containing characters that were not previously  registered or had their Unicode attributes such as case-folding  behavior updated since Unicode 3.2.0."},"relatedVulnerabilities":[{"id":"CVE-2026-17084","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/69f92ebaec681e9149dfd70fd02d4ed52d2a6296","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/commit/c28b121a4f0b975937c8b5a1b4934bb361d84296","https://github.com/python/cpython/commit/c42790b34f634051750e5da340d17c7da19e4784","https://github.com/python/cpython/commit/d397a4979cfc80a8cd6c73838aa10e9c8cf5ef72","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-17084","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"risk":0.40370000000000006,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables  B.2 or B.3 correctly: the latest Unicode codepoint attributes were used  instead of the specified Unicode 3.2.0. This behavior would cause  mismatches when processing domain names using IDNA 2003 (the \"idna\"  codec) and the in_table_b2() function of the \"stringprep\" module. This  only affects domain names containing characters that were not previously  registered or had their Unicode attributes such as case-folding  behavior updated since Unicode 3.2.0."},"relatedVulnerabilities":[{"id":"CVE-2026-17084","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/69f92ebaec681e9149dfd70fd02d4ed52d2a6296","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/commit/c28b121a4f0b975937c8b5a1b4934bb361d84296","https://github.com/python/cpython/commit/c42790b34f634051750e5da340d17c7da19e4784","https://github.com/python/cpython/commit/d397a4979cfc80a8cd6c73838aa10e9c8cf5ef72","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0."}]},{"artifact":{"id":"f314997677a3aacc","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/debian/imagemagick@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.list"},{"path":"/var/lib/dpkg/info/imagemagick.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.postinst"},{"path":"/var/lib/dpkg/info/imagemagick.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.postrm"},{"path":"/var/lib/dpkg/info/imagemagick.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.preinst"},{"path":"/var/lib/dpkg/info/imagemagick.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-34152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-34152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"risk":0.40055,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."},"relatedVulnerabilities":[{"id":"CVE-2023-34152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"urls":["https://access.redhat.com/security/cve/CVE-2023-34152","https://bugzilla.redhat.com/show_bug.cgi?id=2210659","https://github.com/ImageMagick/ImageMagick/issues/6339","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4UFQJCYJ23HWHNDOVKBHZQ7HCXXL6MM3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V2ZUHZXQ2C3JZYKPW4XHCMVVL467MA2V/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."}]},{"artifact":{"id":"58eb8529873897ef","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/debian/imagemagick-6-common@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-34152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-34152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"risk":0.40055,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."},"relatedVulnerabilities":[{"id":"CVE-2023-34152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"urls":["https://access.redhat.com/security/cve/CVE-2023-34152","https://bugzilla.redhat.com/show_bug.cgi?id=2210659","https://github.com/ImageMagick/ImageMagick/issues/6339","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4UFQJCYJ23HWHNDOVKBHZQ7HCXXL6MM3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V2ZUHZXQ2C3JZYKPW4XHCMVVL467MA2V/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."}]},{"artifact":{"id":"81d27bbb42434f07","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/debian/imagemagick-6.q16@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-34152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-34152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"risk":0.40055,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."},"relatedVulnerabilities":[{"id":"CVE-2023-34152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"urls":["https://access.redhat.com/security/cve/CVE-2023-34152","https://bugzilla.redhat.com/show_bug.cgi?id=2210659","https://github.com/ImageMagick/ImageMagick/issues/6339","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4UFQJCYJ23HWHNDOVKBHZQ7HCXXL6MM3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V2ZUHZXQ2C3JZYKPW4XHCMVVL467MA2V/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."}]},{"artifact":{"id":"4166e52734c45414","cpes":["cpe:2.3:a:libmagickcore-6-arch-config:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6-arch-config:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_arch_config:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_arch_config:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6-arch:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6-arch:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_arch:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_arch:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6-arch-config","purl":"pkg:deb/debian/libmagickcore-6-arch-config@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6-arch-config/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6-arch-config/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6-arch-config:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-arch-config:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-34152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-34152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"risk":0.40055,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."},"relatedVulnerabilities":[{"id":"CVE-2023-34152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"urls":["https://access.redhat.com/security/cve/CVE-2023-34152","https://bugzilla.redhat.com/show_bug.cgi?id=2210659","https://github.com/ImageMagick/ImageMagick/issues/6339","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4UFQJCYJ23HWHNDOVKBHZQ7HCXXL6MM3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V2ZUHZXQ2C3JZYKPW4XHCMVVL467MA2V/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."}]},{"artifact":{"id":"aa218174a16ba41d","cpes":["cpe:2.3:a:libmagickcore-6-headers:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6-headers:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_headers:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_headers:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6-headers","purl":"pkg:deb/debian/libmagickcore-6-headers@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6-headers/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.list"},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.postinst"},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.postrm"},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.preinst"},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-34152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-34152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"risk":0.40055,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."},"relatedVulnerabilities":[{"id":"CVE-2023-34152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"urls":["https://access.redhat.com/security/cve/CVE-2023-34152","https://bugzilla.redhat.com/show_bug.cgi?id=2210659","https://github.com/ImageMagick/ImageMagick/issues/6339","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4UFQJCYJ23HWHNDOVKBHZQ7HCXXL6MM3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V2ZUHZXQ2C3JZYKPW4XHCMVVL467MA2V/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."}]},{"artifact":{"id":"b5cf9ab484b0ba4d","cpes":["cpe:2.3:a:libmagickcore-6.q16-6:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-6:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-6","purl":"pkg:deb/debian/libmagickcore-6.q16-6@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-6/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6.q16-6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-6:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-34152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-34152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"risk":0.40055,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."},"relatedVulnerabilities":[{"id":"CVE-2023-34152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"urls":["https://access.redhat.com/security/cve/CVE-2023-34152","https://bugzilla.redhat.com/show_bug.cgi?id=2210659","https://github.com/ImageMagick/ImageMagick/issues/6339","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4UFQJCYJ23HWHNDOVKBHZQ7HCXXL6MM3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V2ZUHZXQ2C3JZYKPW4XHCMVVL467MA2V/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."}]},{"artifact":{"id":"839820a05a2b8d61","cpes":["cpe:2.3:a:libmagickcore-6.q16-6-extra:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-6-extra:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6_extra:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6_extra:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-6:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-6:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-6-extra","purl":"pkg:deb/debian/libmagickcore-6.q16-6-extra@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-6-extra/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6.q16-6-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-6-extra:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-6-extra:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-34152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-34152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"risk":0.40055,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."},"relatedVulnerabilities":[{"id":"CVE-2023-34152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"urls":["https://access.redhat.com/security/cve/CVE-2023-34152","https://bugzilla.redhat.com/show_bug.cgi?id=2210659","https://github.com/ImageMagick/ImageMagick/issues/6339","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4UFQJCYJ23HWHNDOVKBHZQ7HCXXL6MM3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V2ZUHZXQ2C3JZYKPW4XHCMVVL467MA2V/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."}]},{"artifact":{"id":"6bdab316f776d434","cpes":["cpe:2.3:a:libmagickcore-6.q16-dev:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-dev:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_dev:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_dev:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-dev","purl":"pkg:deb/debian/libmagickcore-6.q16-dev@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6.q16-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-34152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-34152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"risk":0.40055,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."},"relatedVulnerabilities":[{"id":"CVE-2023-34152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"urls":["https://access.redhat.com/security/cve/CVE-2023-34152","https://bugzilla.redhat.com/show_bug.cgi?id=2210659","https://github.com/ImageMagick/ImageMagick/issues/6339","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4UFQJCYJ23HWHNDOVKBHZQ7HCXXL6MM3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V2ZUHZXQ2C3JZYKPW4XHCMVVL467MA2V/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."}]},{"artifact":{"id":"4ecf55d018da7a3a","cpes":["cpe:2.3:a:libmagickcore-dev:libmagickcore-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-dev:libmagickcore_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_dev:libmagickcore-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_dev:libmagickcore_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-dev","purl":"pkg:deb/debian/libmagickcore-dev@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.list"},{"path":"/var/lib/dpkg/info/libmagickcore-dev.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.postinst"},{"path":"/var/lib/dpkg/info/libmagickcore-dev.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.postrm"},{"path":"/var/lib/dpkg/info/libmagickcore-dev.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.preinst"},{"path":"/var/lib/dpkg/info/libmagickcore-dev.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-34152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-34152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"risk":0.40055,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."},"relatedVulnerabilities":[{"id":"CVE-2023-34152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"urls":["https://access.redhat.com/security/cve/CVE-2023-34152","https://bugzilla.redhat.com/show_bug.cgi?id=2210659","https://github.com/ImageMagick/ImageMagick/issues/6339","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4UFQJCYJ23HWHNDOVKBHZQ7HCXXL6MM3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V2ZUHZXQ2C3JZYKPW4XHCMVVL467MA2V/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."}]},{"artifact":{"id":"b5ed8bc1dc425827","cpes":["cpe:2.3:a:libmagickwand-6-headers:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6-headers:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6_headers:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6_headers:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickwand-6-headers","purl":"pkg:deb/debian/libmagickwand-6-headers@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickwand-6-headers/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.list"},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.postinst"},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.postrm"},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.preinst"},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-34152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-34152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"risk":0.40055,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."},"relatedVulnerabilities":[{"id":"CVE-2023-34152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"urls":["https://access.redhat.com/security/cve/CVE-2023-34152","https://bugzilla.redhat.com/show_bug.cgi?id=2210659","https://github.com/ImageMagick/ImageMagick/issues/6339","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4UFQJCYJ23HWHNDOVKBHZQ7HCXXL6MM3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V2ZUHZXQ2C3JZYKPW4XHCMVVL467MA2V/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."}]},{"artifact":{"id":"8cdb31d88acebec5","cpes":["cpe:2.3:a:libmagickwand-6.q16-6:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-6:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_6:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_6:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-6","purl":"pkg:deb/debian/libmagickwand-6.q16-6@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-6/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickwand-6.q16-6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-6:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-34152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-34152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"risk":0.40055,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."},"relatedVulnerabilities":[{"id":"CVE-2023-34152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"urls":["https://access.redhat.com/security/cve/CVE-2023-34152","https://bugzilla.redhat.com/show_bug.cgi?id=2210659","https://github.com/ImageMagick/ImageMagick/issues/6339","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4UFQJCYJ23HWHNDOVKBHZQ7HCXXL6MM3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V2ZUHZXQ2C3JZYKPW4XHCMVVL467MA2V/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."}]},{"artifact":{"id":"bfccc5b5605637fa","cpes":["cpe:2.3:a:libmagickwand-6.q16-dev:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-dev:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_dev:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_dev:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-dev","purl":"pkg:deb/debian/libmagickwand-6.q16-dev@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickwand-6.q16-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-34152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-34152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"risk":0.40055,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."},"relatedVulnerabilities":[{"id":"CVE-2023-34152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"urls":["https://access.redhat.com/security/cve/CVE-2023-34152","https://bugzilla.redhat.com/show_bug.cgi?id=2210659","https://github.com/ImageMagick/ImageMagick/issues/6339","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4UFQJCYJ23HWHNDOVKBHZQ7HCXXL6MM3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V2ZUHZXQ2C3JZYKPW4XHCMVVL467MA2V/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."}]},{"artifact":{"id":"9a83dfeec459438d","cpes":["cpe:2.3:a:libmagickwand-dev:libmagickwand-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-dev:libmagickwand_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_dev:libmagickwand-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_dev:libmagickwand_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickwand-dev","purl":"pkg:deb/debian/libmagickwand-dev@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickwand-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.list"},{"path":"/var/lib/dpkg/info/libmagickwand-dev.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.postinst"},{"path":"/var/lib/dpkg/info/libmagickwand-dev.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.postrm"},{"path":"/var/lib/dpkg/info/libmagickwand-dev.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.preinst"},{"path":"/var/lib/dpkg/info/libmagickwand-dev.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-34152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-34152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"risk":0.40055,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."},"relatedVulnerabilities":[{"id":"CVE-2023-34152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"urls":["https://access.redhat.com/security/cve/CVE-2023-34152","https://bugzilla.redhat.com/show_bug.cgi?id=2210659","https://github.com/ImageMagick/ImageMagick/issues/6339","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4UFQJCYJ23HWHNDOVKBHZQ7HCXXL6MM3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V2ZUHZXQ2C3JZYKPW4XHCMVVL467MA2V/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."}]},{"artifact":{"id":"ef5a5a7d880f3e73","cpes":["cpe:2.3:a:wget:wget:1.21.3-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"wget","purl":"pkg:deb/debian/wget@1.21.3-1%2Bdeb12u1?arch=amd64&distro=debian-12.15","type":"deb","version":"1.21.3-1+deb12u1","language":"","licenses":["sha256:c58cb5a2d94f35f0e9b0f1a038d48b73477aa12782ff17328c21d8a86f5f99d5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/wget/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/wget/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.conffiles","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/wget.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/wget.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.list","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/wget.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-58469","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"wget","version":"1.21.3-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58469","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58469","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58469","date":"2026-10-08","epss":0.00493,"percentile":0.4041}],"risk":0.39933,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58469","description":"GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior."},"relatedVulnerabilities":[{"id":"CVE-2026-58469","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58469","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58469","date":"2026-10-08","epss":0.00493,"percentile":0.4041}],"urls":["https://gitlab.com/gnuwget/wget/-/commit/37a40fcb450153f69537c7cbc2a7a4fb0b6f7826","https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-underread-via-metalink-url-parsing"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58469","description":"GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"risk":0.39039,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create an SSLContext per connection or replace it while connections are open; servers that wrap their listening socket with it are not affected.   Mitigation: keep a reference to every SSLContext that sets sni_callback for the lifetime of the server. TLS clients are not affected."},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"risk":0.39039,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create an SSLContext per connection or replace it while connections are open; servers that wrap their listening socket with it are not affected.   Mitigation: keep a reference to every SSLContext that sets sni_callback for the lifetime of the server. TLS clients are not affected."},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"risk":0.39039,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create an SSLContext per connection or replace it while connections are open; servers that wrap their listening socket with it are not affected.   Mitigation: keep a reference to every SSLContext that sets sni_callback for the lifetime of the server. TLS clients are not affected."},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"risk":0.39039,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create an SSLContext per connection or replace it while connections are open; servers that wrap their listening socket with it are not affected.   Mitigation: keep a reference to every SSLContext that sets sni_callback for the lifetime of the server. TLS clients are not affected."},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"6dec48f68a6dce02","cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"libheif1","purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","type":"deb","version":"1.15.1-1+deb12u1","language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libheif"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84384","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-84384","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84384","cwe":"CWE-409","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84384","date":"2026-10-08","epss":0.00517,"percentile":0.42172}],"risk":0.38775,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84384","description":"libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.2, crafted HEIF or AVIF mime metadata and unci image data can cause decompress_brotli() and do_inflate() to grow accumulated output without an effective size limit or MemoryHandle accounting. The brotli path has no output bound, while the zlib path checks only a small temporary buffer in a branch that valid streams do not reach, and overlapping icef units can decompress the same payload repeatedly. HeifContext::interpret_heif_file_images() processes multiple compressed metadata items during file opening, allowing a small file to consume unbounded memory and terminate the process. This issue is fixed in version 1.23.2."},"relatedVulnerabilities":[{"id":"CVE-2026-84384","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84384","cwe":"CWE-409","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84384","date":"2026-10-08","epss":0.00517,"percentile":0.42172}],"urls":["https://github.com/strukturag/libheif/commit/21893e8f66c8b79363ca2809391b07d35e1a95ec","https://github.com/strukturag/libheif/releases/tag/v1.23.2","https://github.com/strukturag/libheif/security/advisories/GHSA-24wx-9w62-c96w"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84384","description":"libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.2, crafted HEIF or AVIF mime metadata and unci image data can cause decompress_brotli() and do_inflate() to grow accumulated output without an effective size limit or MemoryHandle accounting. The brotli path has no output bound, while the zlib path checks only a small temporary buffer in a branch that valid streams do not reach, and overlapping icef units can decompress the same payload repeatedly. HeifContext::interpret_heif_file_images() processes multiple compressed metadata items during file opening, allowing a small file to consume unbounded memory and terminate the process. This issue is fixed in version 1.23.2."}]},{"artifact":{"id":"6dec48f68a6dce02","cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"libheif1","purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","type":"deb","version":"1.15.1-1+deb12u1","language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libheif"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84447","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-84447","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84447","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84447","date":"2026-10-08","epss":0.00517,"percentile":0.42172}],"risk":0.38775,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84447","description":"libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 and earlier, crafted grid, iovl, and iden reference graphs can repeatedly decode the same base image because processed_ids is copied per branch and ImageItem::decode_image() has no shared operation budget. This vulnerability is fixed in 1.23.2."},"relatedVulnerabilities":[{"id":"CVE-2026-84447","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84447","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84447","date":"2026-10-08","epss":0.00517,"percentile":0.42172}],"urls":["https://github.com/strukturag/libheif/commit/30b52a4e829efe0ee6d7208e8500b99f664af5e9","https://github.com/strukturag/libheif/releases/tag/v1.23.2","https://github.com/strukturag/libheif/security/advisories/GHSA-x8xm-cm2c-cfc8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84447","description":"libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 and earlier, crafted grid, iovl, and iden reference graphs can repeatedly decode the same base image because processed_ids is copied per branch and ImageItem::decode_image() has no shared operation budget. This vulnerability is fixed in 1.23.2."}]},{"artifact":{"id":"ac9f96c95674631f","cpes":["cpe:2.3:a:libopenexr-3-1-30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1-30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-3-1-30","purl":"pkg:deb/debian/libopenexr-3-1-30@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-3-1-30/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-3-1-30/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34543","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-34543","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34543","cwe":"CWE-908","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34543","date":"2026-10-08","epss":0.00517,"percentile":0.42125}],"risk":0.38775,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34543","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, sensitive information from heap memory may be leaked through the decoded pixel data (information disclosure). This occurs under default settings; simply reading a malicious EXR file is sufficient to trigger the issue, without any user interaction. This issue has been patched in version 3.4.8."},"relatedVulnerabilities":[{"id":"CVE-2026-34543","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34543","cwe":"CWE-908","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34543","date":"2026-10-08","epss":0.00517,"percentile":0.42125}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/5f6d0aaa9e43802917af7db90f181e88e083d3b8","https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.8","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-vc68-257w-m432"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34543","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, sensitive information from heap memory may be leaked through the decoded pixel data (information disclosure). This occurs under default settings; simply reading a malicious EXR file is sufficient to trigger the issue, without any user interaction. This issue has been patched in version 3.4.8."}]},{"artifact":{"id":"229cdd73859abf63","cpes":["cpe:2.3:a:libopenexr-dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-dev","purl":"pkg:deb/debian/libopenexr-dev@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.list"}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34543","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-34543","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34543","cwe":"CWE-908","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34543","date":"2026-10-08","epss":0.00517,"percentile":0.42125}],"risk":0.38775,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34543","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, sensitive information from heap memory may be leaked through the decoded pixel data (information disclosure). This occurs under default settings; simply reading a malicious EXR file is sufficient to trigger the issue, without any user interaction. This issue has been patched in version 3.4.8."},"relatedVulnerabilities":[{"id":"CVE-2026-34543","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34543","cwe":"CWE-908","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34543","date":"2026-10-08","epss":0.00517,"percentile":0.42125}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/5f6d0aaa9e43802917af7db90f181e88e083d3b8","https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.8","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-vc68-257w-m432"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34543","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, sensitive information from heap memory may be leaked through the decoded pixel data (information disclosure). This occurs under default settings; simply reading a malicious EXR file is sufficient to trigger the issue, without any user interaction. This issue has been patched in version 3.4.8."}]},{"artifact":{"id":"57bc3e079dc33e92","cpes":["cpe:2.3:a:libbluetooth-dev:libbluetooth-dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth-dev:libbluetooth_dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth_dev:libbluetooth-dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth_dev:libbluetooth_dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth:libbluetooth-dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libbluetooth:libbluetooth_dev:5.66-1\\+deb12u2:*:*:*:*:*:*:*"],"name":"libbluetooth-dev","purl":"pkg:deb/debian/libbluetooth-dev@5.66-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=bluez","type":"deb","version":"5.66-1+deb12u2","language":"","licenses":["Apache-2.0","BSD-2-clause","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libbluetooth-dev/copyright","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/usr/share/doc/libbluetooth-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbluetooth-dev:amd64.md5sums","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/info/libbluetooth-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bluez"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80186","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"bluez","version":"5.66-1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-80186","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80186","cwe":"CWE-120","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-80186","date":"2026-10-08","epss":0.00501,"percentile":0.40962}],"risk":0.378255,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80186","description":"A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-80186","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80186","cwe":"CWE-120","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-80186","date":"2026-10-08","epss":0.00501,"percentile":0.40962}],"urls":["https://access.redhat.com/security/cve/CVE-2026-80186","https://bugzilla.redhat.com/show_bug.cgi?id=2524132","https://github.com/bluez/bluez/security/advisories/GHSA-68h6-5qgp-3975"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80186","description":"A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution."}]},{"artifact":{"id":"818aff19ee069170","cpes":["cpe:2.3:a:libbluetooth3:libbluetooth3:5.66-1\\+deb12u2:*:*:*:*:*:*:*"],"name":"libbluetooth3","purl":"pkg:deb/debian/libbluetooth3@5.66-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=bluez","type":"deb","version":"5.66-1+deb12u2","language":"","licenses":["Apache-2.0","BSD-2-clause","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libbluetooth3/copyright","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/usr/share/doc/libbluetooth3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbluetooth3:amd64.md5sums","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/info/libbluetooth3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bluez"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80186","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"bluez","version":"5.66-1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-80186","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80186","cwe":"CWE-120","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-80186","date":"2026-10-08","epss":0.00501,"percentile":0.40962}],"risk":0.378255,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80186","description":"A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-80186","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80186","cwe":"CWE-120","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-80186","date":"2026-10-08","epss":0.00501,"percentile":0.40962}],"urls":["https://access.redhat.com/security/cve/CVE-2026-80186","https://bugzilla.redhat.com/show_bug.cgi?id=2524132","https://github.com/bluez/bluez/security/advisories/GHSA-68h6-5qgp-3975"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80186","description":"A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8328","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8328","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-8328","date":"2026-10-08","epss":0.00683,"percentile":0.51056}],"risk":0.37223500000000004,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8328","description":"The ftpcp() function in Lib/ftplib.py was not updated when  CVE-2021-4189 was fixed. While makepasv() was patched to replace  server-supplied PASV host addresses with the actual peer address  (getpeername()[0]), ftpcp() still calls parse227() directly and passes  the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189."},"relatedVulnerabilities":[{"id":"CVE-2026-8328","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-8328","date":"2026-10-08","epss":0.00683,"percentile":0.51056}],"urls":["https://github.com/python/cpython/commit/2bbcf3fb7a420a05605576c0f9468d4675381b5f","https://github.com/python/cpython/commit/5dadc64673ce875ebfb24163907777dae0f6ca06","https://github.com/python/cpython/commit/7d95a1dc7382b55cba7fdd6a110336077584a4f0","https://github.com/python/cpython/commit/bb3446dda6c49b32e67c11dbbbf221b40be00763","https://github.com/python/cpython/commit/c88704431ea3248ca769384c13856330976fac1d","https://github.com/python/cpython/commit/eac4fe3b2c77693790a5ef7dfab127c1fee81bf9","https://github.com/python/cpython/commit/ef12d0dc824baccf737bba1458e5eed3d1e0fceb","https://github.com/python/cpython/issues/87451","https://github.com/python/cpython/pull/149648","https://mail.python.org/archives/list/security-announce@python.org/thread/ITF2BAPBQEPYK3LDMPRSY435JGNHYNDP/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8328","description":"The ftpcp() function in Lib/ftplib.py was not updated when \nCVE-2021-4189 was fixed. While makepasv() was patched to replace \nserver-supplied PASV host addresses with the actual peer address \n(getpeername()[0]), ftpcp() still calls parse227() directly and passes \nthe raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8328","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8328","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-8328","date":"2026-10-08","epss":0.00683,"percentile":0.51056}],"risk":0.37223500000000004,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8328","description":"The ftpcp() function in Lib/ftplib.py was not updated when  CVE-2021-4189 was fixed. While makepasv() was patched to replace  server-supplied PASV host addresses with the actual peer address  (getpeername()[0]), ftpcp() still calls parse227() directly and passes  the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189."},"relatedVulnerabilities":[{"id":"CVE-2026-8328","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-8328","date":"2026-10-08","epss":0.00683,"percentile":0.51056}],"urls":["https://github.com/python/cpython/commit/2bbcf3fb7a420a05605576c0f9468d4675381b5f","https://github.com/python/cpython/commit/5dadc64673ce875ebfb24163907777dae0f6ca06","https://github.com/python/cpython/commit/7d95a1dc7382b55cba7fdd6a110336077584a4f0","https://github.com/python/cpython/commit/bb3446dda6c49b32e67c11dbbbf221b40be00763","https://github.com/python/cpython/commit/c88704431ea3248ca769384c13856330976fac1d","https://github.com/python/cpython/commit/eac4fe3b2c77693790a5ef7dfab127c1fee81bf9","https://github.com/python/cpython/commit/ef12d0dc824baccf737bba1458e5eed3d1e0fceb","https://github.com/python/cpython/issues/87451","https://github.com/python/cpython/pull/149648","https://mail.python.org/archives/list/security-announce@python.org/thread/ITF2BAPBQEPYK3LDMPRSY435JGNHYNDP/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8328","description":"The ftpcp() function in Lib/ftplib.py was not updated when \nCVE-2021-4189 was fixed. While makepasv() was patched to replace \nserver-supplied PASV host addresses with the actual peer address \n(getpeername()[0]), ftpcp() still calls parse227() directly and passes \nthe raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8328","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8328","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-8328","date":"2026-10-08","epss":0.00683,"percentile":0.51056}],"risk":0.37223500000000004,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8328","description":"The ftpcp() function in Lib/ftplib.py was not updated when  CVE-2021-4189 was fixed. While makepasv() was patched to replace  server-supplied PASV host addresses with the actual peer address  (getpeername()[0]), ftpcp() still calls parse227() directly and passes  the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189."},"relatedVulnerabilities":[{"id":"CVE-2026-8328","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-8328","date":"2026-10-08","epss":0.00683,"percentile":0.51056}],"urls":["https://github.com/python/cpython/commit/2bbcf3fb7a420a05605576c0f9468d4675381b5f","https://github.com/python/cpython/commit/5dadc64673ce875ebfb24163907777dae0f6ca06","https://github.com/python/cpython/commit/7d95a1dc7382b55cba7fdd6a110336077584a4f0","https://github.com/python/cpython/commit/bb3446dda6c49b32e67c11dbbbf221b40be00763","https://github.com/python/cpython/commit/c88704431ea3248ca769384c13856330976fac1d","https://github.com/python/cpython/commit/eac4fe3b2c77693790a5ef7dfab127c1fee81bf9","https://github.com/python/cpython/commit/ef12d0dc824baccf737bba1458e5eed3d1e0fceb","https://github.com/python/cpython/issues/87451","https://github.com/python/cpython/pull/149648","https://mail.python.org/archives/list/security-announce@python.org/thread/ITF2BAPBQEPYK3LDMPRSY435JGNHYNDP/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8328","description":"The ftpcp() function in Lib/ftplib.py was not updated when \nCVE-2021-4189 was fixed. While makepasv() was patched to replace \nserver-supplied PASV host addresses with the actual peer address \n(getpeername()[0]), ftpcp() still calls parse227() directly and passes \nthe raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8328","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8328","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-8328","date":"2026-10-08","epss":0.00683,"percentile":0.51056}],"risk":0.37223500000000004,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8328","description":"The ftpcp() function in Lib/ftplib.py was not updated when  CVE-2021-4189 was fixed. While makepasv() was patched to replace  server-supplied PASV host addresses with the actual peer address  (getpeername()[0]), ftpcp() still calls parse227() directly and passes  the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189."},"relatedVulnerabilities":[{"id":"CVE-2026-8328","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-8328","date":"2026-10-08","epss":0.00683,"percentile":0.51056}],"urls":["https://github.com/python/cpython/commit/2bbcf3fb7a420a05605576c0f9468d4675381b5f","https://github.com/python/cpython/commit/5dadc64673ce875ebfb24163907777dae0f6ca06","https://github.com/python/cpython/commit/7d95a1dc7382b55cba7fdd6a110336077584a4f0","https://github.com/python/cpython/commit/bb3446dda6c49b32e67c11dbbbf221b40be00763","https://github.com/python/cpython/commit/c88704431ea3248ca769384c13856330976fac1d","https://github.com/python/cpython/commit/eac4fe3b2c77693790a5ef7dfab127c1fee81bf9","https://github.com/python/cpython/commit/ef12d0dc824baccf737bba1458e5eed3d1e0fceb","https://github.com/python/cpython/issues/87451","https://github.com/python/cpython/pull/149648","https://mail.python.org/archives/list/security-announce@python.org/thread/ITF2BAPBQEPYK3LDMPRSY435JGNHYNDP/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8328","description":"The ftpcp() function in Lib/ftplib.py was not updated when \nCVE-2021-4189 was fixed. While makepasv() was patched to replace \nserver-supplied PASV host addresses with the actual peer address \n(getpeername()[0]), ftpcp() still calls parse227() directly and passes \nthe raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5928","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5928","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"risk":0.36975,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."},"relatedVulnerabilities":[{"id":"CVE-2026-5928","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33998","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."}]},{"artifact":{"id":"05457b2d3472913c","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5928","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5928","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"risk":0.36975,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."},"relatedVulnerabilities":[{"id":"CVE-2026-5928","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33998","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5928","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5928","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"risk":0.36975,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."},"relatedVulnerabilities":[{"id":"CVE-2026-5928","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33998","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."}]},{"artifact":{"id":"be9fcdc16d52ab8f","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5928","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5928","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"risk":0.36975,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."},"relatedVulnerabilities":[{"id":"CVE-2026-5928","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33998","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."}]},{"artifact":{"id":"6dec48f68a6dce02","cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"libheif1","purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","type":"deb","version":"1.15.1-1+deb12u1","language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libheif"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-47247","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-47247","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47247","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-47247","cwe":"CWE-226","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-47247","cwe":"CWE-682","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-47247","cwe":"CWE-908","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-47247","date":"2026-10-08","epss":0.00479,"percentile":0.39363}],"risk":0.35925,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-47247","description":"libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain to leak process heap memory as visible pixel values in decoded grid images. An attacker who uploads a crafted AVIF/HEIC file to any server-side image processor (WordPress, Sharp/libvips, ImageMagick, etc.) can recover heap data - including library function pointers sufficient to defeat ASLR, or any other secret - from the publicly-downloadable transcoded JPEG/PNG/WebP output. Local attack vectors are also possible. Version 1.22.0 fixes the issue."