{"grype_matches":[{"artifact":{"id":"f56688673fdbf7bd","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.SignalR.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.SignalR.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5f2m-466j-3848","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-5f2m-466j-3848","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-08","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0981","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0981","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"risk":3.70725,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0981","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0981","https://github.com/dotnet/announcements/issues/113","https://github.com/github/advisory-database/issues/302"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5f2m-466j-3848","description":"Denial of service in ASP.NET Core"},"relatedVulnerabilities":[{"id":"CVE-2019-0981","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0981","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0981","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"urls":["https://access.redhat.com/errata/RHSA-2019:1259","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0981"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0981","description":"A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980."}]},{"artifact":{"id":"bdf664761f147504","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Core.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Core.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5f2m-466j-3848","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-5f2m-466j-3848","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-08","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0981","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0981","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"risk":3.70725,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0981","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0981","https://github.com/dotnet/announcements/issues/113","https://github.com/github/advisory-database/issues/302"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5f2m-466j-3848","description":"Denial of service in ASP.NET Core"},"relatedVulnerabilities":[{"id":"CVE-2019-0981","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0981","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0981","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"urls":["https://access.redhat.com/errata/RHSA-2019:1259","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0981"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0981","description":"A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980."}]},{"artifact":{"id":"c4e72ac7f1bde673","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Host.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Host.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5f2m-466j-3848","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-5f2m-466j-3848","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-08","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0981","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0981","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"risk":3.70725,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0981","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0981","https://github.com/dotnet/announcements/issues/113","https://github.com/github/advisory-database/issues/302"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5f2m-466j-3848","description":"Denial of service in ASP.NET Core"},"relatedVulnerabilities":[{"id":"CVE-2019-0981","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0981","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0981","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"urls":["https://access.redhat.com/errata/RHSA-2019:1259","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0981"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0981","description":"A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980."}]},{"artifact":{"id":"df54d41ba7f0d1c1","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Common.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Common.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5f2m-466j-3848","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-5f2m-466j-3848","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-08","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0981","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0981","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"risk":3.70725,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0981","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0981","https://github.com/dotnet/announcements/issues/113","https://github.com/github/advisory-database/issues/302"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5f2m-466j-3848","description":"Denial of service in ASP.NET Core"},"relatedVulnerabilities":[{"id":"CVE-2019-0981","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0981","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0981","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"urls":["https://access.redhat.com/errata/RHSA-2019:1259","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0981"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0981","description":"A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980."}]},{"artifact":{"id":"e994c662c1cc2643","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Api.V3.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Api.V3.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5f2m-466j-3848","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-5f2m-466j-3848","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-08","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0981","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0981","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"risk":3.70725,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0981","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0981","https://github.com/dotnet/announcements/issues/113","https://github.com/github/advisory-database/issues/302"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5f2m-466j-3848","description":"Denial of service in ASP.NET Core"},"relatedVulnerabilities":[{"id":"CVE-2019-0981","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0981","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0981","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"urls":["https://access.redhat.com/errata/RHSA-2019:1259","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0981"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0981","description":"A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980."