},"relatedVulnerabilities":[{"id":"CVE-2026-47247","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47247","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-47247","cwe":"CWE-226","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-47247","cwe":"CWE-682","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-47247","cwe":"CWE-908","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-47247","date":"2026-10-08","epss":0.00479,"percentile":0.39363}],"urls":["https://github.com/strukturag/libheif/security/advisories/GHSA-2vh6-whr3-cmq3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47247","description":"libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain to leak process heap memory as visible pixel values in decoded grid images. An attacker who uploads a crafted AVIF/HEIC file to any server-side image processor (WordPress, Sharp/libvips, ImageMagick, etc.) can recover heap data - including library function pointers sufficient to defeat ASLR, or any other secret - from the publicly-downloadable transcoded JPEG/PNG/WebP output. Local attack vectors are also possible. Version 1.22.0 fixes the issue."}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-13608","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-13608","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-08","epss":0.00479,"percentile":0.39377}],"risk":0.356855,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation."},"relatedVulnerabilities":[{"id":"CVE-2026-13608","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-08","epss":0.00479,"percentile":0.39377}],"urls":["https://curl.se/docs/CVE-2026-13608.html","https://curl.se/docs/CVE-2026-13608.json","https://hackerone.com/reports/3822248"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an\nincomplete handshake sequence to be misinterpreted as a successful\ncryptographic verification. An attacker executing a Man-in-the-Middle (MITM)\nattack can inject a premature or shortcut response that bypasses complete peer\nvalidation."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13608","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-13608","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-08","epss":0.00479,"percentile":0.39377}],"risk":0.356855,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation."},"relatedVulnerabilities":[{"id":"CVE-2026-13608","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-08","epss":0.00479,"percentile":0.39377}],"urls":["https://curl.se/docs/CVE-2026-13608.html","https://curl.se/docs/CVE-2026-13608.json","https://hackerone.com/reports/3822248"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an\nincomplete handshake sequence to be misinterpreted as a successful\ncryptographic verification. An attacker executing a Man-in-the-Middle (MITM)\nattack can inject a premature or shortcut response that bypasses complete peer\nvalidation."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13608","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-13608","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-08","epss":0.00479,"percentile":0.39377}],"risk":0.356855,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation."},"relatedVulnerabilities":[{"id":"CVE-2026-13608","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-08","epss":0.00479,"percentile":0.39377}],"urls":["https://curl.se/docs/CVE-2026-13608.html","https://curl.se/docs/CVE-2026-13608.json","https://hackerone.com/reports/3822248"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an\nincomplete handshake sequence to be misinterpreted as a successful\ncryptographic verification. An attacker executing a Man-in-the-Middle (MITM)\nattack can inject a premature or shortcut response that bypasses complete peer\nvalidation."}]},{"artifact":{"id":"610d5f28e0c6125d","cpes":["cpe:2.3:a:libcurl4-openssl-dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl-dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4-openssl-dev","purl":"pkg:deb/debian/libcurl4-openssl-dev@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4-openssl-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libcurl4-openssl-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13608","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-13608","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-08","epss":0.00479,"percentile":0.39377}],"risk":0.356855,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation."},"relatedVulnerabilities":[{"id":"CVE-2026-13608","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-08","epss":0.00479,"percentile":0.39377}],"urls":["https://curl.se/docs/CVE-2026-13608.html","https://curl.se/docs/CVE-2026-13608.json","https://hackerone.com/reports/3822248"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an\nincomplete handshake sequence to be misinterpreted as a successful\ncryptographic verification. An attacker executing a Man-in-the-Middle (MITM)\nattack can inject a premature or shortcut response that bypasses complete peer\nvalidation."}]},{"artifact":{"id":"6dec48f68a6dce02","cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"libheif1","purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","type":"deb","version":"1.15.1-1+deb12u1","language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libheif"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84444","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-84444","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84444","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84444","date":"2026-10-08","epss":0.00478,"percentile":0.39246}],"risk":0.35611000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84444","description":"libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, when WITH_UNCOMPRESSED_CODEC is enabled, heif_context_add_image_tile() accepts an independently constructed tile whose component-plane dimensions do not match the tile geometry established by the prototype image. ImageItem_uncompressed::add_image_tile() passes that tile directly to unc_encoder::encode_tile(), which lacked the check_component_sizes() gate and sizes its output from the configured tile geometry while copying the tile's actual component-plane dimensions. An oversized component plane can therefore make unc_encoder_component_interleave::encode_tile() copy attacker-controlled data beyond the heap output buffer. This issue is fixed in version 1.23.2."},"relatedVulnerabilities":[{"id":"CVE-2026-84444","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84444","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84444","date":"2026-10-08","epss":0.00478,"percentile":0.39246}],"urls":["https://github.com/strukturag/libheif/commit/e65071f59a1ac08aa1eb0d07a831deaf6bb4d03b","https://github.com/strukturag/libheif/releases/tag/v1.23.2","https://github.com/strukturag/libheif/security/advisories/GHSA-j264-xvrp-5v7q"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84444","description":"libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, when WITH_UNCOMPRESSED_CODEC is enabled, heif_context_add_image_tile() accepts an independently constructed tile whose component-plane dimensions do not match the tile geometry established by the prototype image. ImageItem_uncompressed::add_image_tile() passes that tile directly to unc_encoder::encode_tile(), which lacked the check_component_sizes() gate and sizes its output from the configured tile geometry while copying the tile's actual component-plane dimensions. An oversized component plane can therefore make unc_encoder_component_interleave::encode_tile() copy attacker-controlled data beyond the heap output buffer. This issue is fixed in version 1.23.2."}]},{"artifact":{"id":"692b9197d4b21a92","cpes":["cpe:2.3:a:libldap-2.5-0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5-0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5_0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5_0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"],"name":"libldap-2.5-0","purl":"pkg:deb/debian/libldap-2.5-0@2.5.13%2Bdfsg-5?arch=amd64&distro=debian-12.15&upstream=openldap","type":"deb","version":"2.5.13+dfsg-5","language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.5-0/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/libldap-2.5-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.5-0:amd64.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/libldap-2.5-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-17740","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openldap","version":"2.5.13+dfsg-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2017-17740","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-17740","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-17740","date":"2026-10-08","epss":0.07022,"percentile":0.94018}],"risk":0.3511,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-17740","description":"contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation."},"relatedVulnerabilities":[{"id":"CVE-2017-17740","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-17740","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-17740","date":"2026-10-08","epss":0.07022,"percentile":0.94018}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00053.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00058.html","http://www.openldap.org/its/index.cgi/Incoming?id=8759","https://kc.mcafee.com/corporate/index?page=content&id=SB10365","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-17740","description":"contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation."}]},{"artifact":{"id":"dee83f732098ecac","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/debian/libxml2@2.9.14%2Bdfsg-1.3~deb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"2.9.14+dfsg-1.3~deb12u6","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-74860","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-74860","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.5,"impactScore":6.1,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-74860","cwe":"CWE-763","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-74860","date":"2026-10-08","epss":0.00436,"percentile":0.35841}],"risk":0.3488,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74860","description":"A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings."},"relatedVulnerabilities":[{"id":"CVE-2026-74860","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.5,"impactScore":6.1,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-74860","cwe":"CWE-763","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-74860","date":"2026-10-08","epss":0.00436,"percentile":0.35841}],"urls":["https://access.redhat.com/errata/RHSA-2026:64463","https://access.redhat.com/errata/RHSA-2026:71585","https://access.redhat.com/errata/RHSA-2026:71586","https://access.redhat.com/errata/RHSA-2026:71641","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/security/cve/CVE-2026-74860","https://bugzilla.redhat.com/show_bug.cgi?id=2529697"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74860","description":"A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings."}]},{"artifact":{"id":"e34af58fe794c658","cpes":["cpe:2.3:a:libxml2-dev:libxml2-dev:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*","cpe:2.3:a:libxml2-dev:libxml2_dev:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*","cpe:2.3:a:libxml2_dev:libxml2-dev:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*","cpe:2.3:a:libxml2_dev:libxml2_dev:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*","cpe:2.3:a:libxml2:libxml2-dev:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*","cpe:2.3:a:libxml2:libxml2_dev:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*"],"name":"libxml2-dev","purl":"pkg:deb/debian/libxml2-dev@2.9.14%2Bdfsg-1.3~deb12u6?arch=amd64&distro=debian-12.15&upstream=libxml2","type":"deb","version":"2.9.14+dfsg-1.3~deb12u6","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libxml2-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libxml2-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libxml2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-74860","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-74860","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.5,"impactScore":6.1,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-74860","cwe":"CWE-763","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-74860","date":"2026-10-08","epss":0.00436,"percentile":0.35841}],"risk":0.3488,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74860","description":"A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings."},"relatedVulnerabilities":[{"id":"CVE-2026-74860","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.5,"impactScore":6.1,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-74860","cwe":"CWE-763","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-74860","date":"2026-10-08","epss":0.00436,"percentile":0.35841}],"urls":["https://access.redhat.com/errata/RHSA-2026:64463","https://access.redhat.com/errata/RHSA-2026:71585","https://access.redhat.com/errata/RHSA-2026:71586","https://access.redhat.com/errata/RHSA-2026:71641","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/security/cve/CVE-2026-74860","https://bugzilla.redhat.com/show_bug.cgi?id=2529697"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74860","description":"A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings."}]},{"artifact":{"id":"6dec48f68a6dce02","cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"libheif1","purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","type":"deb","version":"1.15.1-1+deb12u1","language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libheif"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-41071","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-41071","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41071","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41071","date":"2026-10-08","epss":0.00442,"percentile":0.36427}],"risk":0.34476,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-41071","description":"libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file where the saiz box declares more samples than actually exist in the track's chunk table causes a heap-buffer-overflow (out-of-bounds read) in the SampleAuxInfoReader constructor. The SampleAuxInfoReader constructor iterates over saiz->get_num_samples() samples but doesn't validate that this count is consistent with the number of chunks in the chunks vector. When saiz declares more samples than the chunks cover, the loop increments current_chunk past chunks.size(), causing an out-of-bounds read on the chunks vector. The vulnerability is triggered during file parsing (heif_context_read_from_file) without any additional user interaction. Any application using libheif to open untrusted HEIF files is affected. This issue has been fixed in version 1.22.0."},"relatedVulnerabilities":[{"id":"CVE-2026-41071","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41071","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41071","date":"2026-10-08","epss":0.00442,"percentile":0.36427}],"urls":["https://github.com/strukturag/libheif/releases/tag/v1.22.0","https://github.com/strukturag/libheif/security/advisories/GHSA-xj92-xjff-h8w3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41071","description":"libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file where the saiz box declares more samples than actually exist in the track's chunk table causes a heap-buffer-overflow (out-of-bounds read) in the SampleAuxInfoReader constructor. The SampleAuxInfoReader constructor iterates over saiz->get_num_samples() samples but doesn't validate that this count is consistent with the number of chunks in the chunks vector. When saiz declares more samples than the chunks cover, the loop increments current_chunk past chunks.size(), causing an out-of-bounds read on the chunks vector. The vulnerability is triggered during file parsing (heif_context_read_from_file) without any additional user interaction. Any application using libheif to open untrusted HEIF files is affected. This issue has been fixed in version 1.22.0."}]},{"artifact":{"id":"6dec48f68a6dce02","cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"libheif1","purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","type":"deb","version":"1.15.1-1+deb12u1","language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libheif"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84446","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-84446","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84446","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84446","date":"2026-10-08","epss":0.00458,"percentile":0.37755}],"risk":0.34349999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84446","description":"libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, crafted HEIF sequence timing and edit-list data can make Track::init_sample_timing_table() compute a logical m_num_output_samples value that exceeds the uint32_t counters used by Track_Visual::decode_next_image_sample() and Track::get_next_sample_raw_data(). The resulting comparison can never reach the oversized output count, causing non-terminating decode or raw-sample loops and bypassing max_sequence_frames. The same sequence path repeatedly calls Box_stts::get_sample_duration() and allocates Chunk::m_sample_ranges and Track::m_presentation_timeline outside MemoryHandle accounting, allowing severe CPU and memory exhaustion from a small file. This issue is fixed in version 1.23.2."},"relatedVulnerabilities":[{"id":"CVE-2026-84446","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84446","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84446","date":"2026-10-08","epss":0.00458,"percentile":0.37755}],"urls":["https://github.com/strukturag/libheif/commit/3a7a69ae325f652e48c026b8241ab25bedf44d9b","https://github.com/strukturag/libheif/releases/tag/v1.23.2","https://github.com/strukturag/libheif/security/advisories/GHSA-xw34-mjcp-jqh8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84446","description":"libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, crafted HEIF sequence timing and edit-list data can make Track::init_sample_timing_table() compute a logical m_num_output_samples value that exceeds the uint32_t counters used by Track_Visual::decode_next_image_sample() and Track::get_next_sample_raw_data(). The resulting comparison can never reach the oversized output count, causing non-terminating decode or raw-sample loops and bypassing max_sequence_frames. The same sequence path repeatedly calls Box_stts::get_sample_duration() and allocates Chunk::m_sample_ranges and Track::m_presentation_timeline outside MemoryHandle accounting, allowing severe CPU and memory exhaustion from a small file. This issue is fixed in version 1.23.2."}]},{"artifact":{"id":"aff0821f961165d7","cpes":["cpe:2.3:a:libncurses-dev:libncurses-dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncurses-dev:libncurses_dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncurses_dev:libncurses-dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncurses_dev:libncurses_dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncurses:libncurses-dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncurses:libncurses_dev:6.4-4:*:*:*:*:*:*:*"],"name":"libncurses-dev","purl":"pkg:deb/debian/libncurses-dev@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libncurses-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libncurses-dev:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libncurses-dev/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"9d88525499877381","cpes":["cpe:2.3:a:libncurses5-dev:libncurses5-dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncurses5-dev:libncurses5_dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncurses5_dev:libncurses5-dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncurses5_dev:libncurses5_dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncurses5:libncurses5-dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncurses5:libncurses5_dev:6.4-4:*:*:*:*:*:*:*"],"name":"libncurses5-dev","purl":"pkg:deb/debian/libncurses5-dev@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libncurses5-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libncurses5-dev:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libncurses5-dev/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"45ca0a14113d5717","cpes":["cpe:2.3:a:libncurses6:libncurses6:6.4-4:*:*:*:*:*:*:*"],"name":"libncurses6","purl":"pkg:deb/debian/libncurses6@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libncurses6:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libncurses6:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libncurses6/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"b44a1de54805a03c","cpes":["cpe:2.3:a:libncursesw5-dev:libncursesw5-dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncursesw5-dev:libncursesw5_dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncursesw5_dev:libncursesw5-dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncursesw5_dev:libncursesw5_dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncursesw5:libncursesw5-dev:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:libncursesw5:libncursesw5_dev:6.4-4:*:*:*:*:*:*:*"],"name":"libncursesw5-dev","purl":"pkg:deb/debian/libncursesw5-dev@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libncursesw5-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libncursesw5-dev:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libncursesw5-dev/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"2b3a2ba7a41a0529","cpes":["cpe:2.3:a:libncursesw6:libncursesw6:6.4-4:*:*:*:*:*:*:*"],"name":"libncursesw6","purl":"pkg:deb/debian/libncursesw6@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libncursesw6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"a6231fb14cfeaaac","cpes":["cpe:2.3:a:libtinfo6:libtinfo6:6.4-4:*:*:*:*:*:*:*"],"name":"libtinfo6","purl":"pkg:deb/debian/libtinfo6@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libtinfo6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"ec73073218fd031a","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.4-4:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/debian/ncurses-base@6.4-4?arch=all&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"c5b18ac268f2ccdf","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.4-4:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/debian/ncurses-bin@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"f314997677a3aacc","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/debian/imagemagick@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.list"},{"path":"/var/lib/dpkg/info/imagemagick.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.postinst"},{"path":"/var/lib/dpkg/info/imagemagick.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.postrm"},{"path":"/var/lib/dpkg/info/imagemagick.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.preinst"},{"path":"/var/lib/dpkg/info/imagemagick.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86421","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86421","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"risk":0.33975000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86421","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4jv7-q6xw-6f4x","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-memory-leak-via-msl-decoder"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."}]},{"artifact":{"id":"58eb8529873897ef","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/debian/imagemagick-6-common@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86421","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86421","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"risk":0.33975000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86421","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4jv7-q6xw-6f4x","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-memory-leak-via-msl-decoder"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."}]},{"artifact":{"id":"81d27bbb42434f07","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/debian/imagemagick-6.q16@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86421","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86421","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"risk":0.33975000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86421","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4jv7-q6xw-6f4x","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-memory-leak-via-msl-decoder"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."}]},{"artifact":{"id":"4166e52734c45414","cpes":["cpe:2.3:a:libmagickcore-6-arch-config:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6-arch-config:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_arch_config:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_arch_config:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6-arch:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6-arch:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_arch:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_arch:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6-arch-config","purl":"pkg:deb/debian/libmagickcore-6-arch-config@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6-arch-config/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6-arch-config/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6-arch-config:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-arch-config:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86421","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86421","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"risk":0.33975000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86421","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4jv7-q6xw-6f4x","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-memory-leak-via-msl-decoder"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."}]},{"artifact":{"id":"aa218174a16ba41d","cpes":["cpe:2.3:a:libmagickcore-6-headers:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6-headers:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_headers:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_headers:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6-headers","purl":"pkg:deb/debian/libmagickcore-6-headers@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6-headers/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.list"},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.postinst"},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.postrm"},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.preinst"},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86421","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86421","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"risk":0.33975000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86421","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4jv7-q6xw-6f4x","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-memory-leak-via-msl-decoder"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."}]},{"artifact":{"id":"b5cf9ab484b0ba4d","cpes":["cpe:2.3:a:libmagickcore-6.q16-6:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-6:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-6","purl":"pkg:deb/debian/libmagickcore-6.q16-6@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-6/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6.q16-6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-6:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86421","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86421","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"risk":0.33975000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86421","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4jv7-q6xw-6f4x","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-memory-leak-via-msl-decoder"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."}]},{"artifact":{"id":"839820a05a2b8d61","cpes":["cpe:2.3:a:libmagickcore-6.q16-6-extra:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-6-extra:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6_extra:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6_extra:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-6:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-6:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-6-extra","purl":"pkg:deb/debian/libmagickcore-6.q16-6-extra@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-6-extra/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6.q16-6-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-6-extra:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-6-extra:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86421","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86421","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"risk":0.33975000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86421","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4jv7-q6xw-6f4x","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-memory-leak-via-msl-decoder"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."}]},{"artifact":{"id":"6bdab316f776d434","cpes":["cpe:2.3:a:libmagickcore-6.q16-dev:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-dev:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_dev:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_dev:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-dev","purl":"pkg:deb/debian/libmagickcore-6.q16-dev@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6.q16-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86421","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86421","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"risk":0.33975000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86421","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4jv7-q6xw-6f4x","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-memory-leak-via-msl-decoder"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."}]},{"artifact":{"id":"4ecf55d018da7a3a","cpes":["cpe:2.3:a:libmagickcore-dev:libmagickcore-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-dev:libmagickcore_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_dev:libmagickcore-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_dev:libmagickcore_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-dev","purl":"pkg:deb/debian/libmagickcore-dev@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.list"},{"path":"/var/lib/dpkg/info/libmagickcore-dev.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.postinst"},{"path":"/var/lib/dpkg/info/libmagickcore-dev.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.postrm"},{"path":"/var/lib/dpkg/info/libmagickcore-dev.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.preinst"},{"path":"/var/lib/dpkg/info/libmagickcore-dev.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86421","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86421","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"risk":0.33975000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86421","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4jv7-q6xw-6f4x","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-memory-leak-via-msl-decoder"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."}]},{"artifact":{"id":"b5ed8bc1dc425827","cpes":["cpe:2.3:a:libmagickwand-6-headers:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6-headers:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6_headers:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6_headers:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickwand-6-headers","purl":"pkg:deb/debian/libmagickwand-6-headers@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickwand-6-headers/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.list"},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.postinst"},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.postrm"},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.preinst"},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86421","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86421","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"risk":0.33975000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86421","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4jv7-q6xw-6f4x","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-memory-leak-via-msl-decoder"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."}]},{"artifact":{"id":"8cdb31d88acebec5","cpes":["cpe:2.3:a:libmagickwand-6.q16-6:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-6:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_6:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_6:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-6","purl":"pkg:deb/debian/libmagickwand-6.q16-6@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-6/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickwand-6.q16-6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-6:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86421","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86421","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"risk":0.33975000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86421","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4jv7-q6xw-6f4x","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-memory-leak-via-msl-decoder"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."}]},{"artifact":{"id":"bfccc5b5605637fa","cpes":["cpe:2.3:a:libmagickwand-6.q16-dev:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-dev:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_dev:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_dev:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-dev","purl":"pkg:deb/debian/libmagickwand-6.q16-dev@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickwand-6.q16-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86421","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86421","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"risk":0.33975000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86421","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4jv7-q6xw-6f4x","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-memory-leak-via-msl-decoder"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."}]},{"artifact":{"id":"9a83dfeec459438d","cpes":["cpe:2.3:a:libmagickwand-dev:libmagickwand-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-dev:libmagickwand_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_dev:libmagickwand-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_dev:libmagickwand_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickwand-dev","purl":"pkg:deb/debian/libmagickwand-dev@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickwand-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.list"},{"path":"/var/lib/dpkg/info/libmagickwand-dev.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.postinst"},{"path":"/var/lib/dpkg/info/libmagickwand-dev.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.postrm"},{"path":"/var/lib/dpkg/info/libmagickwand-dev.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.preinst"},{"path":"/var/lib/dpkg/info/libmagickwand-dev.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86421","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86421","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"risk":0.33975000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86421","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4jv7-q6xw-6f4x","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-memory-leak-via-msl-decoder"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."}]},{"artifact":{"id":"ac9f96c95674631f","cpes":["cpe:2.3:a:libopenexr-3-1-30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1-30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-3-1-30","purl":"pkg:deb/debian/libopenexr-3-1-30@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-3-1-30/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-3-1-30/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34379","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-34379","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34379","cwe":"CWE-704","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34379","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34379","cwe":"CWE-843","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34379","cwe":"CWE-475","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-34379","date":"2026-10-08","epss":0.00464,"percentile":0.3823}],"risk":0.33872,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34379","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a misaligned memory write vulnerability exists in LossyDctDecoder_execute() in src/lib/OpenEXRCore/internal_dwa_decoder.h:749. When decoding a DWA or DWAB-compressed EXR file containing a FLOAT-type channel, the decoder performs an in-place HALF→FLOAT conversion by casting an unaligned uint8_t * row pointer to float * and writing through it. Because the row buffer may not be 4-byte aligned, this constitutes undefined behavior under the C standard and crashes immediately on architectures that enforce alignment (ARM, RISC-V, etc.). On x86 it is silently tolerated at runtime but remains exploitable via compiler optimizations that assume aligned access. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9."},"relatedVulnerabilities":[{"id":"CVE-2026-34379","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34379","cwe":"CWE-704","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34379","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34379","cwe":"CWE-843","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34379","cwe":"CWE-475","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-34379","date":"2026-10-08","epss":0.00464,"percentile":0.3823}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.2.7","https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.3.9","https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.9","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-w88v-vqhq-5p24","https://access.redhat.com/security/cve/CVE-2026-34379","https://bugzilla.redhat.com/show_bug.cgi?id=2455402","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34379.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34379","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a misaligned memory write vulnerability exists in LossyDctDecoder_execute() in src/lib/OpenEXRCore/internal_dwa_decoder.h:749. When decoding a DWA or DWAB-compressed EXR file containing a FLOAT-type channel, the decoder performs an in-place HALF→FLOAT conversion by casting an unaligned uint8_t * row pointer to float * and writing through it. Because the row buffer may not be 4-byte aligned, this constitutes undefined behavior under the C standard and crashes immediately on architectures that enforce alignment (ARM, RISC-V, etc.). On x86 it is silently tolerated at runtime but remains exploitable via compiler optimizations that assume aligned access. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9."}]},{"artifact":{"id":"229cdd73859abf63","cpes":["cpe:2.3:a:libopenexr-dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-dev","purl":"pkg:deb/debian/libopenexr-dev@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.list"}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34379","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-34379","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34379","cwe":"CWE-704","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34379","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34379","cwe":"CWE-843","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34379","cwe":"CWE-475","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-34379","date":"2026-10-08","epss":0.00464,"percentile":0.3823}],"risk":0.33872,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34379","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a misaligned memory write vulnerability exists in LossyDctDecoder_execute() in src/lib/OpenEXRCore/internal_dwa_decoder.h:749. When decoding a DWA or DWAB-compressed EXR file containing a FLOAT-type channel, the decoder performs an in-place HALF→FLOAT conversion by casting an unaligned uint8_t * row pointer to float * and writing through it. Because the row buffer may not be 4-byte aligned, this constitutes undefined behavior under the C standard and crashes immediately on architectures that enforce alignment (ARM, RISC-V, etc.). On x86 it is silently tolerated at runtime but remains exploitable via compiler optimizations that assume aligned access. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9."},"relatedVulnerabilities":[{"id":"CVE-2026-34379","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34379","cwe":"CWE-704","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34379","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34379","cwe":"CWE-843","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34379","cwe":"CWE-475","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-34379","date":"2026-10-08","epss":0.00464,"percentile":0.3823}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.2.7","https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.3.9","https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.9","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-w88v-vqhq-5p24","https://access.redhat.com/security/cve/CVE-2026-34379","https://bugzilla.redhat.com/show_bug.cgi?id=2455402","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34379.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34379","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a misaligned memory write vulnerability exists in LossyDctDecoder_execute() in src/lib/OpenEXRCore/internal_dwa_decoder.h:749. When decoding a DWA or DWAB-compressed EXR file containing a FLOAT-type channel, the decoder performs an in-place HALF→FLOAT conversion by casting an unaligned uint8_t * row pointer to float * and writing through it. Because the row buffer may not be 4-byte aligned, this constitutes undefined behavior under the C standard and crashes immediately on architectures that enforce alignment (ARM, RISC-V, etc.). On x86 it is silently tolerated at runtime but remains exploitable via compiler optimizations that assume aligned access. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9."}]},{"artifact":{"id":"b280459d31091296","cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*"],"name":"libopenjp2-7","purl":"pkg:deb/debian/libopenjp2-7@2.5.0-2%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=openjpeg2","type":"deb","version":"2.5.0-2+deb12u3","language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjpeg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-39329","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjpeg2","version":"2.5.0-2+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-39329","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39329","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-39329","date":"2026-10-08","epss":0.00588,"percentile":0.4644}],"risk":0.33809999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-39329","description":"A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2023-39329","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39329","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-39329","date":"2026-10-08","epss":0.00588,"percentile":0.4644}],"urls":["https://access.redhat.com/errata/RHSA-2026:4128","https://access.redhat.com/security/cve/CVE-2023-39329","https://bugzilla.redhat.com/show_bug.cgi?id=2295816","https://github.com/uclouvain/openjpeg/issues/1474"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-39329","description":"A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial of service."}]},{"artifact":{"id":"29b0a2eb864a8178","cpes":["cpe:2.3:a:libopenjp2-7-dev:libopenjp2-7-dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7-dev:libopenjp2_7_dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7_dev:libopenjp2-7-dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7_dev:libopenjp2_7_dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2-7-dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7_dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7-dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7_dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7-dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7_dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*"],"name":"libopenjp2-7-dev","purl":"pkg:deb/debian/libopenjp2-7-dev@2.5.0-2%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=openjpeg2","type":"deb","version":"2.5.0-2+deb12u3","language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenjp2-7-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenjp2-7-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjpeg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-39329","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjpeg2","version":"2.5.0-2+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-39329","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39329","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-39329","date":"2026-10-08","epss":0.00588,"percentile":0.4644}],"risk":0.33809999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-39329","description":"A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2023-39329","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39329","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-39329","date":"2026-10-08","epss":0.00588,"percentile":0.4644}],"urls":["https://access.redhat.com/errata/RHSA-2026:4128","https://access.redhat.com/security/cve/CVE-2023-39329","https://bugzilla.redhat.com/show_bug.cgi?id=2295816","https://github.com/uclouvain/openjpeg/issues/1474"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-39329","description":"A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial of service."