}]},{"artifact":{"id":"5d5e6e68ac2ba7b9","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Http.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Http.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5f2m-466j-3848","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-5f2m-466j-3848","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-08","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0981","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0981","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"risk":3.70725,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0981","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0981","https://github.com/dotnet/announcements/issues/113","https://github.com/github/advisory-database/issues/302"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5f2m-466j-3848","description":"Denial of service in ASP.NET Core"},"relatedVulnerabilities":[{"id":"CVE-2019-0981","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0981","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0981","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"urls":["https://access.redhat.com/errata/RHSA-2019:1259","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0981"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0981","description":"A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980."}]},{"artifact":{"id":"f56688673fdbf7bd","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.SignalR.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.SignalR.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-xhfc-gr8f-ffwc","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-xhfc-gr8f-ffwc","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-08","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0980","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0980","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"risk":3.70725,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0980","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0980","https://github.com/dotnet/announcements/issues/112","https://github.com/github/advisory-database/issues/302"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-xhfc-gr8f-ffwc","description":"Denial of service in ASP.NET Core"},"relatedVulnerabilities":[{"id":"CVE-2019-0980","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0980","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0980","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"urls":["https://access.redhat.com/errata/RHSA-2019:1259","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0980"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0980","description":"A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0981."}]},{"artifact":{"id":"5d5e6e68ac2ba7b9","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Http.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Http.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-xhfc-gr8f-ffwc","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-xhfc-gr8f-ffwc","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-08","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0980","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0980","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"risk":3.70725,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0980","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0980","https://github.com/dotnet/announcements/issues/112","https://github.com/github/advisory-database/issues/302"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-xhfc-gr8f-ffwc","description":"Denial of service in ASP.NET Core"},"relatedVulnerabilities":[{"id":"CVE-2019-0980","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0980","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0980","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"urls":["https://access.redhat.com/errata/RHSA-2019:1259","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0980"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0980","description":"A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0981."}]},{"artifact":{"id":"c4e72ac7f1bde673","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Host.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Host.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-xhfc-gr8f-ffwc","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-xhfc-gr8f-ffwc","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-08","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0980","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0980","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"risk":3.70725,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0980","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0980","https://github.com/dotnet/announcements/issues/112","https://github.com/github/advisory-database/issues/302"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-xhfc-gr8f-ffwc","description":"Denial of service in ASP.NET Core"},"relatedVulnerabilities":[{"id":"CVE-2019-0980","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0980","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0980","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"urls":["https://access.redhat.com/errata/RHSA-2019:1259","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0980"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0980","description":"A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0981."}]},{"artifact":{"id":"bdf664761f147504","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Core.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Core.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-xhfc-gr8f-ffwc","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-xhfc-gr8f-ffwc","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-08","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0980","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0980","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"risk":3.70725,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0980","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0980","https://github.com/dotnet/announcements/issues/112","https://github.com/github/advisory-database/issues/302"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-xhfc-gr8f-ffwc","description":"Denial of service in ASP.NET Core"},"relatedVulnerabilities":[{"id":"CVE-2019-0980","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0980","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0980","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"urls":["https://access.redhat.com/errata/RHSA-2019:1259","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0980"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0980","description":"A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0981."}]},{"artifact":{"id":"df54d41ba7f0d1c1","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Common.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Common.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-xhfc-gr8f-ffwc","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-xhfc-gr8f-ffwc","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-08","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0980","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0980","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"risk":3.70725,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0980","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0980","https://github.com/dotnet/announcements/issues/112","https://github.com/github/advisory-database/issues/302"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-xhfc-gr8f-ffwc","description":"Denial of service in ASP.NET Core"},"relatedVulnerabilities":[{"id":"CVE-2019-0980","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0980","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0980","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"urls":["https://access.redhat.com/errata/RHSA-2019:1259","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0980"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0980","description":"A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0981."}]},{"artifact":{"id":"e994c662c1cc2643","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Api.V3.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Api.V3.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-xhfc-gr8f-ffwc","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-xhfc-gr8f-ffwc","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-08","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0980","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0980","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"risk":3.70725,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0980","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0980","https://github.com/dotnet/announcements/issues/112","https://github.com/github/advisory-database/issues/302"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-xhfc-gr8f-ffwc","description":"Denial of service in ASP.NET Core"},"relatedVulnerabilities":[{"id":"CVE-2019-0980","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0980","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0980","date":"2026-10-08","epss":0.04943,"percentile":0.91934}],"urls":["https://access.redhat.com/errata/RHSA-2019:1259","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0980"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0980","description":"A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0981."}]},{"artifact":{"id":"5d5e6e68ac2ba7b9","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Http.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Http.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-x5qj-9vmx-7g6g","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-x5qj-9vmx-7g6g","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-09","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0657","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0657","date":"2026-10-08","epss":0.04518,"percentile":0.91284}],"risk":2.46231,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0657","https://access.redhat.com/errata/RHSA-2019:0349","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657","http://www.securityfocus.com/bid/106890","https://github.com/dotnet/announcements/issues/97","https://github.com/github/advisory-database/issues/302"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-x5qj-9vmx-7g6g","description":"Improper Input Validation in .Net Framework API's"},"relatedVulnerabilities":[{"id":"CVE-2019-0657","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0657","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0657","date":"2026-10-08","epss":0.04518,"percentile":0.91284}],"urls":["http://www.securityfocus.com/bid/106890","https://access.redhat.com/errata/RHSA-2019:0349","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0657","description":"A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'."}]},{"artifact":{"id":"e994c662c1cc2643","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Api.V3.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Api.V3.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-x5qj-9vmx-7g6g","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-x5qj-9vmx-7g6g","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-09","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0657","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0657","date":"2026-10-08","epss":0.04518,"percentile":0.91284}],"risk":2.46231,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0657","https://access.redhat.com/errata/RHSA-2019:0349","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657","http://www.securityfocus.com/bid/106890","https://github.com/dotnet/announcements/issues/97","https://github.com/github/advisory-database/issues/302"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-x5qj-9vmx-7g6g","description":"Improper Input Validation in .Net Framework API's"},"relatedVulnerabilities":[{"id":"CVE-2019-0657","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0657","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0657","date":"2026-10-08","epss":0.04518,"percentile":0.91284}],"urls":["http://www.securityfocus.com/bid/106890","https://access.redhat.com/errata/RHSA-2019:0349","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0657","description":"A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'."}]},{"artifact":{"id":"df54d41ba7f0d1c1","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Common.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Common.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-x5qj-9vmx-7g6g","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-x5qj-9vmx-7g6g","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-09","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0657","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0657","date":"2026-10-08","epss":0.04518,"percentile":0.91284}],"risk":2.46231,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0657","https://access.redhat.com/errata/RHSA-2019:0349","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657","http://www.securityfocus.com/bid/106890","https://github.com/dotnet/announcements/issues/97","https://github.com/github/advisory-database/issues/302"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-x5qj-9vmx-7g6g","description":"Improper Input Validation in .Net Framework API's"},"relatedVulnerabilities":[{"id":"CVE-2019-0657","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0657","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0657","date":"2026-10-08","epss":0.04518,"percentile":0.91284}],"urls":["http://www.securityfocus.com/bid/106890","https://access.redhat.com/errata/RHSA-2019:0349","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0657","description":"A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'."