}]},{"artifact":{"id":"797a08aa0e653cc1","cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*"],"name":"libperl5.36","purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u4","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-9538","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"risk":0.33599999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."},"relatedVulnerabilities":[{"id":"CVE-2026-9538","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."}]},{"artifact":{"id":"1abbc10047509a69","cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u4?arch=amd64&distro=debian-12.15","type":"deb","version":"5.36.0-7+deb12u4","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-9538","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"risk":0.33599999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."},"relatedVulnerabilities":[{"id":"CVE-2026-9538","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."}]},{"artifact":{"id":"5a32e7d822381d5b","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u4","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-9538","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"risk":0.33599999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."},"relatedVulnerabilities":[{"id":"CVE-2026-9538","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."}]},{"artifact":{"id":"ab813d7f861aa617","cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u4:*:*:*:*:*:*:*"],"name":"perl-modules-5.36","purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u4?arch=all&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u4","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-9538","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"risk":0.33599999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."},"relatedVulnerabilities":[{"id":"CVE-2026-9538","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."}]},{"artifact":{"id":"dee83f732098ecac","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/debian/libxml2@2.9.14%2Bdfsg-1.3~deb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"2.9.14+dfsg-1.3~deb12u6","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-6653","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6653","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6653","cwe":"CWE-416","type":"Secondary","source":"security@ubuntu.com"},{"cve":"CVE-2026-6653","cwe":"CWE-611","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-6653","date":"2026-10-08","epss":0.00355,"percentile":0.27192}],"risk":0.33370000000000005,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6653","description":"Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling."},"relatedVulnerabilities":[{"id":"CVE-2026-6653","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6653","cwe":"CWE-416","type":"Secondary","source":"security@ubuntu.com"},{"cve":"CVE-2026-6653","cwe":"CWE-611","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-6653","date":"2026-10-08","epss":0.00355,"percentile":0.27192}],"urls":["https://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/2141260","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6653","description":"Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling."}]},{"artifact":{"id":"e34af58fe794c658","cpes":["cpe:2.3:a:libxml2-dev:libxml2-dev:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*","cpe:2.3:a:libxml2-dev:libxml2_dev:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*","cpe:2.3:a:libxml2_dev:libxml2-dev:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*","cpe:2.3:a:libxml2_dev:libxml2_dev:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*","cpe:2.3:a:libxml2:libxml2-dev:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*","cpe:2.3:a:libxml2:libxml2_dev:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*"],"name":"libxml2-dev","purl":"pkg:deb/debian/libxml2-dev@2.9.14%2Bdfsg-1.3~deb12u6?arch=amd64&distro=debian-12.15&upstream=libxml2","type":"deb","version":"2.9.14+dfsg-1.3~deb12u6","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libxml2-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libxml2-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libxml2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6653","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6653","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6653","cwe":"CWE-416","type":"Secondary","source":"security@ubuntu.com"},{"cve":"CVE-2026-6653","cwe":"CWE-611","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-6653","date":"2026-10-08","epss":0.00355,"percentile":0.27192}],"risk":0.33370000000000005,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6653","description":"Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling."},"relatedVulnerabilities":[{"id":"CVE-2026-6653","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6653","cwe":"CWE-416","type":"Secondary","source":"security@ubuntu.com"},{"cve":"CVE-2026-6653","cwe":"CWE-611","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-6653","date":"2026-10-08","epss":0.00355,"percentile":0.27192}],"urls":["https://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/2141260","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6653","description":"Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling."}]},{"artifact":{"id":"6dec48f68a6dce02","cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"libheif1","purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","type":"deb","version":"1.15.1-1+deb12u1","language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libheif"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-32741","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-32741","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32741","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-32741","cwe":"CWE-120","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32741","date":"2026-10-08","epss":0.00449,"percentile":0.37026}],"risk":0.32777,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-32741","description":"libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and below contain a heap buffer overflow in MaskImageCodec::decode_mask_image(). When decoding a HEIF file containing a mask image (mski), the function copies the full iloc extent data into a pixel buffer using memcpy(dst, data.data(), data.size()). The copy length data.size() is determined by the iloc extent in the file (attacker-controlled), while the destination buffer is sized based on the declared image dimensions. Because no upper-bound check exists on the data length, a crafted file whose iloc extent exceeds the pixel buffer allocation overflows the heap. The vulnerable single-memcpy branch is reached when the mskC property specifies bits_per_pixel = 8 and the ispe property declares an even width ≥ 64 (so that stride == width), with no changes to default security limits or external codec plugins required. This issue has been fixed in version 1.22.0."},"relatedVulnerabilities":[{"id":"CVE-2026-32741","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32741","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-32741","cwe":"CWE-120","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32741","date":"2026-10-08","epss":0.00449,"percentile":0.37026}],"urls":["https://github.com/strukturag/libheif/releases/tag/v1.22.0","https://github.com/strukturag/libheif/security/advisories/GHSA-j3w5-7whq-p37q","https://access.redhat.com/security/cve/CVE-2026-32741","https://bugzilla.redhat.com/show_bug.cgi?id=2480002","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32741.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32741","description":"libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and below contain a heap buffer overflow in MaskImageCodec::decode_mask_image(). When decoding a HEIF file containing a mask image (mski), the function copies the full iloc extent data into a pixel buffer using memcpy(dst, data.data(), data.size()). The copy length data.size() is determined by the iloc extent in the file (attacker-controlled), while the destination buffer is sized based on the declared image dimensions. Because no upper-bound check exists on the data length, a crafted file whose iloc extent exceeds the pixel buffer allocation overflows the heap. The vulnerable single-memcpy branch is reached when the mskC property specifies bits_per_pixel = 8 and the ispe property declares an even width ≥ 64 (so that stride == width), with no changes to default security limits or external codec plugins required. This issue has been fixed in version 1.22.0."}]},{"artifact":{"id":"ac9f96c95674631f","cpes":["cpe:2.3:a:libopenexr-3-1-30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1-30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-3-1-30","purl":"pkg:deb/debian/libopenexr-3-1-30@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-3-1-30/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-3-1-30/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53532","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53532","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53532","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-53532","date":"2026-10-08","epss":0.00445,"percentile":0.36661}],"risk":0.32485,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53532","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a crafted HTJ2K-compressed EXR file causes an unconditional process abort in any application that calls exr_start_read() on untrusted input, resulting in denial of service. The crash is triggered by a QCD marker whose lower five bits are zero, which OpenEXR passes into the vendored OpenJPH library while constructing the codestream and evaluating its quantization delta parameters. OpenJPH uses an assertion rather than a recoverable error to validate those bits, so any invalid value calls abort() directly and cannot be intercepted by surrounding error handling, a problem compounded by OpenEXR wrapping only its internal HT header parser in error handling while leaving the later codestream read and construction calls unprotected. This issue has been resolved in version 3.4.13."},"relatedVulnerabilities":[{"id":"CVE-2026-53532","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53532","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-53532","date":"2026-10-08","epss":0.00445,"percentile":0.36661}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.13","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-2f85-52wj-hc3c"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53532","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a crafted HTJ2K-compressed EXR file causes an unconditional process abort in any application that calls exr_start_read() on untrusted input, resulting in denial of service. The crash is triggered by a QCD marker whose lower five bits are zero, which OpenEXR passes into the vendored OpenJPH library while constructing the codestream and evaluating its quantization delta parameters. OpenJPH uses an assertion rather than a recoverable error to validate those bits, so any invalid value calls abort() directly and cannot be intercepted by surrounding error handling, a problem compounded by OpenEXR wrapping only its internal HT header parser in error handling while leaving the later codestream read and construction calls unprotected. This issue has been resolved in version 3.4.13."}]},{"artifact":{"id":"229cdd73859abf63","cpes":["cpe:2.3:a:libopenexr-dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-dev","purl":"pkg:deb/debian/libopenexr-dev@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.list"}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53532","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53532","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53532","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-53532","date":"2026-10-08","epss":0.00445,"percentile":0.36661}],"risk":0.32485,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53532","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a crafted HTJ2K-compressed EXR file causes an unconditional process abort in any application that calls exr_start_read() on untrusted input, resulting in denial of service. The crash is triggered by a QCD marker whose lower five bits are zero, which OpenEXR passes into the vendored OpenJPH library while constructing the codestream and evaluating its quantization delta parameters. OpenJPH uses an assertion rather than a recoverable error to validate those bits, so any invalid value calls abort() directly and cannot be intercepted by surrounding error handling, a problem compounded by OpenEXR wrapping only its internal HT header parser in error handling while leaving the later codestream read and construction calls unprotected. This issue has been resolved in version 3.4.13."},"relatedVulnerabilities":[{"id":"CVE-2026-53532","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53532","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-53532","date":"2026-10-08","epss":0.00445,"percentile":0.36661}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.13","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-2f85-52wj-hc3c"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53532","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a crafted HTJ2K-compressed EXR file causes an unconditional process abort in any application that calls exr_start_read() on untrusted input, resulting in denial of service. The crash is triggered by a QCD marker whose lower five bits are zero, which OpenEXR passes into the vendored OpenJPH library while constructing the codestream and evaluating its quantization delta parameters. OpenJPH uses an assertion rather than a recoverable error to validate those bits, so any invalid value calls abort() directly and cannot be intercepted by surrounding error handling, a problem compounded by OpenEXR wrapping only its internal HT header parser in error handling while leaving the later codestream read and construction calls unprotected. This issue has been resolved in version 3.4.13."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6019","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6019","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6019","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6019","date":"2026-10-08","epss":0.00584,"percentile":0.46224}],"risk":0.32411999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6019","description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value."},"relatedVulnerabilities":[{"id":"CVE-2026-6019","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6019","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6019","date":"2026-10-08","epss":0.00584,"percentile":0.46224}],"urls":["https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c","https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104","https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8","https://github.com/python/cpython/issues/90309","https://github.com/python/cpython/pull/148848","https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6019","description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6019","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6019","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6019","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6019","date":"2026-10-08","epss":0.00584,"percentile":0.46224}],"risk":0.32411999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6019","description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value."},"relatedVulnerabilities":[{"id":"CVE-2026-6019","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6019","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6019","date":"2026-10-08","epss":0.00584,"percentile":0.46224}],"urls":["https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c","https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104","https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8","https://github.com/python/cpython/issues/90309","https://github.com/python/cpython/pull/148848","https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6019","description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-6019","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6019","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6019","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6019","date":"2026-10-08","epss":0.00584,"percentile":0.46224}],"risk":0.32411999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6019","description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value."},"relatedVulnerabilities":[{"id":"CVE-2026-6019","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6019","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6019","date":"2026-10-08","epss":0.00584,"percentile":0.46224}],"urls":["https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c","https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104","https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8","https://github.com/python/cpython/issues/90309","https://github.com/python/cpython/pull/148848","https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6019","description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6019","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6019","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6019","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6019","date":"2026-10-08","epss":0.00584,"percentile":0.46224}],"risk":0.32411999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6019","description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value."},"relatedVulnerabilities":[{"id":"CVE-2026-6019","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6019","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6019","date":"2026-10-08","epss":0.00584,"percentile":0.46224}],"urls":["https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c","https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104","https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8","https://github.com/python/cpython/issues/90309","https://github.com/python/cpython/pull/148848","https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6019","description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value."}]},{"artifact":{"id":"35095459163cc193","cpes":["cpe:2.3:a:libtiff-dev:libtiff-dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libtiff-dev:libtiff_dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libtiff_dev:libtiff-dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libtiff_dev:libtiff_dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libtiff:libtiff-dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libtiff:libtiff_dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"name":"libtiff-dev","purl":"pkg:deb/debian/libtiff-dev@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","type":"deb","version":"4.5.0-6+deb12u4","language":"","licenses":["Hylafax"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libtiff-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libtiff-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"tiff"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12912","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-12912","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12912","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-12912","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-12912","date":"2026-10-08","epss":0.00433,"percentile":0.35555}],"risk":0.3204199999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12912","description":"A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-12912","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12912","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-12912","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-12912","date":"2026-10-08","epss":0.00433,"percentile":0.35555}],"urls":["https://access.redhat.com/errata/RHSA-2026:34890","https://access.redhat.com/errata/RHSA-2026:41892","https://access.redhat.com/errata/RHSA-2026:42668","https://access.redhat.com/errata/RHSA-2026:47183","https://access.redhat.com/errata/RHSA-2026:47184","https://access.redhat.com/errata/RHSA-2026:49671","https://access.redhat.com/errata/RHSA-2026:50774","https://access.redhat.com/errata/RHSA-2026:54638","https://access.redhat.com/errata/RHSA-2026:54640","https://access.redhat.com/errata/RHSA-2026:54642","https://access.redhat.com/errata/RHSA-2026:58545","https://access.redhat.com/errata/RHSA-2026:58553","https://access.redhat.com/errata/RHSA-2026:58554","https://access.redhat.com/errata/RHSA-2026:58556","https://access.redhat.com/errata/RHSA-2026:61657","https://access.redhat.com/errata/RHSA-2026:69292","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-12912","https://bugzilla.redhat.com/show_bug.cgi?id=2492871","https://gitlab.com/libtiff/libtiff/-/merge_requests/873","https://gitlab.com/libtiff/libtiff/-/work_items/824","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12912.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12912","description":"A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS)."}]},{"artifact":{"id":"d41dc3f05b6fab73","cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"name":"libtiff6","purl":"pkg:deb/debian/libtiff6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","type":"deb","version":"4.5.0-6+deb12u4","language":"","licenses":["Hylafax"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"tiff"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12912","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-12912","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12912","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-12912","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-12912","date":"2026-10-08","epss":0.00433,"percentile":0.35555}],"risk":0.3204199999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12912","description":"A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-12912","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12912","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-12912","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-12912","date":"2026-10-08","epss":0.00433,"percentile":0.35555}],"urls":["https://access.redhat.com/errata/RHSA-2026:34890","https://access.redhat.com/errata/RHSA-2026:41892","https://access.redhat.com/errata/RHSA-2026:42668","https://access.redhat.com/errata/RHSA-2026:47183","https://access.redhat.com/errata/RHSA-2026:47184","https://access.redhat.com/errata/RHSA-2026:49671","https://access.redhat.com/errata/RHSA-2026:50774","https://access.redhat.com/errata/RHSA-2026:54638","https://access.redhat.com/errata/RHSA-2026:54640","https://access.redhat.com/errata/RHSA-2026:54642","https://access.redhat.com/errata/RHSA-2026:58545","https://access.redhat.com/errata/RHSA-2026:58553","https://access.redhat.com/errata/RHSA-2026:58554","https://access.redhat.com/errata/RHSA-2026:58556","https://access.redhat.com/errata/RHSA-2026:61657","https://access.redhat.com/errata/RHSA-2026:69292","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-12912","https://bugzilla.redhat.com/show_bug.cgi?id=2492871","https://gitlab.com/libtiff/libtiff/-/merge_requests/873","https://gitlab.com/libtiff/libtiff/-/work_items/824","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12912.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12912","description":"A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS)."}]},{"artifact":{"id":"05a611224dadb719","cpes":["cpe:2.3:a:libtiffxx6:libtiffxx6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"name":"libtiffxx6","purl":"pkg:deb/debian/libtiffxx6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","type":"deb","version":"4.5.0-6+deb12u4","language":"","licenses":["Hylafax"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiffxx6/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libtiffxx6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiffxx6:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libtiffxx6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"tiff"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12912","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-12912","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12912","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-12912","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-12912","date":"2026-10-08","epss":0.00433,"percentile":0.35555}],"risk":0.3204199999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12912","description":"A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-12912","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12912","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-12912","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-12912","date":"2026-10-08","epss":0.00433,"percentile":0.35555}],"urls":["https://access.redhat.com/errata/RHSA-2026:34890","https://access.redhat.com/errata/RHSA-2026:41892","https://access.redhat.com/errata/RHSA-2026:42668","https://access.redhat.com/errata/RHSA-2026:47183","https://access.redhat.com/errata/RHSA-2026:47184","https://access.redhat.com/errata/RHSA-2026:49671","https://access.redhat.com/errata/RHSA-2026:50774","https://access.redhat.com/errata/RHSA-2026:54638","https://access.redhat.com/errata/RHSA-2026:54640","https://access.redhat.com/errata/RHSA-2026:54642","https://access.redhat.com/errata/RHSA-2026:58545","https://access.redhat.com/errata/RHSA-2026:58553","https://access.redhat.com/errata/RHSA-2026:58554","https://access.redhat.com/errata/RHSA-2026:58556","https://access.redhat.com/errata/RHSA-2026:61657","https://access.redhat.com/errata/RHSA-2026:69292","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-12912","https://bugzilla.redhat.com/show_bug.cgi?id=2492871","https://gitlab.com/libtiff/libtiff/-/merge_requests/873","https://gitlab.com/libtiff/libtiff/-/work_items/824","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12912.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12912","description":"A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS)."}]},{"artifact":{"id":"f131145b816a43ee","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux%402.38.1-5%2Bdeb12u3","type":"deb","version":"1:2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.38.1-5+deb12u3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"505a5613c52a45e2","cpes":["cpe:2.3:a:libblkid-dev:libblkid-dev:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libblkid-dev:libblkid_dev:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libblkid_dev:libblkid-dev:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libblkid_dev:libblkid_dev:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libblkid:libblkid-dev:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libblkid:libblkid_dev:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libblkid-dev","purl":"pkg:deb/debian/libblkid-dev@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libblkid-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libblkid-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"af35543f081d70bf","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"01ade8e049ac13ed","cpes":["cpe:2.3:a:libmount-dev:libmount-dev:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libmount-dev:libmount_dev:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libmount_dev:libmount-dev:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libmount_dev:libmount_dev:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libmount:libmount-dev:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libmount:libmount_dev:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libmount-dev","purl":"pkg:deb/debian/libmount-dev@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmount-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmount-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"3578a81ebb651f3d","cpes":["cpe:2.3:a:libmount1:libmount1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"ecee94562f1ce06f","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"2049f4c13963925a","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"e75e0a2b6968d414","cpes":["cpe:2.3:a:mount:mount:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"b11f4a313957922c","cpes":["cpe:2.3:a:util-linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"fc9180bcad1f4d49","cpes":["cpe:2.3:a:util-linux-extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux-extra","purl":"pkg:deb/debian/util-linux-extra@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux-extra/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/util-linux-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.conffiles","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/util-linux-extra.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/util-linux-extra.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.list","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/util-linux-extra.list"},{"path":"/var/lib/dpkg/info/util-linux-extra.postinst","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/util-linux-extra.postinst"},{"path":"/var/lib/dpkg/info/util-linux-extra.postrm","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/util-linux-extra.postrm"},{"path":"/var/lib/dpkg/info/util-linux-extra.preinst","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/util-linux-extra.preinst"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"05a15b9bad441604","cpes":["cpe:2.3:a:uuid-dev:uuid-dev:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:uuid-dev:uuid_dev:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:uuid_dev:uuid-dev:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:uuid_dev:uuid_dev:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:uuid:uuid-dev:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:uuid:uuid_dev:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"uuid-dev","purl":"pkg:deb/debian/uuid-dev@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/uuid-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/uuid-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/uuid-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/uuid-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"6dec48f68a6dce02","cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"libheif1","purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","type":"deb","version":"1.15.1-1+deb12u1","language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libheif"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-68431","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-68431","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68431","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-68431","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68431","date":"2026-10-08","epss":0.00427,"percentile":0.34934}],"risk":0.31171000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68431","description":"libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the overlay image item path triggers a heap buffer over-read in `HeifPixelImage::overlay()`. The function computes a negative row length (likely from an unclipped overlay rectangle or invalid offsets), which then underflows when converted to `size_t` and is passed to `memcpy`, causing a very large read past the end of the source plane and a crash. Version 1.21.0 contains a patch. As a workaround, avoid decoding images using `iovl` overlay boxes."},"relatedVulnerabilities":[{"id":"CVE-2025-68431","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68431","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-68431","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68431","date":"2026-10-08","epss":0.00427,"percentile":0.34934}],"urls":["https://github.com/strukturag/libheif/commit/b8c12a7b70f46c9516711a988483bed377b78d46","https://github.com/strukturag/libheif/releases/tag/v1.21.0","https://github.com/strukturag/libheif/security/advisories/GHSA-j87x-4gmq-cqfq"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68431","description":"libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the overlay image item path triggers a heap buffer over-read in `HeifPixelImage::overlay()`. The function computes a negative row length (likely from an unclipped overlay rectangle or invalid offsets), which then underflows when converted to `size_t` and is passed to `memcpy`, causing a very large read past the end of the source plane and a crash. Version 1.21.0 contains a patch. As a workaround, avoid decoding images using `iovl` overlay boxes."}]},{"artifact":{"id":"ac9f96c95674631f","cpes":["cpe:2.3:a:libopenexr-3-1-30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1-30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-3-1-30","purl":"pkg:deb/debian/libopenexr-3-1-30@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-3-1-30/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-3-1-30/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59982","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-59982","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59982","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59982","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59982","date":"2026-10-08","epss":0.00423,"percentile":0.34563}],"risk":0.30879,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59982","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 can return an out-of-bounds pointer from TypedDeepImageChannel::row() when a crafted deep EXR has a nonzero dataWindow origin. This vulnerability occurs because the API combines zero-based row access with an absolute-coordinate-adjusted base pointer, allowing a crash or limited information disclosure. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."},"relatedVulnerabilities":[{"id":"CVE-2026-59982","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59982","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59982","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59982","date":"2026-10-08","epss":0.00423,"percentile":0.34563}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1","https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c","https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-6662-fq6f-93mp"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59982","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 can return an out-of-bounds pointer from TypedDeepImageChannel::row() when a crafted deep EXR has a nonzero dataWindow origin. This vulnerability occurs because the API combines zero-based row access with an absolute-coordinate-adjusted base pointer, allowing a crash or limited information disclosure. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."}]},{"artifact":{"id":"229cdd73859abf63","cpes":["cpe:2.3:a:libopenexr-dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-dev","purl":"pkg:deb/debian/libopenexr-dev@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.list"}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59982","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-59982","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59982","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59982","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59982","date":"2026-10-08","epss":0.00423,"percentile":0.34563}],"risk":0.30879,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59982","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 can return an out-of-bounds pointer from TypedDeepImageChannel::row() when a crafted deep EXR has a nonzero dataWindow origin. This vulnerability occurs because the API combines zero-based row access with an absolute-coordinate-adjusted base pointer, allowing a crash or limited information disclosure. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."},"relatedVulnerabilities":[{"id":"CVE-2026-59982","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59982","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59982","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59982","date":"2026-10-08","epss":0.00423,"percentile":0.34563}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1","https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c","https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-6662-fq6f-93mp"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59982","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 can return an out-of-bounds pointer from TypedDeepImageChannel::row() when a crafted deep EXR has a nonzero dataWindow origin. This vulnerability occurs because the API combines zero-based row access with an absolute-coordinate-adjusted base pointer, allowing a crash or limited information disclosure. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."}]},{"artifact":{"id":"ac9f96c95674631f","cpes":["cpe:2.3:a:libopenexr-3-1-30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1-30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-3-1-30","purl":"pkg:deb/debian/libopenexr-3-1-30@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-3-1-30/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-3-1-30/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59189","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-59189","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59189","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59189","date":"2026-10-08","epss":0.00423,"percentile":0.34562}],"risk":0.30879,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59189","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In OpenEXRUtil versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.12, the documented TypedDeepImageChannel<T>::row() API can return an out-of-bounds pointer when a deep image has a non-zero dataWindow origin, resulting in a heap out-of-bounds read and crash, with potential information disclosure under a controlled heap layout. The flaw arises because ImfDeepImageChannel uses two conflicting coordinate models: at(x, y) uses absolute coordinates (with _base offset by dataWindow.min), while row(r) is documented as 0-based logical access. For a non-zero dataWindow.min, row(0) therefore points outside the _sampleListPointers allocation instead of at the first logical row. This issue is fixed in versions 3.3.13 and 3.4.13."},"relatedVulnerabilities":[{"id":"CVE-2026-59189","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59189","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59189","date":"2026-10-08","epss":0.00423,"percentile":0.34562}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1","https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c","https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-hwmv-39v6-739m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59189","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In OpenEXRUtil versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.12, the documented TypedDeepImageChannel<T>::row() API can return an out-of-bounds pointer when a deep image has a non-zero dataWindow origin, resulting in a heap out-of-bounds read and crash, with potential information disclosure under a controlled heap layout. The flaw arises because ImfDeepImageChannel uses two conflicting coordinate models: at(x, y) uses absolute coordinates (with _base offset by dataWindow.min), while row(r) is documented as 0-based logical access. For a non-zero dataWindow.min, row(0) therefore points outside the _sampleListPointers allocation instead of at the first logical row. This issue is fixed in versions 3.3.13 and 3.4.13."}]},{"artifact":{"id":"ac9f96c95674631f","cpes":["cpe:2.3:a:libopenexr-3-1-30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1-30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-3-1-30","purl":"pkg:deb/debian/libopenexr-3-1-30@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-3-1-30/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-3-1-30/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59981","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-59981","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59981","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59981","date":"2026-10-08","epss":0.00423,"percentile":0.34562}],"risk":0.30879,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59981","description":"OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, the OpenEXRUtil library returns an out-of-bounds pointer from the SampleCountChannel::row() API when a deep image has a non-zero dataWindow origin. The row() accessor is documented as 0-based and computes its address from an internal base that is offset for absolute pixel coordinates, so the two coordinate models conflict whenever dataWindow.min is non-zero. For a deep image whose data window has a large negative vertical origin, row(0) points far outside the allocated sample-count buffer. An application that opens an attacker-controlled deep EXR file and accesses sample counts through row() performs an out-of-bounds read, which can crash the process or, under a controlled heap layout, return adjacent heap memory as sample-count values. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."},"relatedVulnerabilities":[{"id":"CVE-2026-59981","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59981","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59981","date":"2026-10-08","epss":0.00423,"percentile":0.34562}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1","https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c","https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-m799-ffc3-8pxc"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59981","description":"OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, the OpenEXRUtil library returns an out-of-bounds pointer from the SampleCountChannel::row() API when a deep image has a non-zero dataWindow origin. The row() accessor is documented as 0-based and computes its address from an internal base that is offset for absolute pixel coordinates, so the two coordinate models conflict whenever dataWindow.min is non-zero. For a deep image whose data window has a large negative vertical origin, row(0) points far outside the allocated sample-count buffer. An application that opens an attacker-controlled deep EXR file and accesses sample counts through row() performs an out-of-bounds read, which can crash the process or, under a controlled heap layout, return adjacent heap memory as sample-count values. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."}]},{"artifact":{"id":"229cdd73859abf63","cpes":["cpe:2.3:a:libopenexr-dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-dev","purl":"pkg:deb/debian/libopenexr-dev@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.list"}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59189","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-59189","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59189","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59189","date":"2026-10-08","epss":0.00423,"percentile":0.34562}],"risk":0.30879,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59189","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In OpenEXRUtil versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.12, the documented TypedDeepImageChannel<T>::row() API can return an out-of-bounds pointer when a deep image has a non-zero dataWindow origin, resulting in a heap out-of-bounds read and crash, with potential information disclosure under a controlled heap layout. The flaw arises because ImfDeepImageChannel uses two conflicting coordinate models: at(x, y) uses absolute coordinates (with _base offset by dataWindow.min), while row(r) is documented as 0-based logical access. For a non-zero dataWindow.min, row(0) therefore points outside the _sampleListPointers allocation instead of at the first logical row. This issue is fixed in versions 3.3.13 and 3.4.13."},"relatedVulnerabilities":[{"id":"CVE-2026-59189","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59189","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59189","date":"2026-10-08","epss":0.00423,"percentile":0.34562}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1","https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c","https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-hwmv-39v6-739m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59189","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In OpenEXRUtil versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.12, the documented TypedDeepImageChannel<T>::row() API can return an out-of-bounds pointer when a deep image has a non-zero dataWindow origin, resulting in a heap out-of-bounds read and crash, with potential information disclosure under a controlled heap layout. The flaw arises because ImfDeepImageChannel uses two conflicting coordinate models: at(x, y) uses absolute coordinates (with _base offset by dataWindow.min), while row(r) is documented as 0-based logical access. For a non-zero dataWindow.min, row(0) therefore points outside the _sampleListPointers allocation instead of at the first logical row. This issue is fixed in versions 3.3.13 and 3.4.13."}]},{"artifact":{"id":"229cdd73859abf63","cpes":["cpe:2.3:a:libopenexr-dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-dev","purl":"pkg:deb/debian/libopenexr-dev@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.list"}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59981","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-59981","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59981","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59981","date":"2026-10-08","epss":0.00423,"percentile":0.34562}],"risk":0.30879,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59981","description":"OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, the OpenEXRUtil library returns an out-of-bounds pointer from the SampleCountChannel::row() API when a deep image has a non-zero dataWindow origin. The row() accessor is documented as 0-based and computes its address from an internal base that is offset for absolute pixel coordinates, so the two coordinate models conflict whenever dataWindow.min is non-zero. For a deep image whose data window has a large negative vertical origin, row(0) points far outside the allocated sample-count buffer. An application that opens an attacker-controlled deep EXR file and accesses sample counts through row() performs an out-of-bounds read, which can crash the process or, under a controlled heap layout, return adjacent heap memory as sample-count values. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."},"relatedVulnerabilities":[{"id":"CVE-2026-59981","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59981","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59981","date":"2026-10-08","epss":0.00423,"percentile":0.34562}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1","https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c","https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-m799-ffc3-8pxc"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59981","description":"OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, the OpenEXRUtil library returns an out-of-bounds pointer from the SampleCountChannel::row() API when a deep image has a non-zero dataWindow origin. The row() accessor is documented as 0-based and computes its address from an internal base that is offset for absolute pixel coordinates, so the two coordinate models conflict whenever dataWindow.min is non-zero. For a deep image whose data window has a large negative vertical origin, row(0) points far outside the allocated sample-count buffer. An application that opens an attacker-controlled deep EXR file and accesses sample counts through row() performs an out-of-bounds read, which can crash the process or, under a controlled heap layout, return adjacent heap memory as sample-count values. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."}]},{"artifact":{"id":"4ce32b1800528ec6","cpes":["cpe:2.3:a:libssl-dev:libssl-dev:3.0.22-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libssl-dev:libssl_dev:3.0.22-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libssl_dev:libssl-dev:3.0.22-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libssl_dev:libssl_dev:3.0.22-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl-dev:3.0.22-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl_dev:3.0.22-1\\~deb12u1:*:*:*:*:*:*:*"],"name":"libssl-dev","purl":"pkg:deb/debian/libssl-dev@3.0.22-1~deb12u1?arch=amd64&distro=debian-12.15&upstream=openssl","type":"deb","version":"3.0.22-1~deb12u1","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libssl-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libssl-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84782","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.22-1~deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.30615,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly.  Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region.  CWE: CWE-125: Out-of-bounds Read  Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue.  The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer.  Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build.  The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-84782","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"fbd3380dfe250adc","cpes":["cpe:2.3:a:libssl3:libssl3:3.0.22-1\\~deb12u1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:deb/debian/libssl3@3.0.22-1~deb12u1?arch=amd64&distro=debian-12.15&upstream=openssl","type":"deb","version":"3.0.22-1~deb12u1","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/libssl3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3:amd64.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/libssl3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84782","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.22-1~deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.30615,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly.  Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region.  CWE: CWE-125: Out-of-bounds Read  Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue.  The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer.  Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build.  The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-84782","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"2420af2d098dd3c1","cpes":["cpe:2.3:a:openssl:openssl:3.0.22-1\\~deb12u1:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.0.22-1~deb12u1?arch=amd64&distro=debian-12.15","type":"deb","version":"3.0.22-1~deb12u1","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-84782","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.22-1~deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.30615,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly.  Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region.  CWE: CWE-125: Out-of-bounds Read  Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue.  The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer.  Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build.  The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-84782","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"ac9f96c95674631f","cpes":["cpe:2.3:a:libopenexr-3-1-30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1-30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-3-1-30","purl":"pkg:deb/debian/libopenexr-3-1-30@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-3-1-30/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-3-1-30/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59186","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-59186","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59186","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59186","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59186","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59186","date":"2026-10-08","epss":0.00415,"percentile":0.33772}],"risk":0.30295,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59186","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, a crafted tiled EXR can trigger a heap out-of-bounds write on 32-bit/ILP32 builds when read through the public TiledRgbaInputFile RGBA API. The file uses a small 40x40 dataWindow but a 65537x65537 tile size. On ILP32, the Array2D<Rgba> tile-conversion buffer size calculation overflows, allocates a much smaller heap buffer, and tile decode writes past that allocation. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."},"relatedVulnerabilities":[{"id":"CVE-2026-59186","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59186","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59186","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59186","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59186","date":"2026-10-08","epss":0.00415,"percentile":0.33772}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/71907b44ce9a1b05bf3934b8a7821752750731ab","https://github.com/AcademySoftwareFoundation/openexr/commit/904141d3a1f86327ad1e2b93fc92ce2dd5881d34","https://github.com/AcademySoftwareFoundation/openexr/commit/b1a5887372772d79328f4eb42b7f86352a38170b","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-f667-c4wm-c8gq"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59186","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, a crafted tiled EXR can trigger a heap out-of-bounds write on 32-bit/ILP32 builds when read through the public TiledRgbaInputFile RGBA API. The file uses a small 40x40 dataWindow but a 65537x65537 tile size. On ILP32, the Array2D<Rgba> tile-conversion buffer size calculation overflows, allocates a much smaller heap buffer, and tile decode writes past that allocation. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."}]},{"artifact":{"id":"229cdd73859abf63","cpes":["cpe:2.3:a:libopenexr-dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-dev","purl":"pkg:deb/debian/libopenexr-dev@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.list"}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59186","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-59186","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59186","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59186","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59186","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59186","date":"2026-10-08","epss":0.00415,"percentile":0.33772}],"risk":0.30295,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59186","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, a crafted tiled EXR can trigger a heap out-of-bounds write on 32-bit/ILP32 builds when read through the public TiledRgbaInputFile RGBA API. The file uses a small 40x40 dataWindow but a 65537x65537 tile size. On ILP32, the Array2D<Rgba> tile-conversion buffer size calculation overflows, allocates a much smaller heap buffer, and tile decode writes past that allocation. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."},"relatedVulnerabilities":[{"id":"CVE-2026-59186","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59186","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59186","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59186","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59186","date":"2026-10-08","epss":0.00415,"percentile":0.33772}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/71907b44ce9a1b05bf3934b8a7821752750731ab","https://github.com/AcademySoftwareFoundation/openexr/commit/904141d3a1f86327ad1e2b93fc92ce2dd5881d34","https://github.com/AcademySoftwareFoundation/openexr/commit/b1a5887372772d79328f4eb42b7f86352a38170b","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-f667-c4wm-c8gq"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59186","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, a crafted tiled EXR can trigger a heap out-of-bounds write on 32-bit/ILP32 builds when read through the public TiledRgbaInputFile RGBA API. The file uses a small 40x40 dataWindow but a 65537x65537 tile size. On ILP32, the Array2D<Rgba> tile-conversion buffer size calculation overflows, allocates a much smaller heap buffer, and tile decode writes past that allocation. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"risk":0.302755,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname argument isn't supplied then hostname verification would be silently skipped.   This defect could lead to programs where certificate hostname verification *appeared* to be succeeding with SSLContext.check_hostname = True and no ValueError being raised due to misconfiguration.   If the program passes a server_hostname value that isn't an empty string or None to any of these APIs then certificate hostname verification proceeds as expected and the program is not affected by this vulnerability.   Mitigating this vulnerability doesn't require updating Python or applying the patch. To mitigate, pass a valid non-None and non-empty server_hostname value to SSLContext.wrap_bio(), asyncio.create_connection(), or asyncio.loop.start_tls() and certificate hostname verification will proceed as expected. Upgrading to the latest version of Python or applying the patch only changes the behavior from silently skipping hostname verification to raising a ValueError, similar to SSLContext.wrap_socket(), when server_hostname isn't supplied."},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"risk":0.302755,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname argument isn't supplied then hostname verification would be silently skipped.   This defect could lead to programs where certificate hostname verification *appeared* to be succeeding with SSLContext.check_hostname = True and no ValueError being raised due to misconfiguration.   If the program passes a server_hostname value that isn't an empty string or None to any of these APIs then certificate hostname verification proceeds as expected and the program is not affected by this vulnerability.   Mitigating this vulnerability doesn't require updating Python or applying the patch. To mitigate, pass a valid non-None and non-empty server_hostname value to SSLContext.wrap_bio(), asyncio.create_connection(), or asyncio.loop.start_tls() and certificate hostname verification will proceed as expected. Upgrading to the latest version of Python or applying the patch only changes the behavior from silently skipping hostname verification to raising a ValueError, similar to SSLContext.wrap_socket(), when server_hostname isn't supplied."},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"risk":0.302755,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname argument isn't supplied then hostname verification would be silently skipped.   This defect could lead to programs where certificate hostname verification *appeared* to be succeeding with SSLContext.check_hostname = True and no ValueError being raised due to misconfiguration.   If the program passes a server_hostname value that isn't an empty string or None to any of these APIs then certificate hostname verification proceeds as expected and the program is not affected by this vulnerability.   Mitigating this vulnerability doesn't require updating Python or applying the patch. To mitigate, pass a valid non-None and non-empty server_hostname value to SSLContext.wrap_bio(), asyncio.create_connection(), or asyncio.loop.start_tls() and certificate hostname verification will proceed as expected. Upgrading to the latest version of Python or applying the patch only changes the behavior from silently skipping hostname verification to raising a ValueError, similar to SSLContext.wrap_socket(), when server_hostname isn't supplied."},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"risk":0.302755,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname argument isn't supplied then hostname verification would be silently skipped.   This defect could lead to programs where certificate hostname verification *appeared* to be succeeding with SSLContext.check_hostname = True and no ValueError being raised due to misconfiguration.   If the program passes a server_hostname value that isn't an empty string or None to any of these APIs then certificate hostname verification proceeds as expected and the program is not affected by this vulnerability.   Mitigating this vulnerability doesn't require updating Python or applying the patch. To mitigate, pass a valid non-None and non-empty server_hostname value to SSLContext.wrap_bio(), asyncio.create_connection(), or asyncio.loop.start_tls() and certificate hostname verification will proceed as expected. Upgrading to the latest version of Python or applying the patch only changes the behavior from silently skipping hostname verification to raising a ValueError, similar to SSLContext.wrap_socket(), when server_hostname isn't supplied."},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-1502","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-1502","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1502","date":"2026-10-08","epss":0.00562,"percentile":0.45016}],"risk":0.30067,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1502","description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host."},"relatedVulnerabilities":[{"id":"CVE-2026-1502","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1502","date":"2026-10-08","epss":0.00562,"percentile":0.45016}],"urls":["https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69","https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53","https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e","https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd","https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed","https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec","https://github.com/python/cpython/issues/146211","https://github.com/python/cpython/pull/146212","https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/","http://www.openwall.com/lists/oss-security/2026/04/11/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1502","description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-1502","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-1502","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1502","date":"2026-10-08","epss":0.00562,"percentile":0.45016}],"risk":0.30067,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1502","description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host."},"relatedVulnerabilities":[{"id":"CVE-2026-1502","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1502","date":"2026-10-08","epss":0.00562,"percentile":0.45016}],"urls":["https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69","https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53","https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e","https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd","https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed","https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec","https://github.com/python/cpython/issues/146211","https://github.com/python/cpython/pull/146212","https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/","http://www.openwall.com/lists/oss-security/2026/04/11/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1502","description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-1502","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-1502","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1502","date":"2026-10-08","epss":0.00562,"percentile":0.45016}],"risk":0.30067,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1502","description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host."},"relatedVulnerabilities":[{"id":"CVE-2026-1502","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1502","date":"2026-10-08","epss":0.00562,"percentile":0.45016}],"urls":["https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69","https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53","https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e","https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd","https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed","https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec","https://github.com/python/cpython/issues/146211","https://github.com/python/cpython/pull/146212","https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/","http://www.openwall.com/lists/oss-security/2026/04/11/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1502","description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-1502","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-1502","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1502","date":"2026-10-08","epss":0.00562,"percentile":0.45016}],"risk":0.30067,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1502","description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host."},"relatedVulnerabilities":[{"id":"CVE-2026-1502","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1502","date":"2026-10-08","epss":0.00562,"percentile":0.45016}],"urls":["https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69","https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53","https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e","https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd","https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed","https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec","https://github.com/python/cpython/issues/146211","https://github.com/python/cpython/pull/146212","https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/","http://www.openwall.com/lists/oss-security/2026/04/11/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1502","description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host."}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-12064","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-12064","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-08","epss":0.00399,"percentile":0.32065}],"risk":0.29924999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error."},"relatedVulnerabilities":[{"id":"CVE-2026-12064","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-08","epss":0.00399,"percentile":0.32065}],"urls":["https://curl.se/docs/CVE-2026-12064.html","https://curl.se/docs/CVE-2026-12064.json","https://hackerone.com/reports/3797526"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12064","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-12064","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-08","epss":0.00399,"percentile":0.32065}],"risk":0.29924999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error."},"relatedVulnerabilities":[{"id":"CVE-2026-12064","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-08","epss":0.00399,"percentile":0.32065}],"urls":["https://curl.se/docs/CVE-2026-12064.html","https://curl.se/docs/CVE-2026-12064.json","https://hackerone.com/reports/3797526"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12064","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-12064","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-08","epss":0.00399,"percentile":0.32065}],"risk":0.29924999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error."},"relatedVulnerabilities":[{"id":"CVE-2026-12064","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-08","epss":0.00399,"percentile":0.32065}],"urls":["https://curl.se/docs/CVE-2026-12064.html","https://curl.se/docs/CVE-2026-12064.json","https://hackerone.com/reports/3797526"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error."}]},{"artifact":{"id":"610d5f28e0c6125d","cpes":["cpe:2.3:a:libcurl4-openssl-dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl-dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4-openssl-dev","purl":"pkg:deb/debian/libcurl4-openssl-dev@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4-openssl-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libcurl4-openssl-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12064","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-12064","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-08","epss":0.00399,"percentile":0.32065}],"risk":0.29924999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error."},"relatedVulnerabilities":[{"id":"CVE-2026-12064","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-08","epss":0.00399,"percentile":0.32065}],"urls":["https://curl.se/docs/CVE-2026-12064.html","https://curl.se/docs/CVE-2026-12064.json","https://hackerone.com/reports/3797526"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error."}]},{"artifact":{"id":"85369d5a3515d91a","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u4:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=expat","type":"deb","version":"2.5.0-1+deb12u4","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-41080","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-41080","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41080","cwe":"CWE-331","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-41080","date":"2026-10-08","epss":0.00398,"percentile":0.31902}],"risk":0.2985,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-41080","description":"libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document."},"relatedVulnerabilities":[{"id":"CVE-2026-41080","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41080","cwe":"CWE-331","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-41080","date":"2026-10-08","epss":0.00398,"percentile":0.31902}],"urls":["https://blog.hartwork.org/posts/expat-2-8-0-released/","https://github.com/libexpat/libexpat/issues/47","https://github.com/libexpat/libexpat/pull/1183","https://www.openwall.com/lists/oss-security/2026/04/26/1","http://www.openwall.com/lists/oss-security/2026/04/26/1","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41080","description":"libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document."}]},{"artifact":{"id":"d7331d5da68fa7f9","cpes":["cpe:2.3:a:libexpat1-dev:libexpat1-dev:2.5.0-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1-dev:libexpat1_dev:2.5.0-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1-dev:2.5.0-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1_dev:2.5.0-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1-dev:2.5.0-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1_dev:2.5.0-1\\+deb12u4:*:*:*:*:*:*:*"],"name":"libexpat1-dev","purl":"pkg:deb/debian/libexpat1-dev@2.5.0-1%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=expat","type":"deb","version":"2.5.0-1+deb12u4","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libexpat1-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-41080","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-41080","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41080","cwe":"CWE-331","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-41080","date":"2026-10-08","epss":0.00398,"percentile":0.31902}],"risk":0.2985,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-41080","description":"libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document."},"relatedVulnerabilities":[{"id":"CVE-2026-41080","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41080","cwe":"CWE-331","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-41080","date":"2026-10-08","epss":0.00398,"percentile":0.31902}],"urls":["https://blog.hartwork.org/posts/expat-2-8-0-released/","https://github.com/libexpat/libexpat/issues/47","https://github.com/libexpat/libexpat/pull/1183","https://www.openwall.com/lists/oss-security/2026/04/26/1","http://www.openwall.com/lists/oss-security/2026/04/26/1","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41080","description":"libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document."}]},{"artifact":{"id":"4cab7ef7de016d31","cpes":["cpe:2.3:a:libpam-modules:libpam-modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*"],"name":"libpam-modules","purl":"pkg:deb/debian/libpam-modules@1.5.2-6%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=pam","type":"deb","version":"1.5.2-6+deb12u2","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libpam-modules/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pam","version":"1.5.2-6+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"risk":0.2975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"372dffabd059479c","cpes":["cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules-bin:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*"],"name":"libpam-modules-bin","purl":"pkg:deb/debian/libpam-modules-bin@1.5.2-6%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=pam","type":"deb","version":"1.5.2-6+deb12u2","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules-bin/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libpam-modules-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.list","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.list"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pam","version":"1.5.2-6+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"risk":0.2975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"ca1034d5d24bcf54","cpes":["cpe:2.3:a:libpam-runtime:libpam-runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-runtime:libpam_runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam-runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam_runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*"],"name":"libpam-runtime","purl":"pkg:deb/debian/libpam-runtime@1.5.2-6%2Bdeb12u2?arch=all&distro=debian-12.15&upstream=pam","type":"deb","version":"1.5.2-6+deb12u2","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-runtime/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libpam-runtime/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.conffiles","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libpam-runtime.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libpam-runtime.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.list","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libpam-runtime.list"},{"path":"/var/lib/dpkg/info/libpam-runtime.postinst","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libpam-runtime.postinst"},{"path":"/var/lib/dpkg/info/libpam-runtime.postrm","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libpam-runtime.postrm"},{"path":"/var/lib/dpkg/info/libpam-runtime.prerm","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libpam-runtime.prerm"},{"path":"/var/lib/dpkg/info/libpam-runtime.templates","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libpam-runtime.templates"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pam","version":"1.5.2-6+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"risk":0.2975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"87d8465053cf56c8","cpes":["cpe:2.3:a:libpam0g:libpam0g:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*"],"name":"libpam0g","purl":"pkg:deb/debian/libpam0g@1.5.2-6%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=pam","type":"deb","version":"1.5.2-6+deb12u2","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam0g/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libpam0g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pam","version":"1.5.2-6+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"risk":0.2975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8932","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8932","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"risk":0.297,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key."},"relatedVulnerabilities":[{"id":"CVE-2026-8932","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"urls":["https://curl.se/docs/CVE-2026-8932.html","https://curl.se/docs/CVE-2026-8932.json","https://hackerone.com/reports/3733910"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8932","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8932","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"risk":0.297,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key."},"relatedVulnerabilities":[{"id":"CVE-2026-8932","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"urls":["https://curl.se/docs/CVE-2026-8932.html","https://curl.se/docs/CVE-2026-8932.json","https://hackerone.com/reports/3733910"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8932","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8932","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"risk":0.297,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key."},"relatedVulnerabilities":[{"id":"CVE-2026-8932","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"urls":["https://curl.se/docs/CVE-2026-8932.html","https://curl.se/docs/CVE-2026-8932.json","https://hackerone.com/reports/3733910"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key."}]},{"artifact":{"id":"610d5f28e0c6125d","cpes":["cpe:2.3:a:libcurl4-openssl-dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl-dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4-openssl-dev","purl":"pkg:deb/debian/libcurl4-openssl-dev@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4-openssl-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libcurl4-openssl-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8932","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8932","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"risk":0.297,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key."},"relatedVulnerabilities":[{"id":"CVE-2026-8932","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"urls":["https://curl.se/docs/CVE-2026-8932.html","https://curl.se/docs/CVE-2026-8932.json","https://hackerone.com/reports/3733910"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key."}]},{"artifact":{"id":"ac9f96c95674631f","cpes":["cpe:2.3:a:libopenexr-3-1-30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1-30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-3-1-30","purl":"pkg:deb/debian/libopenexr-3-1-30@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-3-1-30/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-3-1-30/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-59184","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59184","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59184","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59184","date":"2026-10-08","epss":0.00404,"percentile":0.32498}],"risk":0.29492,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59184","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 allow a crafted EXR with a nonzero dataWindow.min to make TypedFlatImageChannel::row() return an invalid heap pointer, causing out-of-bounds or use-after-free writes. This occurs when an application writes rows through FlatHalfChannel::row(). Affected consumers are tools, converters, render pipeline components, or image-processing services that accept untrusted EXR files and use FlatHalfChannel::row() on loaded images. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."},"relatedVulnerabilities":[{"id":"CVE-2026-59184","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59184","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59184","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59184","date":"2026-10-08","epss":0.00404,"percentile":0.32498}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1","https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c","https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-pqp9-558c-453q"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59184","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 allow a crafted EXR with a nonzero dataWindow.min to make TypedFlatImageChannel::row() return an invalid heap pointer, causing out-of-bounds or use-after-free writes. This occurs when an application writes rows through FlatHalfChannel::row(). Affected consumers are tools, converters, render pipeline components, or image-processing services that accept untrusted EXR files and use FlatHalfChannel::row() on loaded images. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."}]},{"artifact":{"id":"229cdd73859abf63","cpes":["cpe:2.3:a:libopenexr-dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-dev","purl":"pkg:deb/debian/libopenexr-dev@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.list"}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-59184","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59184","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59184","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59184","date":"2026-10-08","epss":0.00404,"percentile":0.32498}],"risk":0.29492,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59184","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 allow a crafted EXR with a nonzero dataWindow.min to make TypedFlatImageChannel::row() return an invalid heap pointer, causing out-of-bounds or use-after-free writes. This occurs when an application writes rows through FlatHalfChannel::row(). Affected consumers are tools, converters, render pipeline components, or image-processing services that accept untrusted EXR files and use FlatHalfChannel::row() on loaded images. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."},"relatedVulnerabilities":[{"id":"CVE-2026-59184","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59184","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59184","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59184","date":"2026-10-08","epss":0.00404,"percentile":0.32498}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1","https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c","https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-pqp9-558c-453q"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59184","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 allow a crafted EXR with a nonzero dataWindow.min to make TypedFlatImageChannel::row() return an invalid heap pointer, causing out-of-bounds or use-after-free writes. This occurs when an application writes rows through FlatHalfChannel::row(). Affected consumers are tools, converters, render pipeline components, or image-processing services that accept untrusted EXR files and use FlatHalfChannel::row() on loaded images. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."}]},{"artifact":{"id":"ac9f96c95674631f","cpes":["cpe:2.3:a:libopenexr-3-1-30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1-30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-3-1-30","purl":"pkg:deb/debian/libopenexr-3-1-30@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-3-1-30/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-3-1-30/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59187","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-59187","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59187","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59187","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59187","date":"2026-10-08","epss":0.00402,"percentile":0.32301}],"risk":0.29346,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59187","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13 are vulnerable to a heap out-of-bounds write when exrmetrics reads a crafted deep scanline EXR. This occurs with pixel conversion options such as --pixelmode float or --bench because DeepSlice requests FLOAT output while the backing sample buffers are allocated using the input HALF element size. The issue is fixed in versions 3.3.13 and 3.4.14."},"relatedVulnerabilities":[{"id":"CVE-2026-59187","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59187","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59187","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59187","date":"2026-10-08","epss":0.00402,"percentile":0.32301}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/46e70220dc91dbc1341fac4671704e970b450585","https://github.com/AcademySoftwareFoundation/openexr/commit/7e772dd704b9b5d6dc2564647d89f7813f608e94","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-6jj8-cxcr-j8hm"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59187","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13 are vulnerable to a heap out-of-bounds write when exrmetrics reads a crafted deep scanline EXR. This occurs with pixel conversion options such as --pixelmode float or --bench because DeepSlice requests FLOAT output while the backing sample buffers are allocated using the input HALF element size. The issue is fixed in versions 3.3.13 and 3.4.14."}]},{"artifact":{"id":"229cdd73859abf63","cpes":["cpe:2.3:a:libopenexr-dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-dev","purl":"pkg:deb/debian/libopenexr-dev@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.list"}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59187","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-59187","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59187","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59187","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59187","date":"2026-10-08","epss":0.00402,"percentile":0.32301}],"risk":0.29346,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59187","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13 are vulnerable to a heap out-of-bounds write when exrmetrics reads a crafted deep scanline EXR. This occurs with pixel conversion options such as --pixelmode float or --bench because DeepSlice requests FLOAT output while the backing sample buffers are allocated using the input HALF element size. The issue is fixed in versions 3.3.13 and 3.4.14."},"relatedVulnerabilities":[{"id":"CVE-2026-59187","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59187","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59187","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59187","date":"2026-10-08","epss":0.00402,"percentile":0.32301}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/46e70220dc91dbc1341fac4671704e970b450585","https://github.com/AcademySoftwareFoundation/openexr/commit/7e772dd704b9b5d6dc2564647d89f7813f608e94","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-6jj8-cxcr-j8hm"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59187","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13 are vulnerable to a heap out-of-bounds write when exrmetrics reads a crafted deep scanline EXR. This occurs with pixel conversion options such as --pixelmode float or --bench because DeepSlice requests FLOAT output while the backing sample buffers are allocated using the input HALF element size. The issue is fixed in versions 3.3.13 and 3.4.14."}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-5545","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5545","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5545","cwe":"CWE-613","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5545","date":"2026-10-08","epss":0.0051,"percentile":0.41602}],"risk":0.29324999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5545","description":"libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials.  An application that first uses Negotiate authentication to a server with `user1:password1` and then does another operation to the same server asking for any authentication method but for `user2:password2` (while the previous connection is still alive) - the second request gets confused and wrongly reuses the same connection and sends the new request over that connection thinking it uses a mix of user1's and user2's credentials when it is in fact still using the connection authenticated for user1..."},"relatedVulnerabilities":[{"id":"CVE-2026-5545","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5545","cwe":"CWE-613","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5545","date":"2026-10-08","epss":0.0051,"percentile":0.41602}],"urls":["https://curl.se/docs/CVE-2026-5545.html","https://curl.se/docs/CVE-2026-5545.json","https://hackerone.com/reports/3642555"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5545","description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1..."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5545","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5545","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5545","cwe":"CWE-613","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5545","date":"2026-10-08","epss":0.0051,"percentile":0.41602}],"risk":0.29324999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5545","description":"libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials.  An application that first uses Negotiate authentication to a server with `user1:password1` and then does another operation to the same server asking for any authentication method but for `user2:password2` (while the previous connection is still alive) - the second request gets confused and wrongly reuses the same connection and sends the new request over that connection thinking it uses a mix of user1's and user2's credentials when it is in fact still using the connection authenticated for user1..."},"relatedVulnerabilities":[{"id":"CVE-2026-5545","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5545","cwe":"CWE-613","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5545","date":"2026-10-08","epss":0.0051,"percentile":0.41602}],"urls":["https://curl.se/docs/CVE-2026-5545.html","https://curl.se/docs/CVE-2026-5545.json","https://hackerone.com/reports/3642555"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5545","description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1..."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5545","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5545","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5545","cwe":"CWE-613","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5545","date":"2026-10-08","epss":0.0051,"percentile":0.41602}],"risk":0.29324999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5545","description":"libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials.  An application that first uses Negotiate authentication to a server with `user1:password1` and then does another operation to the same server asking for any authentication method but for `user2:password2` (while the previous connection is still alive) - the second request gets confused and wrongly reuses the same connection and sends the new request over that connection thinking it uses a mix of user1's and user2's credentials when it is in fact still using the connection authenticated for user1..."},"relatedVulnerabilities":[{"id":"CVE-2026-5545","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5545","cwe":"CWE-613","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5545","date":"2026-10-08","epss":0.0051,"percentile":0.41602}],"urls":["https://curl.se/docs/CVE-2026-5545.html","https://curl.se/docs/CVE-2026-5545.json","https://hackerone.com/reports/3642555"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5545","description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1..."}]},{"artifact":{"id":"610d5f28e0c6125d","cpes":["cpe:2.3:a:libcurl4-openssl-dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl-dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4-openssl-dev","purl":"pkg:deb/debian/libcurl4-openssl-dev@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4-openssl-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libcurl4-openssl-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5545","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5545","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5545","cwe":"CWE-613","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5545","date":"2026-10-08","epss":0.0051,"percentile":0.41602}],"risk":0.29324999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5545","description":"libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials.  