}]},{"artifact":{"id":"bdf664761f147504","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Core.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Core.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-x5qj-9vmx-7g6g","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-x5qj-9vmx-7g6g","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-09","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0657","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0657","date":"2026-10-08","epss":0.04518,"percentile":0.91284}],"risk":2.46231,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0657","https://access.redhat.com/errata/RHSA-2019:0349","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657","http://www.securityfocus.com/bid/106890","https://github.com/dotnet/announcements/issues/97","https://github.com/github/advisory-database/issues/302"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-x5qj-9vmx-7g6g","description":"Improper Input Validation in .Net Framework API's"},"relatedVulnerabilities":[{"id":"CVE-2019-0657","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0657","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0657","date":"2026-10-08","epss":0.04518,"percentile":0.91284}],"urls":["http://www.securityfocus.com/bid/106890","https://access.redhat.com/errata/RHSA-2019:0349","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0657","description":"A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'."}]},{"artifact":{"id":"c4e72ac7f1bde673","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Host.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Host.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-x5qj-9vmx-7g6g","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-x5qj-9vmx-7g6g","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-09","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0657","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0657","date":"2026-10-08","epss":0.04518,"percentile":0.91284}],"risk":2.46231,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0657","https://access.redhat.com/errata/RHSA-2019:0349","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657","http://www.securityfocus.com/bid/106890","https://github.com/dotnet/announcements/issues/97","https://github.com/github/advisory-database/issues/302"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-x5qj-9vmx-7g6g","description":"Improper Input Validation in .Net Framework API's"},"relatedVulnerabilities":[{"id":"CVE-2019-0657","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0657","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0657","date":"2026-10-08","epss":0.04518,"percentile":0.91284}],"urls":["http://www.securityfocus.com/bid/106890","https://access.redhat.com/errata/RHSA-2019:0349","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0657","description":"A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'."}]},{"artifact":{"id":"f56688673fdbf7bd","cpes":["cpe:2.3:a:system_private_uri:system_private_uri_.net:4.3.0:*:*:*:*:*:*:*","cpe:2.3:a:system_private_uri:system_private_uri:4.3.0:*:*:*:*:*:*:*"],"name":"System.Private.Uri","purl":"pkg:nuget/System.Private.Uri@4.3.0","type":"dotnet","version":"4.3.0","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.SignalR.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.SignalR.deps.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-x5qj-9vmx-7g6g","versionConstraint":">=4.3.0,<4.3.2 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"System.Private.Uri","version":"4.3.0"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-x5qj-9vmx-7g6g","fix":{"state":"fixed","versions":["4.3.2"],"available":[{"date":"2022-07-09","kind":"first-observed","version":"4.3.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0657","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0657","date":"2026-10-08","epss":0.04518,"percentile":0.91284}],"risk":2.46231,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-0657","https://access.redhat.com/errata/RHSA-2019:0349","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657","http://www.securityfocus.com/bid/106890","https://github.com/dotnet/announcements/issues/97","https://github.com/github/advisory-database/issues/302"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-x5qj-9vmx-7g6g","description":"Improper Input Validation in .Net Framework API's"},"relatedVulnerabilities":[{"id":"CVE-2019-0657","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-0657","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-0657","date":"2026-10-08","epss":0.04518,"percentile":0.91284}],"urls":["http://www.securityfocus.com/bid/106890","https://access.redhat.com/errata/RHSA-2019:0349","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-0657","description":"A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'."}]},{"artifact":{"id":"eb222fe89d397776","cpes":["cpe:2.3:a:zlib:zlib:1.3.2-r0:*:*:*:*:*:*:*"],"name":"zlib","purl":"pkg:apk/alpine/zlib@1.3.2-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"1.3.2-r0","language":"","licenses":["Zlib"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libz.so.1"},{"path":"/usr/lib/libz.so.1.3.2"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"zlib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.3.2-r1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"< 1.3.2-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.2"},"package":{"name":"zlib","version":"1.3.2-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"1.3.2-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"< 1.3.2-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.2"},"package":{"name":"zlib","version":"1.3.2-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-85091","fix":{"state":"fixed","versions":["1.3.2-r1"],"available":[{"date":"2026-10-07","kind":"first-observed","version":"1.3.2-r1"}]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"risk":0.28124,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-85091"},"relatedVulnerabilities":[{"id":"CVE-2026-85091","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."}]},{"artifact":{"id":"b82005f3f0f7ef42","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.SignalR.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.SignalR.