An application that first uses Negotiate authentication to a server with `user1:password1` and then does another operation to the same server asking for any authentication method but for `user2:password2` (while the previous connection is still alive) - the second request gets confused and wrongly reuses the same connection and sends the new request over that connection thinking it uses a mix of user1's and user2's credentials when it is in fact still using the connection authenticated for user1..."},"relatedVulnerabilities":[{"id":"CVE-2026-5545","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5545","cwe":"CWE-613","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5545","date":"2026-10-08","epss":0.0051,"percentile":0.41602}],"urls":["https://curl.se/docs/CVE-2026-5545.html","https://curl.se/docs/CVE-2026-5545.json","https://hackerone.com/reports/3642555"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5545","description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1..."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"risk":0.293035,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.     This behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.     The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64  alphabet they are expecting or verify that their application would not be  affected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"risk":0.293035,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.     This behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.     The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64  alphabet they are expecting or verify that their application would not be  affected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"risk":0.293035,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.     This behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.     The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64  alphabet they are expecting or verify that their application would not be  affected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"risk":0.293035,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.     This behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.     The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64  alphabet they are expecting or verify that their application would not be  affected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-82209","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-82209","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"risk":0.292805,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`).  Instead of coercing it into a strict host-only cookie, libcurl saves the cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is inappropriately included in subsequent outbound requests or HTTP redirects to arbitrary sibling subdomains under the same public suffix (e.g., `attacker.co.uk`)."},"relatedVulnerabilities":[{"id":"CVE-2026-82209","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"urls":["https://curl.se/docs/CVE-2026-82209.html","https://curl.se/docs/CVE-2026-82209.json","https://hackerone.com/reports/3972385"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`)."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82209","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-82209","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"risk":0.292805,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`).  Instead of coercing it into a strict host-only cookie, libcurl saves the cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is inappropriately included in subsequent outbound requests or HTTP redirects to arbitrary sibling subdomains under the same public suffix (e.g., `attacker.co.uk`)."},"relatedVulnerabilities":[{"id":"CVE-2026-82209","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"urls":["https://curl.se/docs/CVE-2026-82209.html","https://curl.se/docs/CVE-2026-82209.json","https://hackerone.com/reports/3972385"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`)."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82209","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-82209","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"risk":0.292805,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`).  Instead of coercing it into a strict host-only cookie, libcurl saves the cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is inappropriately included in subsequent outbound requests or HTTP redirects to arbitrary sibling subdomains under the same public suffix (e.g., `attacker.co.uk`)."},"relatedVulnerabilities":[{"id":"CVE-2026-82209","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"urls":["https://curl.se/docs/CVE-2026-82209.html","https://curl.se/docs/CVE-2026-82209.json","https://hackerone.com/reports/3972385"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`)."}]},{"artifact":{"id":"610d5f28e0c6125d","cpes":["cpe:2.3:a:libcurl4-openssl-dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl-dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4-openssl-dev","purl":"pkg:deb/debian/libcurl4-openssl-dev@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4-openssl-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libcurl4-openssl-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82209","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-82209","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"risk":0.292805,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`).  Instead of coercing it into a strict host-only cookie, libcurl saves the cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is inappropriately included in subsequent outbound requests or HTTP redirects to arbitrary sibling subdomains under the same public suffix (e.g., `attacker.co.uk`)."},"relatedVulnerabilities":[{"id":"CVE-2026-82209","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"urls":["https://curl.se/docs/CVE-2026-82209.html","https://curl.se/docs/CVE-2026-82209.json","https://hackerone.com/reports/3972385"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`)."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"risk":0.29156,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"05457b2d3472913c","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"risk":0.29156,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"risk":0.29156,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"be9fcdc16d52ab8f","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"risk":0.29156,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"d82af4e74abd89bc","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","type":"deb","version":"1:9.2p1-2+deb12u10","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2008-3234","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2008-3234","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2008-3234","cwe":"CWE-264","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2008-3234","date":"2026-10-08","epss":0.05773,"percentile":0.92898}],"risk":0.28865,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2008-3234","description":"sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux roles by appending a :/ (colon slash) sequence, followed by the role name, to the username."},"relatedVulnerabilities":[{"id":"CVE-2008-3234","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":6.5,"impactScore":6.5,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2008-3234","cwe":"CWE-264","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2008-3234","date":"2026-10-08","epss":0.05773,"percentile":0.92898}],"urls":["http://www.securityfocus.com/bid/30276","https://exchange.xforce.ibmcloud.com/vulnerabilities/44037","https://www.exploit-db.com/exploits/6094"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2008-3234","description":"sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux roles by appending a :/ (colon slash) sequence, followed by the role name, to the username."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-20796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"risk":0.28785000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."},"relatedVulnerabilities":[{"id":"CVE-2018-20796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."}]},{"artifact":{"id":"05457b2d3472913c","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-20796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"risk":0.28785000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."},"relatedVulnerabilities":[{"id":"CVE-2018-20796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-20796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"risk":0.28785000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."},"relatedVulnerabilities":[{"id":"CVE-2018-20796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."}]},{"artifact":{"id":"be9fcdc16d52ab8f","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-20796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"risk":0.28785000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."},"relatedVulnerabilities":[{"id":"CVE-2018-20796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."}]},{"artifact":{"id":"ac9f96c95674631f","cpes":["cpe:2.3:a:libopenexr-3-1-30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1-30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-3-1-30","purl":"pkg:deb/debian/libopenexr-3-1-30@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-3-1-30/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-3-1-30/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-64181","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-64181","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-64181","cwe":"CWE-457","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-64181","date":"2026-10-08","epss":0.00382,"percentile":0.30073}],"risk":0.2865,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-64181","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.0 through 3.3.5 and 3.4.0 through 3.4.2, while fuzzing `openexr_exrcheck_fuzzer`, Valgrind reports a conditional branch depending on uninitialized data inside `generic_unpack`. This indicates a use of uninitialized memory. The issue can result in undefined behavior and/or a potential crash/denial of service. Versions 3.3.6 and 3.4.3 fix the issue."},"relatedVulnerabilities":[{"id":"CVE-2025-64181","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-64181","cwe":"CWE-457","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-64181","date":"2026-10-08","epss":0.00382,"percentile":0.30073}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-3h9h-qfvw-98hq","https://github.com/user-attachments/files/23024726/archive0.zip","https://github.com/user-attachments/files/23024736/archive1.zip","https://github.com/user-attachments/files/23024740/archive2.zip","https://github.com/user-attachments/files/23024744/archive3.zip","https://github.com/user-attachments/files/23024746/archive4.zip"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-64181","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.0 through 3.3.5 and 3.4.0 through 3.4.2, while fuzzing `openexr_exrcheck_fuzzer`, Valgrind reports a conditional branch depending on uninitialized data inside `generic_unpack`. This indicates a use of uninitialized memory. The issue can result in undefined behavior and/or a potential crash/denial of service. Versions 3.3.6 and 3.4.3 fix the issue."}]},{"artifact":{"id":"229cdd73859abf63","cpes":["cpe:2.3:a:libopenexr-dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-dev","purl":"pkg:deb/debian/libopenexr-dev@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.list"}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-64181","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-64181","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-64181","cwe":"CWE-457","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-64181","date":"2026-10-08","epss":0.00382,"percentile":0.30073}],"risk":0.2865,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-64181","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.0 through 3.3.5 and 3.4.0 through 3.4.2, while fuzzing `openexr_exrcheck_fuzzer`, Valgrind reports a conditional branch depending on uninitialized data inside `generic_unpack`. This indicates a use of uninitialized memory. The issue can result in undefined behavior and/or a potential crash/denial of service. Versions 3.3.6 and 3.4.3 fix the issue."},"relatedVulnerabilities":[{"id":"CVE-2025-64181","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-64181","cwe":"CWE-457","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-64181","date":"2026-10-08","epss":0.00382,"percentile":0.30073}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-3h9h-qfvw-98hq","https://github.com/user-attachments/files/23024726/archive0.zip","https://github.com/user-attachments/files/23024736/archive1.zip","https://github.com/user-attachments/files/23024740/archive2.zip","https://github.com/user-attachments/files/23024744/archive3.zip","https://github.com/user-attachments/files/23024746/archive4.zip"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-64181","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.0 through 3.3.5 and 3.4.0 through 3.4.2, while fuzzing `openexr_exrcheck_fuzzer`, Valgrind reports a conditional branch depending on uninitialized data inside `generic_unpack`. This indicates a use of uninitialized memory. The issue can result in undefined behavior and/or a potential crash/denial of service. Versions 3.3.6 and 3.4.3 fix the issue."}]},{"artifact":{"id":"ef5a5a7d880f3e73","cpes":["cpe:2.3:a:wget:wget:1.21.3-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"wget","purl":"pkg:deb/debian/wget@1.21.3-1%2Bdeb12u1?arch=amd64&distro=debian-12.15","type":"deb","version":"1.21.3-1+deb12u1","language":"","licenses":["sha256:c58cb5a2d94f35f0e9b0f1a038d48b73477aa12782ff17328c21d8a86f5f99d5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/wget/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/wget/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.conffiles","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/wget.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/wget.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.list","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/wget.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-58471","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"wget","version":"1.21.3-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58471","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58471","cwe":"CWE-122","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58471","date":"2026-10-08","epss":0.0039,"percentile":0.30936}],"risk":0.28469999999999995,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58471","description":"GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response."},"relatedVulnerabilities":[{"id":"CVE-2026-58471","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58471","cwe":"CWE-122","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58471","date":"2026-10-08","epss":0.0039,"percentile":0.30936}],"urls":["https://gitlab.com/gnuwget/wget/-/commit/c2640fe5171c59f87c58dc9fcb195b2d18b010ee","https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-overflow-via-convert-fname-in-url-c"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58471","description":"GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response."}]},{"artifact":{"id":"ef5a5a7d880f3e73","cpes":["cpe:2.3:a:wget:wget:1.21.3-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"wget","purl":"pkg:deb/debian/wget@1.21.3-1%2Bdeb12u1?arch=amd64&distro=debian-12.15","type":"deb","version":"1.21.3-1+deb12u1","language":"","licenses":["sha256:c58cb5a2d94f35f0e9b0f1a038d48b73477aa12782ff17328c21d8a86f5f99d5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/wget/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/wget/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.conffiles","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/wget.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/wget.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.list","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/wget.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-58472","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"wget","version":"1.21.3-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58472","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58472","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58472","date":"2026-10-08","epss":0.0039,"percentile":0.30936}],"risk":0.28469999999999995,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58472","description":"GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase."},"relatedVulnerabilities":[{"id":"CVE-2026-58472","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58472","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58472","date":"2026-10-08","epss":0.0039,"percentile":0.30936}],"urls":["https://gitlab.com/gnuwget/wget/-/commit/dd692d9cea5335b181d877ae917fe6e75587a812","https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-overflow-via-html-attribute-encoding"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58472","description":"GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase."}]},{"artifact":{"id":"077923f667034501","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/debian/zlib1g@1%3A1.2.13.dfsg-1?arch=amd64&distro=debian-12.15&upstream=zlib","type":"deb","version":"1:1.2.13.dfsg-1","language":"","licenses":["Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"zlib","version":"1:1.2.13.dfsg-1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-85091","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"risk":0.28124,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-85091","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."}]},{"artifact":{"id":"3f28e512f3f6e928","cpes":["cpe:2.3:a:zlib1g-dev:zlib1g-dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:zlib1g-dev:zlib1g_dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:zlib1g_dev:zlib1g-dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:zlib1g_dev:zlib1g_dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:zlib1g:zlib1g-dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:zlib1g:zlib1g_dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*"],"name":"zlib1g-dev","purl":"pkg:deb/debian/zlib1g-dev@1%3A1.2.13.dfsg-1?arch=amd64&distro=debian-12.15&upstream=zlib","type":"deb","version":"1:1.2.13.dfsg-1","language":"","licenses":["Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/zlib1g-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/zlib1g-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"zlib","version":"1:1.2.13.dfsg-1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-85091","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"risk":0.28124,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-85091","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."}]},{"artifact":{"id":"35095459163cc193","cpes":["cpe:2.3:a:libtiff-dev:libtiff-dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libtiff-dev:libtiff_dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libtiff_dev:libtiff-dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libtiff_dev:libtiff_dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libtiff:libtiff-dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libtiff:libtiff_dev:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"name":"libtiff-dev","purl":"pkg:deb/debian/libtiff-dev@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","type":"deb","version":"4.5.0-6+deb12u4","language":"","licenses":["Hylafax"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libtiff-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libtiff-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"tiff"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-16232","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2017-16232","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-16232","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-16232","date":"2026-10-08","epss":0.05584,"percentile":0.92685}],"risk":0.2792,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-16232","description":"LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue"},"relatedVulnerabilities":[{"id":"CVE-2017-16232","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-16232","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-16232","date":"2026-10-08","epss":0.05584,"percentile":0.92685}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00036.html","http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00041.html","http://packetstormsecurity.com/files/150896/LibTIFF-4.0.8-Memory-Leak.html","http://seclists.org/fulldisclosure/2018/Dec/32","http://seclists.org/fulldisclosure/2018/Dec/47","http://www.openwall.com/lists/oss-security/2017/11/01/11","http://www.openwall.com/lists/oss-security/2017/11/01/3","http://www.openwall.com/lists/oss-security/2017/11/01/7","http://www.openwall.com/lists/oss-security/2017/11/01/8","http://www.securityfocus.com/bid/101696"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-16232","description":"LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue"}]},{"artifact":{"id":"d41dc3f05b6fab73","cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"name":"libtiff6","purl":"pkg:deb/debian/libtiff6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","type":"deb","version":"4.5.0-6+deb12u4","language":"","licenses":["Hylafax"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"tiff"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-16232","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2017-16232","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-16232","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-16232","date":"2026-10-08","epss":0.05584,"percentile":0.92685}],"risk":0.2792,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-16232","description":"LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue"},"relatedVulnerabilities":[{"id":"CVE-2017-16232","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-16232","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-16232","date":"2026-10-08","epss":0.05584,"percentile":0.92685}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00036.html","http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00041.html","http://packetstormsecurity.com/files/150896/LibTIFF-4.0.8-Memory-Leak.html","http://seclists.org/fulldisclosure/2018/Dec/32","http://seclists.org/fulldisclosure/2018/Dec/47","http://www.openwall.com/lists/oss-security/2017/11/01/11","http://www.openwall.com/lists/oss-security/2017/11/01/3","http://www.openwall.com/lists/oss-security/2017/11/01/7","http://www.openwall.com/lists/oss-security/2017/11/01/8","http://www.securityfocus.com/bid/101696"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-16232","description":"LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue"}]},{"artifact":{"id":"05a611224dadb719","cpes":["cpe:2.3:a:libtiffxx6:libtiffxx6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"name":"libtiffxx6","purl":"pkg:deb/debian/libtiffxx6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","type":"deb","version":"4.5.0-6+deb12u4","language":"","licenses":["Hylafax"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiffxx6/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libtiffxx6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiffxx6:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libtiffxx6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"tiff"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-16232","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2017-16232","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-16232","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-16232","date":"2026-10-08","epss":0.05584,"percentile":0.92685}],"risk":0.2792,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-16232","description":"LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue"},"relatedVulnerabilities":[{"id":"CVE-2017-16232","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-16232","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-16232","date":"2026-10-08","epss":0.05584,"percentile":0.92685}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00036.html","http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00041.html","http://packetstormsecurity.com/files/150896/LibTIFF-4.0.8-Memory-Leak.html","http://seclists.org/fulldisclosure/2018/Dec/32","http://seclists.org/fulldisclosure/2018/Dec/47","http://www.openwall.com/lists/oss-security/2017/11/01/11","http://www.openwall.com/lists/oss-security/2017/11/01/3","http://www.openwall.com/lists/oss-security/2017/11/01/7","http://www.openwall.com/lists/oss-security/2017/11/01/8","http://www.securityfocus.com/bid/101696"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-16232","description":"LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue"}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-80230","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-80230","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"risk":0.27825,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected."},"relatedVulnerabilities":[{"id":"CVE-2026-80230","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"urls":["https://curl.se/docs/CVE-2026-80230.html","https://curl.se/docs/CVE-2026-80230.json","https://hackerone.com/reports/3969300"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80230","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-80230","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"risk":0.27825,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected."},"relatedVulnerabilities":[{"id":"CVE-2026-80230","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"urls":["https://curl.se/docs/CVE-2026-80230.html","https://curl.se/docs/CVE-2026-80230.json","https://hackerone.com/reports/3969300"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80230","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-80230","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"risk":0.27825,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected."},"relatedVulnerabilities":[{"id":"CVE-2026-80230","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"urls":["https://curl.se/docs/CVE-2026-80230.html","https://curl.se/docs/CVE-2026-80230.json","https://hackerone.com/reports/3969300"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected."}]},{"artifact":{"id":"610d5f28e0c6125d","cpes":["cpe:2.3:a:libcurl4-openssl-dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl-dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4-openssl-dev","purl":"pkg:deb/debian/libcurl4-openssl-dev@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4-openssl-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libcurl4-openssl-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80230","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-80230","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"risk":0.27825,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected."},"relatedVulnerabilities":[{"id":"CVE-2026-80230","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"urls":["https://curl.se/docs/CVE-2026-80230.html","https://curl.se/docs/CVE-2026-80230.json","https://hackerone.com/reports/3969300"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected."}]},{"artifact":{"id":"d82af4e74abd89bc","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","type":"deb","version":"1:9.2p1-2+deb12u10","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60002","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-60002","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":9.4,"impactScore":5.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60002","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60002","date":"2026-10-08","epss":0.003,"percentile":0.20792}],"risk":0.276,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60002","description":"ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)"},"relatedVulnerabilities":[{"id":"CVE-2026-60002","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":9.4,"impactScore":5.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60002","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60002","date":"2026-10-08","epss":0.003,"percentile":0.20792}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60002","description":"ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)"}]},{"artifact":{"id":"47f6ae6b597dbb7b","cpes":["cpe:2.3:a:cpp-12:cpp-12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:cpp-12:cpp_12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:cpp_12:cpp-12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:cpp_12:cpp_12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:cpp:cpp-12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:cpp:cpp_12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"cpp-12","purl":"pkg:deb/debian/cpp-12@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/cpp-12.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/cpp-12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/cpp-12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/cpp-12.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/cpp-12.list"}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"6ff8ff63ca8b7466","cpes":["cpe:2.3:a:g\\+\\+-12:g\\+\\+-12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-12:g\\+\\+_12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_12:g\\+\\+-12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_12:g\\+\\+_12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+:g\\+\\+-12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+:g\\+\\+_12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"g++-12","purl":"pkg:deb/debian/g%2B%2B-12@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/g++-12.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/g++-12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/g++-12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/g++-12.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/g++-12.list"}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"5c074d6bc3f2ee94","cpes":["cpe:2.3:a:gcc-12:gcc-12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-12:gcc_12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12:gcc-12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12:gcc_12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc-12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc_12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"gcc-12","purl":"pkg:deb/debian/gcc-12@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/gcc-12.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/gcc-12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/gcc-12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-12.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/gcc-12.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"58c10ea7ffbc22a3","cpes":["cpe:2.3:a:gcc-12-base:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-12-base:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12_base:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12_base:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-12:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-12:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"gcc-12-base","purl":"pkg:deb/debian/gcc-12-base@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/gcc-12-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-12-base:amd64.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/gcc-12-base:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"45a0296b4a207092","cpes":["cpe:2.3:a:libasan8:libasan8:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"libasan8","purl":"pkg:deb/debian/libasan8@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libasan8:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libasan8:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libasan8/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"50514db327ffe1b7","cpes":["cpe:2.3:a:libatomic1:libatomic1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"libatomic1","purl":"pkg:deb/debian/libatomic1@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libatomic1:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libatomic1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libatomic1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"4d6867490f2ee31b","cpes":["cpe:2.3:a:libcc1-0:libcc1-0:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libcc1-0:libcc1_0:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libcc1_0:libcc1-0:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libcc1_0:libcc1_0:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libcc1:libcc1-0:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libcc1:libcc1_0:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"libcc1-0","purl":"pkg:deb/debian/libcc1-0@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcc1-0:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libcc1-0:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libcc1-0/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"0a2c9fc9336a4052","cpes":["cpe:2.3:a:libgcc-12-dev:libgcc-12-dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-12-dev:libgcc_12_dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_12_dev:libgcc-12-dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_12_dev:libgcc_12_dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-12:libgcc-12-dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-12:libgcc_12_dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_12:libgcc-12-dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_12:libgcc_12_dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc-12-dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc_12_dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"libgcc-12-dev","purl":"pkg:deb/debian/libgcc-12-dev@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libgcc-12-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libgcc-12-dev:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libgcc-12-dev/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"9454a77b5ea4561d","cpes":["cpe:2.3:a:libgcc-s1:libgcc-s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-s1:libgcc_s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc-s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc_s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc-s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc_s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"libgcc-s1","purl":"pkg:deb/debian/libgcc-s1@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libgcc-s1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcc-s1:amd64.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libgcc-s1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"5c053ad6c4a6e4ee","cpes":["cpe:2.3:a:libgomp1:libgomp1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"libgomp1","purl":"pkg:deb/debian/libgomp1@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libgomp1:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libgomp1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libgomp1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"5d691685b72bfc39","cpes":["cpe:2.3:a:libitm1:libitm1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"libitm1","purl":"pkg:deb/debian/libitm1@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libitm1:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libitm1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libitm1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"d282807e9bb10aec","cpes":["cpe:2.3:a:liblsan0:liblsan0:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"liblsan0","purl":"pkg:deb/debian/liblsan0@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/liblsan0:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/liblsan0:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/liblsan0/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"25f43087fc45f095","cpes":["cpe:2.3:a:libquadmath0:libquadmath0:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"libquadmath0","purl":"pkg:deb/debian/libquadmath0@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libquadmath0:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libquadmath0:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libquadmath0/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"23363a8f5cb22d0c","cpes":["cpe:2.3:a:libstdc\\+\\+-12-dev:libstdc\\+\\+-12-dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+-12-dev:libstdc\\+\\+_12_dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+_12_dev:libstdc\\+\\+-12-dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+_12_dev:libstdc\\+\\+_12_dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+-12:libstdc\\+\\+-12-dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+-12:libstdc\\+\\+_12_dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+_12:libstdc\\+\\+-12-dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+_12:libstdc\\+\\+_12_dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+-12-dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+_12_dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"libstdc++-12-dev","purl":"pkg:deb/debian/libstdc%2B%2B-12-dev@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libstdc++-12-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libstdc++-12-dev:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libstdc++-12-dev/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"c2f4fec51904a8ce","cpes":["cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"libstdc++6","purl":"pkg:deb/debian/libstdc%2B%2B6@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libstdc++6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"84ebb3dcf8d53111","cpes":["cpe:2.3:a:libtsan2:libtsan2:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"libtsan2","purl":"pkg:deb/debian/libtsan2@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libtsan2:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libtsan2:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libtsan2/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"eab3329c061e989f","cpes":["cpe:2.3:a:libubsan1:libubsan1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"libubsan1","purl":"pkg:deb/debian/libubsan1@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libubsan1:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libubsan1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libubsan1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"d82af4e74abd89bc","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","type":"deb","version":"1:9.2p1-2+deb12u10","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-20012","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2016-20012","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-20012","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-20012","cwe":"CWE-203","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-20012","date":"2026-10-08","epss":0.05326,"percentile":0.92406}],"risk":0.26630000000000004,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-20012","description":"OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not recognize user enumeration as a vulnerability for this product"},"relatedVulnerabilities":[{"id":"CVE-2016-20012","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-20012","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-20012","cwe":"CWE-203","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-20012","date":"2026-10-08","epss":0.05326,"percentile":0.92406}],"urls":["https://github.com/openssh/openssh-portable/blob/d0fffc88c8fe90c1815c6f4097bc8cbcabc0f3dd/auth2-pubkey.c#L261-L265","https://github.com/openssh/openssh-portable/pull/270","https://github.com/openssh/openssh-portable/pull/270#issuecomment-920577097","https://github.com/openssh/openssh-portable/pull/270#issuecomment-943909185","https://rushter.com/blog/public-ssh-keys/","https://security.netapp.com/advisory/ntap-20211014-0005/","https://utcc.utoronto.ca/~cks/space/blog/tech/SSHKeysAreInfoLeak","https://www.openwall.com/lists/oss-security/2018/08/24/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-20012","description":"OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not recognize user enumeration as a vulnerability for this product"}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-6429","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6429","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6429","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-6429","date":"2026-10-08","epss":0.00512,"percentile":0.41775}],"risk":0.26368,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6429","description":"When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances."},"relatedVulnerabilities":[{"id":"CVE-2026-6429","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6429","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-6429","date":"2026-10-08","epss":0.00512,"percentile":0.41775}],"urls":["https://curl.se/docs/CVE-2026-6429.html","https://curl.se/docs/CVE-2026-6429.json","https://hackerone.com/reports/3677759"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6429","description":"When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6429","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6429","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6429","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-6429","date":"2026-10-08","epss":0.00512,"percentile":0.41775}],"risk":0.26368,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6429","description":"When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances."},"relatedVulnerabilities":[{"id":"CVE-2026-6429","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6429","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-6429","date":"2026-10-08","epss":0.00512,"percentile":0.41775}],"urls":["https://curl.se/docs/CVE-2026-6429.html","https://curl.se/docs/CVE-2026-6429.json","https://hackerone.com/reports/3677759"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6429","description":"When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6429","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6429","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6429","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-6429","date":"2026-10-08","epss":0.00512,"percentile":0.41775}],"risk":0.26368,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6429","description":"When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances."},"relatedVulnerabilities":[{"id":"CVE-2026-6429","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6429","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-6429","date":"2026-10-08","epss":0.00512,"percentile":0.41775}],"urls":["https://curl.se/docs/CVE-2026-6429.html","https://curl.se/docs/CVE-2026-6429.json","https://hackerone.com/reports/3677759"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6429","description":"When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances."}]},{"artifact":{"id":"610d5f28e0c6125d","cpes":["cpe:2.3:a:libcurl4-openssl-dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl-dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4-openssl-dev","purl":"pkg:deb/debian/libcurl4-openssl-dev@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4-openssl-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libcurl4-openssl-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6429","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6429","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6429","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-6429","date":"2026-10-08","epss":0.00512,"percentile":0.41775}],"risk":0.26368,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6429","description":"When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances."},"relatedVulnerabilities":[{"id":"CVE-2026-6429","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6429","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-6429","date":"2026-10-08","epss":0.00512,"percentile":0.41775}],"urls":["https://curl.se/docs/CVE-2026-6429.html","https://curl.se/docs/CVE-2026-6429.json","https://hackerone.com/reports/3677759"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6429","description":"When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances."}]},{"artifact":{"id":"692b9197d4b21a92","cpes":["cpe:2.3:a:libldap-2.5-0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5-0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5_0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5_0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"],"name":"libldap-2.5-0","purl":"pkg:deb/debian/libldap-2.5-0@2.5.13%2Bdfsg-5?arch=amd64&distro=debian-12.15&upstream=openldap","type":"deb","version":"2.5.13+dfsg-5","language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.5-0/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/libldap-2.5-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.5-0:amd64.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/libldap-2.5-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2015-3276","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openldap","version":"2.5.13+dfsg-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2015-3276","fix":{"state":"not-fixed","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2015-3276","date":"2026-10-08","epss":0.05269,"percentile":0.92348}],"risk":0.26345,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2015-3276","description":"The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors."},"relatedVulnerabilities":[{"id":"CVE-2015-3276","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2015-3276","date":"2026-10-08","epss":0.05269,"percentile":0.92348}],"urls":["http://rhn.redhat.com/errata/RHSA-2015-2131.html","http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html","http://www.securitytracker.com/id/1034221","https://bugzilla.redhat.com/show_bug.cgi?id=1238322"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2015-3276","description":"The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors."}]},{"artifact":{"id":"6dec48f68a6dce02","cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"libheif1","purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","type":"deb","version":"1.15.1-1+deb12u1","language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libheif"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48029","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-48029","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48029","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-48029","cwe":"CWE-191","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-48029","date":"2026-10-08","epss":0.00359,"percentile":0.27627}],"risk":0.26206999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48029","description":"libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow. Version 1.22.0 fixes the issue."},"relatedVulnerabilities":[{"id":"CVE-2026-48029","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48029","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-48029","cwe":"CWE-191","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-48029","date":"2026-10-08","epss":0.00359,"percentile":0.27627}],"urls":["https://github.com/strukturag/libheif/commit/e523ec0bf379110b7c33d4c159f8b1202d332157","https://github.com/strukturag/libheif/security/advisories/GHSA-6x5f-qchq-cxqv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48029","description":"libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow. Version 1.22.0 fixes the issue."}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-6276","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6276","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-346","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6276","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6276","date":"2026-10-08","epss":0.00349,"percentile":0.26447}],"risk":0.26175,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6276","description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them."},"relatedVulnerabilities":[{"id":"CVE-2026-6276","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-346","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6276","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6276","date":"2026-10-08","epss":0.00349,"percentile":0.26447}],"urls":["https://curl.se/docs/CVE-2026-6276.html","https://curl.se/docs/CVE-2026-6276.json","https://hackerone.com/reports/3671818","http://www.openwall.com/lists/oss-security/2026/04/29/13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6276","description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6276","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6276","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-346","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6276","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6276","date":"2026-10-08","epss":0.00349,"percentile":0.26447}],"risk":0.26175,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6276","description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them."},"relatedVulnerabilities":[{"id":"CVE-2026-6276","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-346","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6276","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6276","date":"2026-10-08","epss":0.00349,"percentile":0.26447}],"urls":["https://curl.se/docs/CVE-2026-6276.html","https://curl.se/docs/CVE-2026-6276.json","https://hackerone.com/reports/3671818","http://www.openwall.com/lists/oss-security/2026/04/29/13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6276","description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6276","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6276","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-346","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6276","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6276","date":"2026-10-08","epss":0.00349,"percentile":0.26447}],"risk":0.26175,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6276","description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them."},"relatedVulnerabilities":[{"id":"CVE-2026-6276","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-346","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6276","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6276","date":"2026-10-08","epss":0.00349,"percentile":0.26447}],"urls":["https://curl.se/docs/CVE-2026-6276.html","https://curl.se/docs/CVE-2026-6276.json","https://hackerone.com/reports/3671818","http://www.openwall.com/lists/oss-security/2026/04/29/13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6276","description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them."}]},{"artifact":{"id":"610d5f28e0c6125d","cpes":["cpe:2.3:a:libcurl4-openssl-dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl-dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4-openssl-dev","purl":"pkg:deb/debian/libcurl4-openssl-dev@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4-openssl-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libcurl4-openssl-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6276","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6276","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-346","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6276","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6276","date":"2026-10-08","epss":0.00349,"percentile":0.26447}],"risk":0.26175,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6276","description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them."},"relatedVulnerabilities":[{"id":"CVE-2026-6276","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-346","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6276","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6276","date":"2026-10-08","epss":0.00349,"percentile":0.26447}],"urls":["https://curl.se/docs/CVE-2026-6276.html","https://curl.se/docs/CVE-2026-6276.json","https://hackerone.com/reports/3671818","http://www.openwall.com/lists/oss-security/2026/04/29/13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6276","description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them."}]},{"artifact":{"id":"f314997677a3aacc","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/debian/imagemagick@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.list"},{"path":"/var/lib/dpkg/info/imagemagick.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.postinst"},{"path":"/var/lib/dpkg/info/imagemagick.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.postrm"},{"path":"/var/lib/dpkg/info/imagemagick.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.preinst"},{"path":"/var/lib/dpkg/info/imagemagick.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-15607","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-15607","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"risk":0.26065000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."},"relatedVulnerabilities":[{"id":"CVE-2018-15607","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"urls":["http://www.securityfocus.com/bid/105137","https://github.com/ImageMagick/ImageMagick/issues/1255","https://usn.ubuntu.com/4034-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."}]},{"artifact":{"id":"58eb8529873897ef","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/debian/imagemagick-6-common@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-15607","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-15607","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"risk":0.26065000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."},"relatedVulnerabilities":[{"id":"CVE-2018-15607","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"urls":["http://www.securityfocus.com/bid/105137","https://github.com/ImageMagick/ImageMagick/issues/1255","https://usn.ubuntu.com/4034-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."}]},{"artifact":{"id":"81d27bbb42434f07","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/debian/imagemagick-6.q16@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-15607","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-15607","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"risk":0.26065000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."},"relatedVulnerabilities":[{"id":"CVE-2018-15607","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"urls":["http://www.securityfocus.com/bid/105137","https://github.com/ImageMagick/ImageMagick/issues/1255","https://usn.ubuntu.com/4034-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."}]},{"artifact":{"id":"4166e52734c45414","cpes":["cpe:2.3:a:libmagickcore-6-arch-config:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6-arch-config:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_arch_config:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_arch_config:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6-arch:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6-arch:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_arch:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_arch:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6-arch-config","purl":"pkg:deb/debian/libmagickcore-6-arch-config@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6-arch-config/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6-arch-config/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6-arch-config:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-arch-config:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-15607","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-15607","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"risk":0.26065000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."},"relatedVulnerabilities":[{"id":"CVE-2018-15607","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"urls":["http://www.securityfocus.com/bid/105137","https://github.com/ImageMagick/ImageMagick/issues/1255","https://usn.ubuntu.com/4034-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."}]},{"artifact":{"id":"aa218174a16ba41d","cpes":["cpe:2.3:a:libmagickcore-6-headers:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6-headers:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_headers:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_headers:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6-headers","purl":"pkg:deb/debian/libmagickcore-6-headers@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6-headers/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.list"},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.postinst"},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.postrm"},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.preinst"},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-15607","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-15607","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"risk":0.26065000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."},"relatedVulnerabilities":[{"id":"CVE-2018-15607","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"urls":["http://www.securityfocus.com/bid/105137","https://github.com/ImageMagick/ImageMagick/issues/1255","https://usn.ubuntu.com/4034-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."}]},{"artifact":{"id":"b5cf9ab484b0ba4d","cpes":["cpe:2.3:a:libmagickcore-6.q16-6:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-6:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-6","purl":"pkg:deb/debian/libmagickcore-6.q16-6@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-6/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6.q16-6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-6:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-15607","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-15607","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"risk":0.26065000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."},"relatedVulnerabilities":[{"id":"CVE-2018-15607","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"urls":["http://www.securityfocus.com/bid/105137","https://github.com/ImageMagick/ImageMagick/issues/1255","https://usn.ubuntu.com/4034-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."}]},{"artifact":{"id":"839820a05a2b8d61","cpes":["cpe:2.3:a:libmagickcore-6.q16-6-extra:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-6-extra:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6_extra:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6_extra:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-6:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-6:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-6-extra","purl":"pkg:deb/debian/libmagickcore-6.q16-6-extra@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-6-extra/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6.q16-6-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-6-extra:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-6-extra:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-15607","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-15607","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"risk":0.26065000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."},"relatedVulnerabilities":[{"id":"CVE-2018-15607","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"urls":["http://www.securityfocus.com/bid/105137","https://github.com/ImageMagick/ImageMagick/issues/1255","https://usn.ubuntu.com/4034-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."}]},{"artifact":{"id":"6bdab316f776d434","cpes":["cpe:2.3:a:libmagickcore-6.q16-dev:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-dev:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_dev:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_dev:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-dev","purl":"pkg:deb/debian/libmagickcore-6.q16-dev@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6.q16-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-15607","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-15607","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"risk":0.26065000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."},"relatedVulnerabilities":[{"id":"CVE-2018-15607","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"urls":["http://www.securityfocus.com/bid/105137","https://github.com/ImageMagick/ImageMagick/issues/1255","https://usn.ubuntu.com/4034-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."}]},{"artifact":{"id":"4ecf55d018da7a3a","cpes":["cpe:2.3:a:libmagickcore-dev:libmagickcore-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-dev:libmagickcore_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_dev:libmagickcore-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_dev:libmagickcore_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-dev","purl":"pkg:deb/debian/libmagickcore-dev@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.list"},{"path":"/var/lib/dpkg/info/libmagickcore-dev.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.postinst"},{"path":"/var/lib/dpkg/info/libmagickcore-dev.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.postrm"},{"path":"/var/lib/dpkg/info/libmagickcore-dev.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.preinst"},{"path":"/var/lib/dpkg/info/libmagickcore-dev.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-15607","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-15607","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"risk":0.26065000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."},"relatedVulnerabilities":[{"id":"CVE-2018-15607","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"urls":["http://www.securityfocus.com/bid/105137","https://github.com/ImageMagick/ImageMagick/issues/1255","https://usn.ubuntu.com/4034-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."}]},{"artifact":{"id":"b5ed8bc1dc425827","cpes":["cpe:2.3:a:libmagickwand-6-headers:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6-headers:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6_headers:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6_headers:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickwand-6-headers","purl":"pkg:deb/debian/libmagickwand-6-headers@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickwand-6-headers/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.list"},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.postinst"},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.postrm"},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.preinst"},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-15607","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-15607","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"risk":0.26065000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."},"relatedVulnerabilities":[{"id":"CVE-2018-15607","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"urls":["http://www.securityfocus.com/bid/105137","https://github.com/ImageMagick/ImageMagick/issues/1255","https://usn.ubuntu.com/4034-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."}]},{"artifact":{"id":"8cdb31d88acebec5","cpes":["cpe:2.3:a:libmagickwand-6.q16-6:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-6:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_6:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_6:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-6","purl":"pkg:deb/debian/libmagickwand-6.q16-6@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-6/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickwand-6.q16-6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-6:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-15607","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-15607","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"risk":0.26065000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."},"relatedVulnerabilities":[{"id":"CVE-2018-15607","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"urls":["http://www.securityfocus.com/bid/105137","https://github.com/ImageMagick/ImageMagick/issues/1255","https://usn.ubuntu.com/4034-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."}]},{"artifact":{"id":"bfccc5b5605637fa","cpes":["cpe:2.3:a:libmagickwand-6.q16-dev:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-dev:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_dev:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_dev:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-dev","purl":"pkg:deb/debian/libmagickwand-6.q16-dev@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickwand-6.q16-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-15607","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-15607","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"risk":0.26065000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."},"relatedVulnerabilities":[{"id":"CVE-2018-15607","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"urls":["http://www.securityfocus.com/bid/105137","https://github.com/ImageMagick/ImageMagick/issues/1255","https://usn.ubuntu.com/4034-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."}]},{"artifact":{"id":"9a83dfeec459438d","cpes":["cpe:2.3:a:libmagickwand-dev:libmagickwand-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-dev:libmagickwand_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_dev:libmagickwand-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_dev:libmagickwand_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickwand-dev","purl":"pkg:deb/debian/libmagickwand-dev@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickwand-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.list"},{"path":"/var/lib/dpkg/info/libmagickwand-dev.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.postinst"},{"path":"/var/lib/dpkg/info/libmagickwand-dev.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.postrm"},{"path":"/var/lib/dpkg/info/libmagickwand-dev.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.preinst"},{"path":"/var/lib/dpkg/info/libmagickwand-dev.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-15607","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-15607","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"risk":0.26065000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."},"relatedVulnerabilities":[{"id":"CVE-2018-15607","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"urls":["http://www.securityfocus.com/bid/105137","https://github.com/ImageMagick/ImageMagick/issues/1255","https://usn.ubuntu.com/4034-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."}]},{"artifact":{"id":"ac9f96c95674631f","cpes":["cpe:2.3:a:libopenexr-3-1-30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1-30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-3-1-30","purl":"pkg:deb/debian/libopenexr-3-1-30@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-3-1-30/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-3-1-30/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-68516","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-68516","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68516","cwe":"CWE-121","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-68516","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-68516","date":"2026-10-08","epss":0.00452,"percentile":0.37268}],"risk":0.25989999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68516","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.13, a crafted HTJ2K-compressed EXR can crash OpenEXR during normal decode. An HTJ2K-compressed EXR whose JPEG 2000 SIZ fields place the first tile outside the visible image can reach invalid tile and codeblock geometry in the vendored OpenJPH AVX2 decoder, causing a stack out-of-bounds write and denial of service. OpenEXR's HTJ2K path validates the decoded codestream dimensions against the EXR chunk size, but it does not reject SIZ image-offset/tile-grid geometry where the first tile does not intersect the image. This issue is fixed in version 3.4.14."},"relatedVulnerabilities":[{"id":"CVE-2026-68516","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68516","cwe":"CWE-121","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-68516","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-68516","date":"2026-10-08","epss":0.00452,"percentile":0.37268}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/45521f92104373b5c850f27f2d4659ab6759e848","https://github.com/AcademySoftwareFoundation/openexr/commit/85009d840cc085aa96ad03ae76fa6463defeb0e5","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-fw66-6xph-56jm"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68516","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.13, a crafted HTJ2K-compressed EXR can crash OpenEXR during normal decode. An HTJ2K-compressed EXR whose JPEG 2000 SIZ fields place the first tile outside the visible image can reach invalid tile and codeblock geometry in the vendored OpenJPH AVX2 decoder, causing a stack out-of-bounds write and denial of service. OpenEXR's HTJ2K path validates the decoded codestream dimensions against the EXR chunk size, but it does not reject SIZ image-offset/tile-grid geometry where the first tile does not intersect the image. This issue is fixed in version 3.4.14."}]},{"artifact":{"id":"229cdd73859abf63","cpes":["cpe:2.3:a:libopenexr-dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-dev","purl":"pkg:deb/debian/libopenexr-dev@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.list"}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-68516","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-68516","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68516","cwe":"CWE-121","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-68516","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-68516","date":"2026-10-08","epss":0.00452,"percentile":0.37268}],"risk":0.25989999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68516","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.13, a crafted HTJ2K-compressed EXR can crash OpenEXR during normal decode. An HTJ2K-compressed EXR whose JPEG 2000 SIZ fields place the first tile outside the visible image can reach invalid tile and codeblock geometry in the vendored OpenJPH AVX2 decoder, causing a stack out-of-bounds write and denial of service. OpenEXR's HTJ2K path validates the decoded codestream dimensions against the EXR chunk size, but it does not reject SIZ image-offset/tile-grid geometry where the first tile does not intersect the image. This issue is fixed in version 3.4.14."},"relatedVulnerabilities":[{"id":"CVE-2026-68516","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68516","cwe":"CWE-121","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-68516","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-68516","date":"2026-10-08","epss":0.00452,"percentile":0.37268}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/45521f92104373b5c850f27f2d4659ab6759e848","https://github.com/AcademySoftwareFoundation/openexr/commit/85009d840cc085aa96ad03ae76fa6463defeb0e5","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-fw66-6xph-56jm"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68516","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.13, a crafted HTJ2K-compressed EXR can crash OpenEXR during normal decode. An HTJ2K-compressed EXR whose JPEG 2000 SIZ fields place the first tile outside the visible image can reach invalid tile and codeblock geometry in the vendored OpenJPH AVX2 decoder, causing a stack out-of-bounds write and denial of service. OpenEXR's HTJ2K path validates the decoded codestream dimensions against the EXR chunk size, but it does not reject SIZ image-offset/tile-grid geometry where the first tile does not intersect the image. This issue is fixed in version 3.4.14."}]},{"artifact":{"id":"b280459d31091296","cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*"],"name":"libopenjp2-7","purl":"pkg:deb/debian/libopenjp2-7@2.5.0-2%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=openjpeg2","type":"deb","version":"2.5.0-2+deb12u3","language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjpeg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-39327","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjpeg2","version":"2.5.0-2+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-39327","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39327","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-39327","date":"2026-10-08","epss":0.00555,"percentile":0.44547}],"risk":0.258075,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-39327","description":"A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal."},"relatedVulnerabilities":[{"id":"CVE-2023-39327","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39327","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-39327","date":"2026-10-08","epss":0.00555,"percentile":0.44547}],"urls":["https://access.redhat.com/errata/RHSA-2026:4128","https://access.redhat.com/security/cve/CVE-2023-39327","https://bugzilla.redhat.com/show_bug.cgi?id=2295812","https://github.com/uclouvain/openjpeg/issues/1472"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-39327","description":"A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal."}]},{"artifact":{"id":"29b0a2eb864a8178","cpes":["cpe:2.3:a:libopenjp2-7-dev:libopenjp2-7-dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7-dev:libopenjp2_7_dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7_dev:libopenjp2-7-dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7_dev:libopenjp2_7_dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2-7-dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7_dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7-dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7_dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7-dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7_dev:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*"],"name":"libopenjp2-7-dev","purl":"pkg:deb/debian/libopenjp2-7-dev@2.5.0-2%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=openjpeg2","type":"deb","version":"2.5.0-2+deb12u3","language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenjp2-7-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenjp2-7-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjpeg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-39327","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjpeg2","version":"2.5.0-2+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-39327","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39327","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-39327","date":"2026-10-08","epss":0.00555,"percentile":0.44547}],"risk":0.258075,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-39327","description":"A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal."},"relatedVulnerabilities":[{"id":"CVE-2023-39327","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39327","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-39327","date":"2026-10-08","epss":0.00555,"percentile":0.44547}],"urls":["https://access.redhat.com/errata/RHSA-2026:4128","https://access.redhat.com/security/cve/CVE-2023-39327","https://bugzilla.redhat.com/show_bug.cgi?id=2295812","https://github.com/uclouvain/openjpeg/issues/1472"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-39327","description":"A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal."}]},{"artifact":{"id":"6578dd0ecaa04592","cpes":["cpe:2.3:a:libde265-0:libde265-0:1.0.11-1\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libde265-0:libde265_0:1.0.11-1\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265-0:1.0.11-1\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265_0:1.0.11-1\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265-0:1.0.11-1\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265_0:1.0.11-1\\+deb12u3:*:*:*:*:*:*:*"],"name":"libde265-0","purl":"pkg:deb/debian/libde265-0@1.0.11-1%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=libde265","type":"deb","version":"1.0.11-1+deb12u3","language":"","licenses":["BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","other-1","public-domain-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libde265-0/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libde265-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libde265"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-88373","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libde265","version":"1.0.11-1+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-88373","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-88373","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-88373","date":"2026-10-08","epss":0.00343,"percentile":0.25785}],"risk":0.25725000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-88373","description":"libde265 commit 4d45a6b contains a NULL pointer dereference vulnerability in the NAL parsing path. When de265_push_NAL() is called with a zero-length NAL unit, the resulting NAL_unit may retain a NULL backing buffer, which is subsequently passed as the destination argument to memcpy() in NAL_unit::set_data(). Although the copy length is zero, this violates the nonnull requirement of memcpy() and results in undefined behavior, causing process termination in UBSan-instrumented builds and denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-88373","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-88373","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-88373","date":"2026-10-08","epss":0.00343,"percentile":0.25785}],"urls":["https://github.com/strukturag/libde265/commit/f8d324914e43d92af23614f22959cf9eee7bf9ea","https://github.com/strukturag/libde265/issues/534"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-88373","description":"libde265 commit 4d45a6b contains a NULL pointer dereference vulnerability in the NAL parsing path. When de265_push_NAL() is called with a zero-length NAL unit, the resulting NAL_unit may retain a NULL backing buffer, which is subsequently passed as the destination argument to memcpy() in NAL_unit::set_data(). Although the copy length is zero, this violates the nonnull requirement of memcpy() and results in undefined behavior, causing process termination in UBSan-instrumented builds and denial of service."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"05457b2d3472913c","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"be9fcdc16d52ab8f","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15806","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"risk":0.2552,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.  Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.  Users who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."},"relatedVulnerabilities":[{"id":"CVE-2026-15806","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/95355ee3a8e1d3c3d4858d1973aa42a9b91a2801","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/commit/dac88d8615078c55f1304ea4c7a2d822700d4e5a","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15806","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"risk":0.2552,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.  Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.  Users who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."},"relatedVulnerabilities":[{"id":"CVE-2026-15806","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/95355ee3a8e1d3c3d4858d1973aa42a9b91a2801","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/commit/dac88d8615078c55f1304ea4c7a2d822700d4e5a","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15806","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"risk":0.2552,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.  Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.  Users who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."},"relatedVulnerabilities":[{"id":"CVE-2026-15806","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/95355ee3a8e1d3c3d4858d1973aa42a9b91a2801","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/commit/dac88d8615078c55f1304ea4c7a2d822700d4e5a","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15806","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"risk":0.2552,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.  Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.  Users who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."},"relatedVulnerabilities":[{"id":"CVE-2026-15806","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/95355ee3a8e1d3c3d4858d1973aa42a9b91a2801","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/commit/dac88d8615078c55f1304ea4c7a2d822700d4e5a","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."}]},{"artifact":{"id":"f7e49c1a6279cc8f","cpes":["cpe:2.3:a:libglib2.0-0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-0","purl":"pkg:deb/debian/libglib2.0-0@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-0/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15588","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15588","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15588","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15588","date":"2026-10-08","epss":0.00479,"percentile":0.39402}],"risk":0.24668500000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15588","description":"A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang."},"relatedVulnerabilities":[{"id":"CVE-2026-15588","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15588","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15588","date":"2026-10-08","epss":0.00479,"percentile":0.39402}],"urls":["https://access.redhat.com/errata/RHSA-2026:39985","https://access.redhat.com/errata/RHSA-2026:40485","https://access.redhat.com/errata/RHSA-2026:42329","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-15588","https://bugzilla.redhat.com/show_bug.cgi?id=2499675","https://gitlab.gnome.org/GNOME/glib/-/issues/3985"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15588","description":"A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang."}]},{"artifact":{"id":"757dc53367620c75","cpes":["cpe:2.3:a:libglib2.0-bin:libglib2.0-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-bin:libglib2.0_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_bin:libglib2.0-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_bin:libglib2.0_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-bin","purl":"pkg:deb/debian/libglib2.0-bin@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-bin/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-bin.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-bin.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-bin.list"}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15588","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15588","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15588","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15588","date":"2026-10-08","epss":0.00479,"percentile":0.39402}],"risk":0.24668500000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15588","description":"A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang."},"relatedVulnerabilities":[{"id":"CVE-2026-15588","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15588","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15588","date":"2026-10-08","epss":0.00479,"percentile":0.39402}],"urls":["https://access.redhat.com/errata/RHSA-2026:39985","https://access.redhat.com/errata/RHSA-2026:40485","https://access.redhat.com/errata/RHSA-2026:42329","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-15588","https://bugzilla.redhat.com/show_bug.cgi?id=2499675","https://gitlab.gnome.org/GNOME/glib/-/issues/3985"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15588","description":"A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang."}]},{"artifact":{"id":"f3f80a402f7cbc1b","cpes":["cpe:2.3:a:libglib2.0-data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-data","purl":"pkg:deb/debian/libglib2.0-data@2.74.6-2%2Bdeb12u9?arch=all&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-data/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-data.list"}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15588","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15588","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15588","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15588","date":"2026-10-08","epss":0.00479,"percentile":0.39402}],"risk":0.24668500000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15588","description":"A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang."},"relatedVulnerabilities":[{"id":"CVE-2026-15588","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15588","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15588","date":"2026-10-08","epss":0.00479,"percentile":0.39402}],"urls":["https://access.redhat.com/errata/RHSA-2026:39985","https://access.redhat.com/errata/RHSA-2026:40485","https://access.redhat.com/errata/RHSA-2026:42329","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-15588","https://bugzilla.redhat.com/show_bug.cgi?id=2499675","https://gitlab.gnome.org/GNOME/glib/-/issues/3985"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15588","description":"A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang."}]},{"artifact":{"id":"17127afcd14d4e5d","cpes":["cpe:2.3:a:libglib2.0-dev:libglib2.0-dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev:libglib2.0_dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0-dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0_dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_dev:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-dev","purl":"pkg:deb/debian/libglib2.0-dev@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15588","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15588","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15588","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15588","date":"2026-10-08","epss":0.00479,"percentile":0.39402}],"risk":0.24668500000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15588","description":"A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang."},"relatedVulnerabilities":[{"id":"CVE-2026-15588","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15588","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15588","date":"2026-10-08","epss":0.00479,"percentile":0.39402}],"urls":["https://access.redhat.com/errata/RHSA-2026:39985","https://access.redhat.com/errata/RHSA-2026:40485","https://access.redhat.com/errata/RHSA-2026:42329","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-15588","https://bugzilla.redhat.com/show_bug.cgi?id=2499675","https://gitlab.gnome.org/GNOME/glib/-/issues/3985"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15588","description":"A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang."}]},{"artifact":{"id":"b56f6def3e8bd4f6","cpes":["cpe:2.3:a:libglib2.0-dev-bin:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev-bin:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev_bin:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev_bin:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-dev:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_dev:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-dev-bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_dev_bin:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"name":"libglib2.0-dev-bin","purl":"pkg:deb/debian/libglib2.0-dev-bin@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","type":"deb","version":"2.74.6-2+deb12u9","language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-dev-bin/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libglib2.0-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.list"},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.postinst"},{"path":"/var/lib/dpkg/info/libglib2.0-dev-bin.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libglib2.0-dev-bin.prerm"}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15588","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15588","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15588","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15588","date":"2026-10-08","epss":0.00479,"percentile":0.39402}],"risk":0.24668500000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15588","description":"A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang."},"relatedVulnerabilities":[{"id":"CVE-2026-15588","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15588","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15588","date":"2026-10-08","epss":0.00479,"percentile":0.39402}],"urls":["https://access.redhat.com/errata/RHSA-2026:39985","https://access.redhat.com/errata/RHSA-2026:40485","https://access.redhat.com/errata/RHSA-2026:42329","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-15588","https://bugzilla.redhat.com/show_bug.cgi?id=2499675","https://gitlab.gnome.org/GNOME/glib/-/issues/3985"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15588","description":"A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang."}]},{"artifact":{"id":"acc529981c64331f","cpes":["cpe:2.3:a:patch:patch:2.7.6-7:*:*:*:*:*:*:*"],"name":"patch","purl":"pkg:deb/debian/patch@2.7.6-7?arch=amd64&distro=debian-12.15","type":"deb","version":"2.7.6-7","language":"","licenses":["sha256:8c70d7b0af209abe627c97cd21883931b891c820d0a4affcc10b789a23538a0d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/patch/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/patch/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/patch.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/patch.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2010-4651","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"patch","version":"2.7.6-7"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2010-4651","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2010-4651","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4651","date":"2026-10-08","epss":0.04874,"percentile":0.91829}],"risk":0.2437,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4651","description":"Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679."},"relatedVulnerabilities":[{"id":"CVE-2010-4651","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:P","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2010-4651","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4651","date":"2026-10-08","epss":0.04874,"percentile":0.91829}],"urls":["http://git.savannah.gnu.org/cgit/patch.git/commit/?id=685a78b6052f4df6eac6d625a545cfb54a6ac0e1","http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html","http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055241.html","http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055246.html","http://lists.gnu.org/archive/html/bug-patch/2010-12/msg00000.html","http://openwall.com/lists/oss-security/2011/01/05/10","http://openwall.com/lists/oss-security/2011/01/06/19","http://openwall.com/lists/oss-security/2011/01/06/20","http://openwall.com/lists/oss-security/2011/01/06/21","http://secunia.com/advisories/43663","http://secunia.com/advisories/43677","http://support.apple.com/kb/HT4723","http://www.securityfocus.com/bid/46768","http://www.vupen.com/english/advisories/2011/0600","https://bugzilla.redhat.com/show_bug.cgi?id=667529"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4651","description":"Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679."}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8286","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8286","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"risk":0.24101999999999998,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not."},"relatedVulnerabilities":[{"id":"CVE-2026-8286","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"urls":["https://curl.se/docs/CVE-2026-8286.html","https://curl.se/docs/CVE-2026-8286.json","https://hackerone.com/reports/3718195"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8286","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8286","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"risk":0.24101999999999998,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not."},"relatedVulnerabilities":[{"id":"CVE-2026-8286","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"urls":["https://curl.se/docs/CVE-2026-8286.html","https://curl.se/docs/CVE-2026-8286.json","https://hackerone.com/reports/3718195"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8286","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8286","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"risk":0.24101999999999998,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not."},"relatedVulnerabilities":[{"id":"CVE-2026-8286","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"urls":["https://curl.se/docs/CVE-2026-8286.html","https://curl.se/docs/CVE-2026-8286.json","https://hackerone.com/reports/3718195"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not."}]},{"artifact":{"id":"610d5f28e0c6125d","cpes":["cpe:2.3:a:libcurl4-openssl-dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl-dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl_dev:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4-openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4_openssl:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4-openssl-dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl4:libcurl4_openssl_dev:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4-openssl-dev","purl":"pkg:deb/debian/libcurl4-openssl-dev@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4-openssl-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libcurl4-openssl-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libcurl4-openssl-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8286","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8286","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"risk":0.24101999999999998,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not."},"relatedVulnerabilities":[{"id":"CVE-2026-8286","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"urls":["https://curl.se/docs/CVE-2026-8286.html","https://curl.se/docs/CVE-2026-8286.json","https://hackerone.com/reports/3718195"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not."}]},{"artifact":{"id":"f314997677a3aacc","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/debian/imagemagick@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.list"},{"path":"/var/lib/dpkg/info/imagemagick.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.postinst"},{"path":"/var/lib/dpkg/info/imagemagick.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.postrm"},{"path":"/var/lib/dpkg/info/imagemagick.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.preinst"},{"path":"/var/lib/dpkg/info/imagemagick.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86420","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86420","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"risk":0.24075,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86420","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4mwf-mggw-29vp","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-denial-of-service-memory-budget"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."}]},{"artifact":{"id":"58eb8529873897ef","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/debian/imagemagick-6-common@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86420","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86420","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"risk":0.24075,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86420","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4mwf-mggw-29vp","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-denial-of-service-memory-budget"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."}]},{"artifact":{"id":"81d27bbb42434f07","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/debian/imagemagick-6.q16@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86420","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86420","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"risk":0.24075,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86420","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4mwf-mggw-29vp","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-denial-of-service-memory-budget"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."}]},{"artifact":{"id":"4166e52734c45414","cpes":["cpe:2.3:a:libmagickcore-6-arch-config:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6-arch-config:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_arch_config:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_arch_config:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6-arch:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6-arch:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_arch:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_arch:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6-arch-config","purl":"pkg:deb/debian/libmagickcore-6-arch-config@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6-arch-config/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6-arch-config/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6-arch-config:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-arch-config:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86420","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86420","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"risk":0.24075,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86420","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4mwf-mggw-29vp","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-denial-of-service-memory-budget"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."}]},{"artifact":{"id":"aa218174a16ba41d","cpes":["cpe:2.3:a:libmagickcore-6-headers:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6-headers:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_headers:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_headers:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6-headers","purl":"pkg:deb/debian/libmagickcore-6-headers@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6-headers/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.list"},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.postinst"},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.postrm"},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.preinst"},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86420","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86420","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"risk":0.24075,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86420","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4mwf-mggw-29vp","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-denial-of-service-memory-budget"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."}]},{"artifact":{"id":"b5cf9ab484b0ba4d","cpes":["cpe:2.3:a:libmagickcore-6.q16-6:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-6:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-6","purl":"pkg:deb/debian/libmagickcore-6.q16-6@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-6/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6.q16-6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-6:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86420","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86420","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"risk":0.24075,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86420","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4mwf-mggw-29vp","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-denial-of-service-memory-budget"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."}]},{"artifact":{"id":"839820a05a2b8d61","cpes":["cpe:2.3:a:libmagickcore-6.q16-6-extra:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-6-extra:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6_extra:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6_extra:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-6:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-6:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-6-extra","purl":"pkg:deb/debian/libmagickcore-6.q16-6-extra@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-6-extra/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6.q16-6-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-6-extra:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-6-extra:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86420","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86420","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"risk":0.24075,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86420","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4mwf-mggw-29vp","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-denial-of-service-memory-budget"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."}]},{"artifact":{"id":"6bdab316f776d434","cpes":["cpe:2.3:a:libmagickcore-6.q16-dev:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-dev:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_dev:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_dev:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-dev","purl":"pkg:deb/debian/libmagickcore-6.q16-dev@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6.q16-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86420","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86420","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"risk":0.24075,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86420","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4mwf-mggw-29vp","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-denial-of-service-memory-budget"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."}]},{"artifact":{"id":"4ecf55d018da7a3a","cpes":["cpe:2.3:a:libmagickcore-dev:libmagickcore-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-dev:libmagickcore_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_dev:libmagickcore-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_dev:libmagickcore_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-dev","purl":"pkg:deb/debian/libmagickcore-dev@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.list"},{"path":"/var/lib/dpkg/info/libmagickcore-dev.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.postinst"},{"path":"/var/lib/dpkg/info/libmagickcore-dev.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.postrm"},{"path":"/var/lib/dpkg/info/libmagickcore-dev.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.preinst"},{"path":"/var/lib/dpkg/info/libmagickcore-dev.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86420","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86420","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"risk":0.24075,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86420","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4mwf-mggw-29vp","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-denial-of-service-memory-budget"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."}]},{"artifact":{"id":"b5ed8bc1dc425827","cpes":["cpe:2.3:a:libmagickwand-6-headers:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6-headers:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6_headers:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6_headers:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickwand-6-headers","purl":"pkg:deb/debian/libmagickwand-6-headers@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickwand-6-headers/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.list"},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.postinst"},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.postrm"},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.preinst"},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86420","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86420","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"risk":0.24075,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86420","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4mwf-mggw-29vp","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-denial-of-service-memory-budget"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."}]},{"artifact":{"id":"8cdb31d88acebec5","cpes":["cpe:2.3:a:libmagickwand-6.q16-6:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-6:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_6:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_6:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-6","purl":"pkg:deb/debian/libmagickwand-6.q16-6@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-6/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickwand-6.q16-6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-6:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86420","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86420","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"risk":0.24075,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86420","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4mwf-mggw-29vp","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-denial-of-service-memory-budget"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."}]},{"artifact":{"id":"bfccc5b5605637fa","cpes":["cpe:2.3:a:libmagickwand-6.q16-dev:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-dev:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_dev:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_dev:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-dev","purl":"pkg:deb/debian/libmagickwand-6.q16-dev@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickwand-6.q16-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86420","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86420","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"risk":0.24075,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86420","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4mwf-mggw-29vp","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-denial-of-service-memory-budget"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."}]},{"artifact":{"id":"9a83dfeec459438d","cpes":["cpe:2.3:a:libmagickwand-dev:libmagickwand-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-dev:libmagickwand_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_dev:libmagickwand-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_dev:libmagickwand_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickwand-dev","purl":"pkg:deb/debian/libmagickwand-dev@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickwand-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.list"},{"path":"/var/lib/dpkg/info/libmagickwand-dev.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.postinst"},{"path":"/var/lib/dpkg/info/libmagickwand-dev.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.postrm"},{"path":"/var/lib/dpkg/info/libmagickwand-dev.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.preinst"},{"path":"/var/lib/dpkg/info/libmagickwand-dev.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86420","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86420","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"risk":0.24075,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86420","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4mwf-mggw-29vp","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-denial-of-service-memory-budget"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."}]},{"artifact":{"id":"ac9f96c95674631f","cpes":["cpe:2.3:a:libopenexr-3-1-30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1-30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1_30:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3-1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3_1:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_3:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-3-1-30:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_3_1_30:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-3-1-30","purl":"pkg:deb/debian/libopenexr-3-1-30@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-3-1-30/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-3-1-30/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-3-1-30:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34589","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-34589","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34589","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34589","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34589","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-34589","date":"2026-10-08","epss":0.00481,"percentile":0.39482}],"risk":0.2405,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34589","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, the DWA lossy decoder constructs temporary per-component block pointers using signed 32-bit arithmetic. For a large enough width, the calculation overflows and later decoder stores operate on a wrapped pointer outside the allocated rowBlock backing store. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9."},"relatedVulnerabilities":[{"id":"CVE-2026-34589","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34589","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34589","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34589","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-34589","date":"2026-10-08","epss":0.00481,"percentile":0.39482}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.2.7","https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.3.9","https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.9","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-p8xc-w3q4-h64x","https://access.redhat.com/security/cve/CVE-2026-34589","https://bugzilla.redhat.com/show_bug.cgi?id=2455411","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34589.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34589","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, the DWA lossy decoder constructs temporary per-component block pointers using signed 32-bit arithmetic. For a large enough width, the calculation overflows and later decoder stores operate on a wrapped pointer outside the allocated rowBlock backing store. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9."}]},{"artifact":{"id":"229cdd73859abf63","cpes":["cpe:2.3:a:libopenexr-dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr-dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr_dev:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr-dev:3.1.5-5:*:*:*:*:*:*:*","cpe:2.3:a:libopenexr:libopenexr_dev:3.1.5-5:*:*:*:*:*:*:*"],"name":"libopenexr-dev","purl":"pkg:deb/debian/libopenexr-dev@3.1.5-5?arch=amd64&distro=debian-12.15&upstream=openexr","type":"deb","version":"3.1.5-5","language":"","licenses":["BSD-3-clause","openexr"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenexr-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libopenexr-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenexr-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libopenexr-dev.list"}],"upstreams":[{"name":"openexr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34589","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openexr","version":"3.1.5-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-34589","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34589","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34589","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34589","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-34589","date":"2026-10-08","epss":0.00481,"percentile":0.39482}],"risk":0.2405,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34589","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, the DWA lossy decoder constructs temporary per-component block pointers using signed 32-bit arithmetic. For a large enough width, the calculation overflows and later decoder stores operate on a wrapped pointer outside the allocated rowBlock backing store. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9."},"relatedVulnerabilities":[{"id":"CVE-2026-34589","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34589","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34589","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34589","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-34589","date":"2026-10-08","epss":0.00481,"percentile":0.39482}],"urls":["https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.2.7","https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.3.9","https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.9","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-p8xc-w3q4-h64x","https://access.redhat.com/security/cve/CVE-2026-34589","https://bugzilla.redhat.com/show_bug.cgi?id=2455411","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34589.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34589","description":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, the DWA lossy decoder constructs temporary per-component block pointers using signed 32-bit arithmetic. For a large enough width, the calculation overflows and later decoder stores operate on a wrapped pointer outside the allocated rowBlock backing store. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9."}]},{"artifact":{"id":"3705ae977c727f09","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/debian/libsqlite3-0@3.40.1-2%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=sqlite3","type":"deb","version":"3.40.1-2+deb12u2","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:7345f80a66167d9ae4a3c28d9280aabd743986ec04e5d862d67a5b8e5d886e78","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11822","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sqlite3","version":"3.40.1-2+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11822","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11822","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-11822","date":"2026-10-08","epss":0.00294,"percentile":0.20129}],"risk":0.2352,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11822","description":"SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database."},"relatedVulnerabilities":[{"id":"CVE-2026-11822","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11822","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-11822","date":"2026-10-08","epss":0.00294,"percentile":0.20129}],"urls":["https://sqlite.org/releaselog/3_53_2.html","https://sqlite.org/src/info/061febcf41ca","https://sqlite.org/src/info/4a5ad516ea93","https://www.vulncheck.com/advisories/sqlite-before-memory-corruption-in-fts5-extension"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11822","description":"SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database."}]},{"artifact":{"id":"1bc2f6ea42a0fdb8","cpes":["cpe:2.3:a:libsqlite3-dev:libsqlite3-dev:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-dev:libsqlite3_dev:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_dev:libsqlite3-dev:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_dev:libsqlite3_dev:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-dev:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_dev:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*"],"name":"libsqlite3-dev","purl":"pkg:deb/debian/libsqlite3-dev@3.40.1-2%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=sqlite3","type":"deb","version":"3.40.1-2+deb12u2","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libsqlite3-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libsqlite3-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11822","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sqlite3","version":"3.40.1-2+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11822","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11822","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-11822","date":"2026-10-08","epss":0.00294,"percentile":0.20129}],"risk":0.2352,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11822","description":"SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database."},"relatedVulnerabilities":[{"id":"CVE-2026-11822","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11822","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-11822","date":"2026-10-08","epss":0.00294,"percentile":0.20129}],"urls":["https://sqlite.org/releaselog/3_53_2.html","https://sqlite.org/src/info/061febcf41ca","https://sqlite.org/src/info/4a5ad516ea93","https://www.vulncheck.com/advisories/sqlite-before-memory-corruption-in-fts5-extension"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11822","description":"SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database."}]},{"artifact":{"id":"e593bea3ea25c1a5","cpes":["cpe:2.3:a:libharfbuzz0b:libharfbuzz0b:6.0.0\\+dfsg-3:*:*:*:*:*:*:*"],"name":"libharfbuzz0b","purl":"pkg:deb/debian/libharfbuzz0b@6.0.0%2Bdfsg-3?arch=amd64&distro=debian-12.15&upstream=harfbuzz","type":"deb","version":"6.0.0+dfsg-3","language":"","licenses":["Apache-2.0","CC0-1.0","Expat","FSFAP","FSFUL","FSFULLR","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","LGPL-2.1+","MIT","Monotype","OFL-1.1","UFL-1.0","Unicode"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libharfbuzz0b/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libharfbuzz0b/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libharfbuzz0b:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libharfbuzz0b:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"harfbuzz"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-22693","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"harfbuzz","version":"6.0.0+dfsg-3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-22693","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-22693","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-22693","date":"2026-10-08","epss":0.00452,"percentile":0.37259}],"risk":0.23278000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-22693","description":"HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault. This issue has been patched in version 12.3.0."},"relatedVulnerabilities":[{"id":"CVE-2026-22693","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-22693","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-22693","date":"2026-10-08","epss":0.00452,"percentile":0.37259}],"urls":["https://github.com/harfbuzz/harfbuzz/commit/1265ff8d990284f04d8768f35b0e20ae5f60daae","https://github.com/harfbuzz/harfbuzz/security/advisories/GHSA-xvjr-f2r9-c7ww","http://www.openwall.com/lists/oss-security/2026/01/11/1","http://www.openwall.com/lists/oss-security/2026/01/12/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-22693","description":"HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault. This issue has been patched in version 12.3.0."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"risk":0.22999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."},"relatedVulnerabilities":[{"id":"CVE-2025-15366","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"risk":0.22999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."},"relatedVulnerabilities":[{"id":"CVE-2025-15366","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"risk":0.22999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."},"relatedVulnerabilities":[{"id":"CVE-2025-15366","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:1049cbfdfb0acf4035a0996bbbf3e5bfc20fcfef65c3d50f09b16c0607afbb38","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"risk":0.22999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."},"relatedVulnerabilities":[{"id":"CVE-2025-15366","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19499","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"risk":0.22572,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.  Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.  At the time of publication, no network-facing application impact is known."},"relatedVulnerabilities":[{"id":"CVE-2026-19499","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34510","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0017"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known."}]},{"artifact":{"id":"05457b2d3472913c","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19499","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"risk":0.22572,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.  Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.  At the time of publication, no network-facing application impact is known."},"relatedVulnerabilities":[{"id":"CVE-2026-19499","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34510","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0017"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19499","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"risk":0.22572,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.  Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.  At the time of publication, no network-facing application impact is known."},"relatedVulnerabilities":[{"id":"CVE-2026-19499","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34510","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0017"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known."}]},{"artifact":{"id":"be9fcdc16d52ab8f","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19499","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"risk":0.22572,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.  Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.  At the time of publication, no network-facing application impact is known."},"relatedVulnerabilities":[{"id":"CVE-2026-19499","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34510","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0017"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"05457b2d3472913c","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"be9fcdc16d52ab8f","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"05457b2d3472913c","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6439a9e3affca36e4cc323dd241724b62721af4a3f4aa590ced4ae11f8083a4b","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"be9fcdc16d52ab8f","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"6dec48f68a6dce02","cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"libheif1","purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","type":"deb","version":"1.15.1-1+deb12u1","language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libheif"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-32814","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-32814","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32814","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-32814","cwe":"CWE-908","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-32814","date":"2026-10-08","epss":0.00389,"percentile":0.30843}],"risk":0.22367499999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-32814","description":"libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid image with strict_decoding=false (the default), a corrupted tile silently fails to decode and the library returns heif_error_Ok with no indication of failure, leading to an uninitialized heap memory information leak. The canvas is allocated via create_clone_image_at_new_size() → plane.alloc() → new (std::nothrow) uint8_t[allocation_size] which does not zero the memory; only the alpha plane is explicitly initialized via fill_plane(), so the Y, Cb, and Cr planes contain whatever was previously at that heap address. The failed tile's region of the canvas is never written. It retains uninitialized heap data that is delivered to the caller as decoded pixel values (4,096 bytes per Y/Cb/Cr plane = 12,288+ bytes total). Any application using libheif to decode grid-based HEIF/AVIF files with default settings is vulnerable: a crafted .heic or .avif file causes 4,096+ bytes of heap memory to appear as pixel values in the decoded image, and the calling application receives heif_error_Ok, so it has no indication the output contains heap garbage. In server-side image processing, an uploaded crafted HEIF decoded and re-encoded (e.g., as PNG/JPEG for thumbnails, CDN, social media) can leak cross-user data such as auth tokens, database results, and other users' image data. This issue has been fixed in version 1.22.0."},"relatedVulnerabilities":[{"id":"CVE-2026-32814","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32814","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-32814","cwe":"CWE-908","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-32814","date":"2026-10-08","epss":0.00389,"percentile":0.30843}],"urls":["https://github.com/strukturag/libheif/releases/tag/v1.22.0","https://github.com/strukturag/libheif/security/advisories/GHSA-4m8r-34pg-rvwc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32814","description":"libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid image with strict_decoding=false (the default), a corrupted tile silently fails to decode and the library returns heif_error_Ok with no indication of failure, leading to an uninitialized heap memory information leak. The canvas is allocated via create_clone_image_at_new_size() → plane.alloc() → new (std::nothrow) uint8_t[allocation_size] which does not zero the memory; only the alpha plane is explicitly initialized via fill_plane(), so the Y, Cb, and Cr planes contain whatever was previously at that heap address. The failed tile's region of the canvas is never written. It retains uninitialized heap data that is delivered to the caller as decoded pixel values (4,096 bytes per Y/Cb/Cr plane = 12,288+ bytes total). Any application using libheif to decode grid-based HEIF/AVIF files with default settings is vulnerable: a crafted .heic or .avif file causes 4,096+ bytes of heap memory to appear as pixel values in the decoded image, and the calling application receives heif_error_Ok, so it has no indication the output contains heap garbage. In server-side image processing, an uploaded crafted HEIF decoded and re-encoded (e.g., as PNG/JPEG for thumbnails, CDN, social media) can leak cross-user data such as auth tokens, database results, and other users' image data. This issue has been fixed in version 1.22.0."}]},{"artifact":{"id":"6dec48f68a6dce02","cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"libheif1","purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","type":"deb","version":"1.15.1-1+deb12u1","language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libheif"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-32739","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-32739","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32739","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-32739","date":"2026-10-08","epss":0.00388,"percentile":0.30755}],"risk":0.2231,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-32739","description":"libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequence file causes an infinite loop in Box_stts::get_sample_duration(), consuming 100% CPU indefinitely with zero progress, leading to DoS. The loop has no iteration limit or timeout and is triggered during file open (parsing) - before any user interaction or image decoding. The process stays alive (no crash, no error logged), making it invisible to crash-based monitoring. This issue has been fixed in version 1.22.0."},"relatedVulnerabilities":[{"id":"CVE-2026-32739","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32739","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-32739","date":"2026-10-08","epss":0.00388,"percentile":0.30755}],"urls":["https://github.com/strukturag/libheif/releases/tag/v1.22.0","https://github.com/strukturag/libheif/security/advisories/GHSA-j9g7-q9hv-gq8c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32739","description":"libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequence file causes an infinite loop in Box_stts::get_sample_duration(), consuming 100% CPU indefinitely with zero progress, leading to DoS. The loop has no iteration limit or timeout and is triggered during file open (parsing) - before any user interaction or image decoding. The process stays alive (no crash, no error logged), making it invisible to crash-based monitoring. This issue has been fixed in version 1.22.0."}]},{"artifact":{"id":"6dec48f68a6dce02","cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"libheif1","purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","type":"deb","version":"1.15.1-1+deb12u1","language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libheif"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-41069","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-41069","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41069","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41069","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41069","date":"2026-10-08","epss":0.00388,"percentile":0.30755}],"risk":0.2231,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-41069","description":"libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS. A malformed file can have stco.entry_count == 0 (creating no chunks) while still passing validation because saio.entry_count == 0 matches, but with saiz.sample_count > 0 the SampleAuxInfoReader constructor still enters its loop. This leads to an out-of-bounds dereference on the empty chunks[0] in chunked mode."},"relatedVulnerabilities":[{"id":"CVE-2026-41069","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41069","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41069","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41069","date":"2026-10-08","epss":0.00388,"percentile":0.30755}],"urls":["https://github.com/strukturag/libheif/releases/tag/v1.22.0","https://github.com/strukturag/libheif/security/advisories/GHSA-p82x-fpmv-576r"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41069","description":"libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS. A malformed file can have stco.entry_count == 0 (creating no chunks) while still passing validation because saio.entry_count == 0 matches, but with saiz.sample_count > 0 the SampleAuxInfoReader constructor still enters its loop. This leads to an out-of-bounds dereference on the empty chunks[0] in chunked mode."}]},{"artifact":{"id":"b587b3626f383fa0","cpes":["cpe:2.3:a:libmariadb-dev:libmariadb-dev:1\\:10.11.18-0\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb-dev:libmariadb_dev:1\\:10.11.18-0\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb_dev:libmariadb-dev:1\\:10.11.18-0\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb_dev:libmariadb_dev:1\\:10.11.18-0\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb:libmariadb-dev:1\\:10.11.18-0\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb:libmariadb_dev:1\\:10.11.18-0\\+deb12u1:*:*:*:*:*:*:*"],"name":"libmariadb-dev","purl":"pkg:deb/debian/libmariadb-dev@1%3A10.11.18-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.18-0+deb12u1","language":"","licenses":["Artistic","BSD-2-Clause","BSD-2-clause","BSD-3-clause","GPL-2","GPL-2+","GPL-2+-with-bison-exception","GPL-3+-with-bison-exception","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","SWsoft","public-domain","unlimited-free-doc","zlib/libpng"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmariadb-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmariadb-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmariadb-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmariadb-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmariadb-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmariadb-dev.list"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-47023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.18-0+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-47023","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.9,"impactScore":3.6,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47023","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-47023","date":"2026-10-08","epss":0.0045,"percentile":0.37093}],"risk":0.22274999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-47023","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)."},"relatedVulnerabilities":[{"id":"CVE-2026-47023","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.9,"impactScore":3.6,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47023","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-47023","date":"2026-10-08","epss":0.0045,"percentile":0.37093}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47023","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)."}]},{"artifact":{"id":"80aca777d36d3b7e","cpes":["cpe:2.3:a:libmariadb-dev-compat:libmariadb-dev-compat:1\\:10.11.18-0\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb-dev-compat:libmariadb_dev_compat:1\\:10.11.18-0\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb_dev_compat:libmariadb-dev-compat:1\\:10.11.18-0\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb_dev_compat:libmariadb_dev_compat:1\\:10.11.18-0\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb-dev:libmariadb-dev-compat:1\\:10.11.18-0\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb-dev:libmariadb_dev_compat:1\\:10.11.18-0\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb_dev:libmariadb-dev-compat:1\\:10.11.18-0\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb_dev:libmariadb_dev_compat:1\\:10.11.18-0\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb:libmariadb-dev-compat:1\\:10.11.18-0\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb:libmariadb_dev_compat:1\\:10.11.18-0\\+deb12u1:*:*:*:*:*:*:*"],"name":"libmariadb-dev-compat","purl":"pkg:deb/debian/libmariadb-dev-compat@1%3A10.11.18-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.18-0+deb12u1","language":"","licenses":["Artistic","BSD-2-Clause","BSD-2-clause","BSD-3-clause","GPL-2","GPL-2+","GPL-2+-with-bison-exception","GPL-3+-with-bison-exception","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","SWsoft","public-domain","unlimited-free-doc","zlib/libpng"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmariadb-dev-compat/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmariadb-dev-compat/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmariadb-dev-compat.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmariadb-dev-compat.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmariadb-dev-compat.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmariadb-dev-compat.list"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-47023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.18-0+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-47023","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.9,"impactScore":3.6,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47023","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-47023","date":"2026-10-08","epss":0.0045,"percentile":0.37093}],"risk":0.22274999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-47023","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)."},"relatedVulnerabilities":[{"id":"CVE-2026-47023","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.9,"impactScore":3.6,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47023","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-47023","date":"2026-10-08","epss":0.0045,"percentile":0.37093}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47023","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)."}]},{"artifact":{"id":"1afca427bfb822c1","cpes":["cpe:2.3:a:libmariadb3:libmariadb3:1\\:10.11.18-0\\+deb12u1:*:*:*:*:*:*:*"],"name":"libmariadb3","purl":"pkg:deb/debian/libmariadb3@1%3A10.11.18-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.18-0+deb12u1","language":"","licenses":["Artistic","BSD-2-Clause","BSD-2-clause","BSD-3-clause","GPL-2","GPL-2+","GPL-2+-with-bison-exception","GPL-3+-with-bison-exception","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","SWsoft","public-domain","unlimited-free-doc","zlib/libpng"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmariadb3/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmariadb3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmariadb3:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmariadb3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-47023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.18-0+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-47023","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.9,"impactScore":3.6,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47023","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-47023","date":"2026-10-08","epss":0.0045,"percentile":0.37093}],"risk":0.22274999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-47023","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)."},"relatedVulnerabilities":[{"id":"CVE-2026-47023","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.9,"impactScore":3.6,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47023","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-47023","date":"2026-10-08","epss":0.0045,"percentile":0.37093}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47023","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)."}]},{"artifact":{"id":"4fb6b822baea4ee6","cpes":["cpe:2.3:a:mariadb-common:mariadb-common:1\\:10.11.18-0\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-common:mariadb_common:1\\:10.11.18-0\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_common:mariadb-common:1\\:10.11.18-0\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_common:mariadb_common:1\\:10.11.18-0\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb-common:1\\:10.11.18-0\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb_common:1\\:10.11.18-0\\+deb12u1:*:*:*:*:*:*:*"],"name":"mariadb-common","purl":"pkg:deb/debian/mariadb-common@1%3A10.11.18-0%2Bdeb12u1?arch=all&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.18-0+deb12u1","language":"","licenses":["Artistic","BSD-2-Clause","BSD-2-clause","BSD-3-clause","GPL-2","GPL-2+","GPL-2+-with-bison-exception","GPL-3+-with-bison-exception","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","SWsoft","public-domain","unlimited-free-doc","zlib/libpng"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mariadb-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/mariadb-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-common.conffiles","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/mariadb-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-common.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/mariadb-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-common.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/mariadb-common.list"},{"path":"/var/lib/dpkg/info/mariadb-common.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/mariadb-common.postinst"},{"path":"/var/lib/dpkg/info/mariadb-common.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/mariadb-common.postrm"},{"path":"/var/lib/dpkg/info/mariadb-common.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/mariadb-common.preinst"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-47023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.18-0+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-47023","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.9,"impactScore":3.6,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47023","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-47023","date":"2026-10-08","epss":0.0045,"percentile":0.37093}],"risk":0.22274999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-47023","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)."},"relatedVulnerabilities":[{"id":"CVE-2026-47023","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.9,"impactScore":3.6,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47023","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-47023","date":"2026-10-08","epss":0.0045,"percentile":0.37093}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47023","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)."}]},{"artifact":{"id":"f314997677a3aacc","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/debian/imagemagick@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.list"},{"path":"/var/lib/dpkg/info/imagemagick.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.postinst"},{"path":"/var/lib/dpkg/info/imagemagick.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.postrm"},{"path":"/var/lib/dpkg/info/imagemagick.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.preinst"},{"path":"/var/lib/dpkg/info/imagemagick.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106578","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106578","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."},"relatedVulnerabilities":[{"id":"CVE-2026-106578","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/5d29c094020612dc8fb471b10fc1d1cc6e9e4378","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6xf5-c3jx-rp39","https://github.com/ImageMagick/ImageMagick6/commit/bfe0117fd9742b3970383e000978d64e5e04372d","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."}]},{"artifact":{"id":"58eb8529873897ef","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/debian/imagemagick-6-common@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106578","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106578","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."},"relatedVulnerabilities":[{"id":"CVE-2026-106578","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/5d29c094020612dc8fb471b10fc1d1cc6e9e4378","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6xf5-c3jx-rp39","https://github.com/ImageMagick/ImageMagick6/commit/bfe0117fd9742b3970383e000978d64e5e04372d","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."}]},{"artifact":{"id":"81d27bbb42434f07","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/debian/imagemagick-6.q16@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106578","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106578","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."},"relatedVulnerabilities":[{"id":"CVE-2026-106578","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/5d29c094020612dc8fb471b10fc1d1cc6e9e4378","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6xf5-c3jx-rp39","https://github.com/ImageMagick/ImageMagick6/commit/bfe0117fd9742b3970383e000978d64e5e04372d","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."}]},{"artifact":{"id":"4166e52734c45414","cpes":["cpe:2.3:a:libmagickcore-6-arch-config:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6-arch-config:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_arch_config:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_arch_config:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6-arch:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6-arch:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_arch:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_arch:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6-arch-config","purl":"pkg:deb/debian/libmagickcore-6-arch-config@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6-arch-config/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6-arch-config/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6-arch-config:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-arch-config:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106578","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106578","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."},"relatedVulnerabilities":[{"id":"CVE-2026-106578","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/5d29c094020612dc8fb471b10fc1d1cc6e9e4378","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6xf5-c3jx-rp39","https://github.com/ImageMagick/ImageMagick6/commit/bfe0117fd9742b3970383e000978d64e5e04372d","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."}]},{"artifact":{"id":"aa218174a16ba41d","cpes":["cpe:2.3:a:libmagickcore-6-headers:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6-headers:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_headers:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_headers:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6-headers","purl":"pkg:deb/debian/libmagickcore-6-headers@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6-headers/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.list"},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.postinst"},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.postrm"},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.preinst"},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106578","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106578","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."},"relatedVulnerabilities":[{"id":"CVE-2026-106578","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/5d29c094020612dc8fb471b10fc1d1cc6e9e4378","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6xf5-c3jx-rp39","https://github.com/ImageMagick/ImageMagick6/commit/bfe0117fd9742b3970383e000978d64e5e04372d","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."}]},{"artifact":{"id":"b5cf9ab484b0ba4d","cpes":["cpe:2.3:a:libmagickcore-6.q16-6:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-6:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-6","purl":"pkg:deb/debian/libmagickcore-6.q16-6@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-6/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6.q16-6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-6:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106578","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106578","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."},"relatedVulnerabilities":[{"id":"CVE-2026-106578","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/5d29c094020612dc8fb471b10fc1d1cc6e9e4378","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6xf5-c3jx-rp39","https://github.com/ImageMagick/ImageMagick6/commit/bfe0117fd9742b3970383e000978d64e5e04372d","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."}]},{"artifact":{"id":"839820a05a2b8d61","cpes":["cpe:2.3:a:libmagickcore-6.q16-6-extra:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-6-extra:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6_extra:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6_extra:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-6:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-6:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-6-extra","purl":"pkg:deb/debian/libmagickcore-6.q16-6-extra@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-6-extra/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6.q16-6-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-6-extra:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-6-extra:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106578","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106578","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."},"relatedVulnerabilities":[{"id":"CVE-2026-106578","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/5d29c094020612dc8fb471b10fc1d1cc6e9e4378","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6xf5-c3jx-rp39","https://github.com/ImageMagick/ImageMagick6/commit/bfe0117fd9742b3970383e000978d64e5e04372d","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."}]},{"artifact":{"id":"6bdab316f776d434","cpes":["cpe:2.3:a:libmagickcore-6.q16-dev:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-dev:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_dev:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_dev:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-dev","purl":"pkg:deb/debian/libmagickcore-6.q16-dev@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6.q16-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106578","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106578","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."},"relatedVulnerabilities":[{"id":"CVE-2026-106578","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/5d29c094020612dc8fb471b10fc1d1cc6e9e4378","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6xf5-c3jx-rp39","https://github.com/ImageMagick/ImageMagick6/commit/bfe0117fd9742b3970383e000978d64e5e04372d","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."}]},{"artifact":{"id":"4ecf55d018da7a3a","cpes":["cpe:2.3:a:libmagickcore-dev:libmagickcore-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-dev:libmagickcore_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_dev:libmagickcore-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_dev:libmagickcore_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-dev","purl":"pkg:deb/debian/libmagickcore-dev@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.list"},{"path":"/var/lib/dpkg/info/libmagickcore-dev.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.postinst"},{"path":"/var/lib/dpkg/info/libmagickcore-dev.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.postrm"},{"path":"/var/lib/dpkg/info/libmagickcore-dev.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.preinst"},{"path":"/var/lib/dpkg/info/libmagickcore-dev.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106578","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106578","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."},"relatedVulnerabilities":[{"id":"CVE-2026-106578","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/5d29c094020612dc8fb471b10fc1d1cc6e9e4378","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6xf5-c3jx-rp39","https://github.com/ImageMagick/ImageMagick6/commit/bfe0117fd9742b3970383e000978d64e5e04372d","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."}]},{"artifact":{"id":"b5ed8bc1dc425827","cpes":["cpe:2.3:a:libmagickwand-6-headers:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6-headers:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6_headers:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6_headers:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickwand-6-headers","purl":"pkg:deb/debian/libmagickwand-6-headers@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickwand-6-headers/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.list"},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.postinst"},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.postrm"},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.preinst"},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106578","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106578","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."},"relatedVulnerabilities":[{"id":"CVE-2026-106578","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/5d29c094020612dc8fb471b10fc1d1cc6e9e4378","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6xf5-c3jx-rp39","https://github.com/ImageMagick/ImageMagick6/commit/bfe0117fd9742b3970383e000978d64e5e04372d","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."}]},{"artifact":{"id":"8cdb31d88acebec5","cpes":["cpe:2.3:a:libmagickwand-6.q16-6:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-6:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_6:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_6:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-6","purl":"pkg:deb/debian/libmagickwand-6.q16-6@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-6/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickwand-6.q16-6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-6:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106578","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106578","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."},"relatedVulnerabilities":[{"id":"CVE-2026-106578","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/5d29c094020612dc8fb471b10fc1d1cc6e9e4378","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6xf5-c3jx-rp39","https://github.com/ImageMagick/ImageMagick6/commit/bfe0117fd9742b3970383e000978d64e5e04372d","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."}]},{"artifact":{"id":"bfccc5b5605637fa","cpes":["cpe:2.3:a:libmagickwand-6.q16-dev:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-dev:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_dev:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_dev:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-dev","purl":"pkg:deb/debian/libmagickwand-6.q16-dev@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickwand-6.q16-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106578","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106578","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."},"relatedVulnerabilities":[{"id":"CVE-2026-106578","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/5d29c094020612dc8fb471b10fc1d1cc6e9e4378","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6xf5-c3jx-rp39","https://github.com/ImageMagick/ImageMagick6/commit/bfe0117fd9742b3970383e000978d64e5e04372d","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."}]},{"artifact":{"id":"9a83dfeec459438d","cpes":["cpe:2.3:a:libmagickwand-dev:libmagickwand-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-dev:libmagickwand_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_dev:libmagickwand-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_dev:libmagickwand_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickwand-dev","purl":"pkg:deb/debian/libmagickwand-dev@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickwand-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.list"},{"path":"/var/lib/dpkg/info/libmagickwand-dev.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.postinst"},{"path":"/var/lib/dpkg/info/libmagickwand-dev.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.postrm"},{"path":"/var/lib/dpkg/info/libmagickwand-dev.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.preinst"},{"path":"/var/lib/dpkg/info/libmagickwand-dev.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106578","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106578","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."},"relatedVulnerabilities":[{"id":"CVE-2026-106578","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/5d29c094020612dc8fb471b10fc1d1cc6e9e4378","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6xf5-c3jx-rp39","https://github.com/ImageMagick/ImageMagick6/commit/bfe0117fd9742b3970383e000978d64e5e04372d","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."}]},{"artifact":{"id":"f314997677a3aacc","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/debian/imagemagick@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.list"},{"path":"/var/lib/dpkg/info/imagemagick.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.postinst"},{"path":"/var/lib/dpkg/info/imagemagick.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.postrm"},{"path":"/var/lib/dpkg/info/imagemagick.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.preinst"},{"path":"/var/lib/dpkg/info/imagemagick.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106565","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106565","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106565","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/e9872c4a165d869e75d10799c47195725ebf4132","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-m9c7-gf3j-hx6h","https://github.com/ImageMagick/ImageMagick6/commit/82f752927a552cbba1213b1d023b85e76845774c","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"f314997677a3aacc","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/debian/imagemagick@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.list"},{"path":"/var/lib/dpkg/info/imagemagick.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.postinst"},{"path":"/var/lib/dpkg/info/imagemagick.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.postrm"},{"path":"/var/lib/dpkg/info/imagemagick.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.preinst"},{"path":"/var/lib/dpkg/info/imagemagick.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-106567","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106567","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106567","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/f053f778409932d55b95758c4b1516b63191d1eb","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g6p6-3ggg-3w7j","https://github.com/ImageMagick/ImageMagick6/commit/61024a2677a3c7973a2dd27170877d8e51419473","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"58eb8529873897ef","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/debian/imagemagick-6-common@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106565","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106565","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106565","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/e9872c4a165d869e75d10799c47195725ebf4132","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-m9c7-gf3j-hx6h","https://github.com/ImageMagick/ImageMagick6/commit/82f752927a552cbba1213b1d023b85e76845774c","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"58eb8529873897ef","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/debian/imagemagick-6-common@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106567","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106567","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106567","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/f053f778409932d55b95758c4b1516b63191d1eb","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g6p6-3ggg-3w7j","https://github.com/ImageMagick/ImageMagick6/commit/61024a2677a3c7973a2dd27170877d8e51419473","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"81d27bbb42434f07","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/debian/imagemagick-6.q16@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106565","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106565","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106565","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/e9872c4a165d869e75d10799c47195725ebf4132","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-m9c7-gf3j-hx6h","https://github.com/ImageMagick/ImageMagick6/commit/82f752927a552cbba1213b1d023b85e76845774c","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"81d27bbb42434f07","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/debian/imagemagick-6.q16@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106567","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106567","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106567","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/f053f778409932d55b95758c4b1516b63191d1eb","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g6p6-3ggg-3w7j","https://github.com/ImageMagick/ImageMagick6/commit/61024a2677a3c7973a2dd27170877d8e51419473","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"4166e52734c45414","cpes":["cpe:2.3:a:libmagickcore-6-arch-config:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6-arch-config:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_arch_config:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_arch_config:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6-arch:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6-arch:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_arch:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_arch:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6-arch-config","purl":"pkg:deb/debian/libmagickcore-6-arch-config@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6-arch-config/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6-arch-config/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6-arch-config:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-arch-config:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106565","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106565","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106565","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/e9872c4a165d869e75d10799c47195725ebf4132","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-m9c7-gf3j-hx6h","https://github.com/ImageMagick/ImageMagick6/commit/82f752927a552cbba1213b1d023b85e76845774c","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"4166e52734c45414","cpes":["cpe:2.3:a:libmagickcore-6-arch-config:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6-arch-config:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_arch_config:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_arch_config:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6-arch:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6-arch:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_arch:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_arch:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6-arch-config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6_arch_config:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6-arch-config","purl":"pkg:deb/debian/libmagickcore-6-arch-config@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6-arch-config/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6-arch-config/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6-arch-config:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-arch-config:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106567","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106567","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106567","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/f053f778409932d55b95758c4b1516b63191d1eb","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g6p6-3ggg-3w7j","https://github.com/ImageMagick/ImageMagick6/commit/61024a2677a3c7973a2dd27170877d8e51419473","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"aa218174a16ba41d","cpes":["cpe:2.3:a:libmagickcore-6-headers:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6-headers:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_headers:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_headers:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6-headers","purl":"pkg:deb/debian/libmagickcore-6-headers@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6-headers/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.list"},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.postinst"},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.postrm"},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.preinst"},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106565","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106565","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106565","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/e9872c4a165d869e75d10799c47195725ebf4132","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-m9c7-gf3j-hx6h","https://github.com/ImageMagick/ImageMagick6/commit/82f752927a552cbba1213b1d023b85e76845774c","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"aa218174a16ba41d","cpes":["cpe:2.3:a:libmagickcore-6-headers:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6-headers:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_headers:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6_headers:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6-headers","purl":"pkg:deb/debian/libmagickcore-6-headers@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6-headers/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.list"},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.postinst"},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.postrm"},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.preinst"},{"path":"/var/lib/dpkg/info/libmagickcore-6-headers.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6-headers.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106567","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106567","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106567","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/f053f778409932d55b95758c4b1516b63191d1eb","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g6p6-3ggg-3w7j","https://github.com/ImageMagick/ImageMagick6/commit/61024a2677a3c7973a2dd27170877d8e51419473","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"b5cf9ab484b0ba4d","cpes":["cpe:2.3:a:libmagickcore-6.q16-6:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-6:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-6","purl":"pkg:deb/debian/libmagickcore-6.q16-6@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-6/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6.q16-6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-6:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106565","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106565","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106565","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/e9872c4a165d869e75d10799c47195725ebf4132","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-m9c7-gf3j-hx6h","https://github.com/ImageMagick/ImageMagick6/commit/82f752927a552cbba1213b1d023b85e76845774c","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"b5cf9ab484b0ba4d","cpes":["cpe:2.3:a:libmagickcore-6.q16-6:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-6:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-6","purl":"pkg:deb/debian/libmagickcore-6.q16-6@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-6/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6.q16-6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-6:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106567","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106567","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106567","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/f053f778409932d55b95758c4b1516b63191d1eb","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g6p6-3ggg-3w7j","https://github.com/ImageMagick/ImageMagick6/commit/61024a2677a3c7973a2dd27170877d8e51419473","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"839820a05a2b8d61","cpes":["cpe:2.3:a:libmagickcore-6.q16-6-extra:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-6-extra:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6_extra:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6_extra:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-6:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-6:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-6-extra","purl":"pkg:deb/debian/libmagickcore-6.q16-6-extra@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-6-extra/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6.q16-6-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-6-extra:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-6-extra:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106565","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106565","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106565","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/e9872c4a165d869e75d10799c47195725ebf4132","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-m9c7-gf3j-hx6h","https://github.com/ImageMagick/ImageMagick6/commit/82f752927a552cbba1213b1d023b85e76845774c","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"839820a05a2b8d61","cpes":["cpe:2.3:a:libmagickcore-6.q16-6-extra:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-6-extra:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6_extra:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6_extra:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-6:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-6:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_6:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-6-extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_6_extra:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-6-extra","purl":"pkg:deb/debian/libmagickcore-6.q16-6-extra@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-6-extra/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6.q16-6-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-6-extra:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-6-extra:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106567","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106567","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106567","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/f053f778409932d55b95758c4b1516b63191d1eb","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g6p6-3ggg-3w7j","https://github.com/ImageMagick/ImageMagick6/commit/61024a2677a3c7973a2dd27170877d8e51419473","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"6bdab316f776d434","cpes":["cpe:2.3:a:libmagickcore-6.q16-dev:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-dev:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_dev:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_dev:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-dev","purl":"pkg:deb/debian/libmagickcore-6.q16-dev@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6.q16-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106565","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106565","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106565","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/e9872c4a165d869e75d10799c47195725ebf4132","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-m9c7-gf3j-hx6h","https://github.com/ImageMagick/ImageMagick6/commit/82f752927a552cbba1213b1d023b85e76845774c","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"6bdab316f776d434","cpes":["cpe:2.3:a:libmagickcore-6.q16-dev:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-dev:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_dev:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_dev:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-dev","purl":"pkg:deb/debian/libmagickcore-6.q16-dev@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-6.q16-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106567","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106567","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106567","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/f053f778409932d55b95758c4b1516b63191d1eb","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g6p6-3ggg-3w7j","https://github.com/ImageMagick/ImageMagick6/commit/61024a2677a3c7973a2dd27170877d8e51419473","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"4ecf55d018da7a3a","cpes":["cpe:2.3:a:libmagickcore-dev:libmagickcore-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-dev:libmagickcore_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_dev:libmagickcore-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_dev:libmagickcore_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-dev","purl":"pkg:deb/debian/libmagickcore-dev@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.list"},{"path":"/var/lib/dpkg/info/libmagickcore-dev.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.postinst"},{"path":"/var/lib/dpkg/info/libmagickcore-dev.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.postrm"},{"path":"/var/lib/dpkg/info/libmagickcore-dev.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.preinst"},{"path":"/var/lib/dpkg/info/libmagickcore-dev.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106565","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106565","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106565","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/e9872c4a165d869e75d10799c47195725ebf4132","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-m9c7-gf3j-hx6h","https://github.com/ImageMagick/ImageMagick6/commit/82f752927a552cbba1213b1d023b85e76845774c","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"4ecf55d018da7a3a","cpes":["cpe:2.3:a:libmagickcore-dev:libmagickcore-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-dev:libmagickcore_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_dev:libmagickcore-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_dev:libmagickcore_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickcore-dev","purl":"pkg:deb/debian/libmagickcore-dev@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickcore-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.list"},{"path":"/var/lib/dpkg/info/libmagickcore-dev.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.postinst"},{"path":"/var/lib/dpkg/info/libmagickcore-dev.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.postrm"},{"path":"/var/lib/dpkg/info/libmagickcore-dev.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.preinst"},{"path":"/var/lib/dpkg/info/libmagickcore-dev.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickcore-dev.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106567","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106567","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106567","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/f053f778409932d55b95758c4b1516b63191d1eb","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g6p6-3ggg-3w7j","https://github.com/ImageMagick/ImageMagick6/commit/61024a2677a3c7973a2dd27170877d8e51419473","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"b5ed8bc1dc425827","cpes":["cpe:2.3:a:libmagickwand-6-headers:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6-headers:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6_headers:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6_headers:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickwand-6-headers","purl":"pkg:deb/debian/libmagickwand-6-headers@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickwand-6-headers/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.list"},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.postinst"},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.postrm"},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.preinst"},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106565","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106565","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106565","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/e9872c4a165d869e75d10799c47195725ebf4132","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-m9c7-gf3j-hx6h","https://github.com/ImageMagick/ImageMagick6/commit/82f752927a552cbba1213b1d023b85e76845774c","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"b5ed8bc1dc425827","cpes":["cpe:2.3:a:libmagickwand-6-headers:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6-headers:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6_headers:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6_headers:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6-headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6_headers:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickwand-6-headers","purl":"pkg:deb/debian/libmagickwand-6-headers@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickwand-6-headers/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.list"},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.postinst"},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.postrm"},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.preinst"},{"path":"/var/lib/dpkg/info/libmagickwand-6-headers.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6-headers.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106567","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106567","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106567","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/f053f778409932d55b95758c4b1516b63191d1eb","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g6p6-3ggg-3w7j","https://github.com/ImageMagick/ImageMagick6/commit/61024a2677a3c7973a2dd27170877d8e51419473","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"8cdb31d88acebec5","cpes":["cpe:2.3:a:libmagickwand-6.q16-6:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-6:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_6:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_6:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-6","purl":"pkg:deb/debian/libmagickwand-6.q16-6@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-6/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickwand-6.q16-6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-6:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106565","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106565","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106565","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/e9872c4a165d869e75d10799c47195725ebf4132","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-m9c7-gf3j-hx6h","https://github.com/ImageMagick/ImageMagick6/commit/82f752927a552cbba1213b1d023b85e76845774c","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"8cdb31d88acebec5","cpes":["cpe:2.3:a:libmagickwand-6.q16-6:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-6:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_6:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_6:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_6:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-6","purl":"pkg:deb/debian/libmagickwand-6.q16-6@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-6/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickwand-6.q16-6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-6:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106567","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106567","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106567","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/f053f778409932d55b95758c4b1516b63191d1eb","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g6p6-3ggg-3w7j","https://github.com/ImageMagick/ImageMagick6/commit/61024a2677a3c7973a2dd27170877d8e51419473","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"bfccc5b5605637fa","cpes":["cpe:2.3:a:libmagickwand-6.q16-dev:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-dev:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_dev:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_dev:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-dev","purl":"pkg:deb/debian/libmagickwand-6.q16-dev@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickwand-6.q16-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106565","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106565","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106565","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/e9872c4a165d869e75d10799c47195725ebf4132","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-m9c7-gf3j-hx6h","https://github.com/ImageMagick/ImageMagick6/commit/82f752927a552cbba1213b1d023b85e76845774c","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"bfccc5b5605637fa","cpes":["cpe:2.3:a:libmagickwand-6.q16-dev:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-dev:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_dev:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_dev:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-dev","purl":"pkg:deb/debian/libmagickwand-6.q16-dev@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=amd64&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-dev/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickwand-6.q16-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-dev:amd64.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106567","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106567","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106567","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/f053f778409932d55b95758c4b1516b63191d1eb","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g6p6-3ggg-3w7j","https://github.com/ImageMagick/ImageMagick6/commit/61024a2677a3c7973a2dd27170877d8e51419473","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"9a83dfeec459438d","cpes":["cpe:2.3:a:libmagickwand-dev:libmagickwand-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-dev:libmagickwand_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_dev:libmagickwand-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_dev:libmagickwand_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_dev:8\\:6.9.11.60\\+dfsg-1.6\\+deb12u13:*:*:*:*:*:*:*"],"name":"libmagickwand-dev","purl":"pkg:deb/debian/libmagickwand-dev@8%3A6.9.11.60%2Bdfsg-1.6%2Bdeb12u13?arch=all&distro=debian-12.15&upstream=imagemagick","type":"deb","version":"8:6.9.11.60+dfsg-1.6+deb12u13","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","TatcherUlrichPublicDomain","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:dfedd5696b506629cf9343d12005c73adb2b910dc3963f513fa4a873f7dc4ff7","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/usr/share/doc/libmagickwand-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-dev.md5sums","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-dev.list","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.list"},{"path":"/var/lib/dpkg/info/libmagickwand-dev.postinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.postinst"},{"path":"/var/lib/dpkg/info/libmagickwand-dev.postrm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.postrm"},{"path":"/var/lib/dpkg/info/libmagickwand-dev.preinst","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.preinst"},{"path":"/var/lib/dpkg/info/libmagickwand-dev.prerm","layerID":"sha256:060a1e8ce9048ff68647726be1cfe515884725d6e527f2fd2382a039f5c0a111","accessPath":"/var/lib/dpkg/info/libmagickwand-dev.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106565","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.6+deb12u13"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106565","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106565","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/e9872c4a165d869e75d10799c47195725ebf4132","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-m9c7-gf3j-hx6h","https://github.com/ImageMagick/ImageMagick6/commit/82f752927a552cbba1213b1d023b85e76845774c","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]}],"grade":"F","score":"0.00","as_of":"2026-10-09T22:48:26.430Z","grype_db_version":"2026-10-09T06:32:32.000Z"}