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j3p4-wp97-rph4","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-j3p4-wp97-rph4","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106113","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106113","date":"2026-10-08","epss":0.0035,"percentile":0.266}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j3p4-wp97-rph4","https://nvd.nist.gov/vuln/detail/CVE-2026-106113","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/c4c4bf292298c026df470db1a17ff826515fd95d","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j3p4-wp97-rph4","description":"ImageSharp: HistogramEqualization uses an unvalidated luminance as an unchecked histogram index"},"relatedVulnerabilities":[{"id":"CVE-2026-106113","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106113","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106113","date":"2026-10-08","epss":0.0035,"percentile":0.266}],"urls":["https://github.com/SixLabors/ImageSharp/commit/c4c4bf292298c026df470db1a17ff826515fd95d","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j3p4-wp97-rph4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106113","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, decoding an attacker-supplied 32-bit floating-point TIFF as Image<HalfVector4> and applying HistogramEqualization can produce a non-finite or out-of-range luminance in ColorNumerics.GetBT709Luminance. GrayscaleLevelsRowOperation.Invoke uses the resulting value as an unchecked histogram offset, causing an unsafe out-of-range access and process termination. Adaptive Histogram Equalization and AutoLevel are not affected by this report. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"bdf04c568ca09005","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Http.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Http.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j3p4-wp97-rph4","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-j3p4-wp97-rph4","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106113","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106113","date":"2026-10-08","epss":0.0035,"percentile":0.266}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j3p4-wp97-rph4","https://nvd.nist.gov/vuln/detail/CVE-2026-106113","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/c4c4bf292298c026df470db1a17ff826515fd95d","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j3p4-wp97-rph4","description":"ImageSharp: HistogramEqualization uses an unvalidated luminance as an unchecked histogram index"},"relatedVulnerabilities":[{"id":"CVE-2026-106113","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106113","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106113","date":"2026-10-08","epss":0.0035,"percentile":0.266}],"urls":["https://github.com/SixLabors/ImageSharp/commit/c4c4bf292298c026df470db1a17ff826515fd95d","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j3p4-wp97-rph4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106113","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, decoding an attacker-supplied 32-bit floating-point TIFF as Image<HalfVector4> and applying HistogramEqualization can produce a non-finite or out-of-range luminance in ColorNumerics.GetBT709Luminance. GrayscaleLevelsRowOperation.Invoke uses the resulting value as an unchecked histogram offset, causing an unsafe out-of-range access and process termination. Adaptive Histogram Equalization and AutoLevel are not affected by this report. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"b7db03e28182d0f4","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j3p4-wp97-rph4","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-j3p4-wp97-rph4","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106113","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106113","date":"2026-10-08","epss":0.0035,"percentile":0.266}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j3p4-wp97-rph4","https://nvd.nist.gov/vuln/detail/CVE-2026-106113","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/c4c4bf292298c026df470db1a17ff826515fd95d","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j3p4-wp97-rph4","description":"ImageSharp: HistogramEqualization uses an unvalidated luminance as an unchecked histogram index"},"relatedVulnerabilities":[{"id":"CVE-2026-106113","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106113","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106113","date":"2026-10-08","epss":0.0035,"percentile":0.266}],"urls":["https://github.com/SixLabors/ImageSharp/commit/c4c4bf292298c026df470db1a17ff826515fd95d","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j3p4-wp97-rph4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106113","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, decoding an attacker-supplied 32-bit floating-point TIFF as Image<HalfVector4> and applying HistogramEqualization can produce a non-finite or out-of-range luminance in ColorNumerics.GetBT709Luminance. GrayscaleLevelsRowOperation.Invoke uses the resulting value as an unchecked histogram offset, causing an unsafe out-of-range access and process termination. Adaptive Histogram Equalization and AutoLevel are not affected by this report. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"7056b49d651734b2","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Api.V3.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Api.V3.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j3p4-wp97-rph4","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-j3p4-wp97-rph4","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106113","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106113","date":"2026-10-08","epss":0.0035,"percentile":0.266}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j3p4-wp97-rph4","https://nvd.nist.gov/vuln/detail/CVE-2026-106113","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/c4c4bf292298c026df470db1a17ff826515fd95d","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j3p4-wp97-rph4","description":"ImageSharp: HistogramEqualization uses an unvalidated luminance as an unchecked histogram index"},"relatedVulnerabilities":[{"id":"CVE-2026-106113","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106113","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106113","date":"2026-10-08","epss":0.0035,"percentile":0.266}],"urls":["https://github.com/SixLabors/ImageSharp/commit/c4c4bf292298c026df470db1a17ff826515fd95d","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j3p4-wp97-rph4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106113","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, decoding an attacker-supplied 32-bit floating-point TIFF as Image<HalfVector4> and applying HistogramEqualization can produce a non-finite or out-of-range luminance in ColorNumerics.GetBT709Luminance. GrayscaleLevelsRowOperation.Invoke uses the resulting value as an unchecked histogram offset, causing an unsafe out-of-range access and process termination. Adaptive Histogram Equalization and AutoLevel are not affected by this report. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"7e5602eec3aa6866","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Core.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Core.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j3p4-wp97-rph4","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-j3p4-wp97-rph4","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106113","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106113","date":"2026-10-08","epss":0.0035,"percentile":0.266}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j3p4-wp97-rph4","https://nvd.nist.gov/vuln/detail/CVE-2026-106113","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/c4c4bf292298c026df470db1a17ff826515fd95d","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j3p4-wp97-rph4","description":"ImageSharp: HistogramEqualization uses an unvalidated luminance as an unchecked histogram index"},"relatedVulnerabilities":[{"id":"CVE-2026-106113","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106113","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106113","date":"2026-10-08","epss":0.0035,"percentile":0.266}],"urls":["https://github.com/SixLabors/ImageSharp/commit/c4c4bf292298c026df470db1a17ff826515fd95d","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j3p4-wp97-rph4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106113","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, decoding an attacker-supplied 32-bit floating-point TIFF as Image<HalfVector4> and applying HistogramEqualization can produce a non-finite or out-of-range luminance in ColorNumerics.GetBT709Luminance. GrayscaleLevelsRowOperation.Invoke uses the resulting value as an unchecked histogram offset, causing an unsafe out-of-range access and process termination. Adaptive Histogram Equalization and AutoLevel are not affected by this report. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"d126fa9a14843a0b","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Host.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Host.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j3p4-wp97-rph4","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-j3p4-wp97-rph4","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106113","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106113","date":"2026-10-08","epss":0.0035,"percentile":0.266}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j3p4-wp97-rph4","https://nvd.nist.gov/vuln/detail/CVE-2026-106113","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/c4c4bf292298c026df470db1a17ff826515fd95d","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j3p4-wp97-rph4","description":"ImageSharp: HistogramEqualization uses an unvalidated luminance as an unchecked histogram index"},"relatedVulnerabilities":[{"id":"CVE-2026-106113","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106113","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106113","date":"2026-10-08","epss":0.0035,"percentile":0.266}],"urls":["https://github.com/SixLabors/ImageSharp/commit/c4c4bf292298c026df470db1a17ff826515fd95d","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j3p4-wp97-rph4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106113","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, decoding an attacker-supplied 32-bit floating-point TIFF as Image<HalfVector4> and applying HistogramEqualization can produce a non-finite or out-of-range luminance in ColorNumerics.GetBT709Luminance. GrayscaleLevelsRowOperation.Invoke uses the resulting value as an unchecked histogram offset, causing an unsafe out-of-range access and process termination. Adaptive Histogram Equalization and AutoLevel are not affected by this report. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"b7db03e28182d0f4","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j9gm-c75j-xc9q","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-j9gm-c75j-xc9q","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106110","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106110","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j9gm-c75j-xc9q","https://nvd.nist.gov/vuln/detail/CVE-2026-106110","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j9gm-c75j-xc9q","description":"ImageSharp: TIFF CCITT T4 encoder can write past its compressed output buffer"},"relatedVulnerabilities":[{"id":"CVE-2026-106110","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106110","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106110","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"urls":["https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j9gm-c75j-xc9q"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106110","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Group 3 encoder allocates an undersized compressed-data buffer for narrow 1-bit images. TiffCcittCompressor.Initialize does not reserve enough space for the row data and T4 end-of-line codes, and T4BitCompressor.CompressStrip reaches unchecked writes when TiffCompression.CcittGroup3Fax is selected directly or inherited from decoded TIFF metadata. An attacker-controlled encode or decode-and-re-encode flow can write beyond the logical output span, corrupt process memory, and terminate the process. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"b82005f3f0f7ef42","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.SignalR.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.SignalR.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j9gm-c75j-xc9q","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-j9gm-c75j-xc9q","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106110","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106110","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j9gm-c75j-xc9q","https://nvd.nist.gov/vuln/detail/CVE-2026-106110","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j9gm-c75j-xc9q","description":"ImageSharp: TIFF CCITT T4 encoder can write past its compressed output buffer"},"relatedVulnerabilities":[{"id":"CVE-2026-106110","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106110","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106110","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"urls":["https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j9gm-c75j-xc9q"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106110","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Group 3 encoder allocates an undersized compressed-data buffer for narrow 1-bit images. TiffCcittCompressor.Initialize does not reserve enough space for the row data and T4 end-of-line codes, and T4BitCompressor.CompressStrip reaches unchecked writes when TiffCompression.CcittGroup3Fax is selected directly or inherited from decoded TIFF metadata. An attacker-controlled encode or decode-and-re-encode flow can write beyond the logical output span, corrupt process memory, and terminate the process. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"bdf04c568ca09005","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Http.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Http.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j9gm-c75j-xc9q","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-j9gm-c75j-xc9q","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106110","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106110","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j9gm-c75j-xc9q","https://nvd.nist.gov/vuln/detail/CVE-2026-106110","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j9gm-c75j-xc9q","description":"ImageSharp: TIFF CCITT T4 encoder can write past its compressed output buffer"},"relatedVulnerabilities":[{"id":"CVE-2026-106110","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106110","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106110","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"urls":["https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j9gm-c75j-xc9q"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106110","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Group 3 encoder allocates an undersized compressed-data buffer for narrow 1-bit images. TiffCcittCompressor.Initialize does not reserve enough space for the row data and T4 end-of-line codes, and T4BitCompressor.CompressStrip reaches unchecked writes when TiffCompression.CcittGroup3Fax is selected directly or inherited from decoded TIFF metadata. An attacker-controlled encode or decode-and-re-encode flow can write beyond the logical output span, corrupt process memory, and terminate the process. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"d126fa9a14843a0b","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Host.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Host.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j9gm-c75j-xc9q","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-j9gm-c75j-xc9q","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106110","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106110","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j9gm-c75j-xc9q","https://nvd.nist.gov/vuln/detail/CVE-2026-106110","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j9gm-c75j-xc9q","description":"ImageSharp: TIFF CCITT T4 encoder can write past its compressed output buffer"},"relatedVulnerabilities":[{"id":"CVE-2026-106110","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106110","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106110","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"urls":["https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j9gm-c75j-xc9q"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106110","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Group 3 encoder allocates an undersized compressed-data buffer for narrow 1-bit images. TiffCcittCompressor.Initialize does not reserve enough space for the row data and T4 end-of-line codes, and T4BitCompressor.CompressStrip reaches unchecked writes when TiffCompression.CcittGroup3Fax is selected directly or inherited from decoded TIFF metadata. An attacker-controlled encode or decode-and-re-encode flow can write beyond the logical output span, corrupt process memory, and terminate the process. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"7e5602eec3aa6866","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Core.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Core.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j9gm-c75j-xc9q","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-j9gm-c75j-xc9q","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106110","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106110","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j9gm-c75j-xc9q","https://nvd.nist.gov/vuln/detail/CVE-2026-106110","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j9gm-c75j-xc9q","description":"ImageSharp: TIFF CCITT T4 encoder can write past its compressed output buffer"},"relatedVulnerabilities":[{"id":"CVE-2026-106110","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106110","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106110","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"urls":["https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j9gm-c75j-xc9q"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106110","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Group 3 encoder allocates an undersized compressed-data buffer for narrow 1-bit images. TiffCcittCompressor.Initialize does not reserve enough space for the row data and T4 end-of-line codes, and T4BitCompressor.CompressStrip reaches unchecked writes when TiffCompression.CcittGroup3Fax is selected directly or inherited from decoded TIFF metadata. An attacker-controlled encode or decode-and-re-encode flow can write beyond the logical output span, corrupt process memory, and terminate the process. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"7056b49d651734b2","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Api.V3.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Api.V3.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j9gm-c75j-xc9q","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-j9gm-c75j-xc9q","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106110","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106110","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j9gm-c75j-xc9q","https://nvd.nist.gov/vuln/detail/CVE-2026-106110","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j9gm-c75j-xc9q","description":"ImageSharp: TIFF CCITT T4 encoder can write past its compressed output buffer"},"relatedVulnerabilities":[{"id":"CVE-2026-106110","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106110","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106110","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"urls":["https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j9gm-c75j-xc9q"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106110","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Group 3 encoder allocates an undersized compressed-data buffer for narrow 1-bit images. TiffCcittCompressor.Initialize does not reserve enough space for the row data and T4 end-of-line codes, and T4BitCompressor.CompressStrip reaches unchecked writes when TiffCompression.CcittGroup3Fax is selected directly or inherited from decoded TIFF metadata. An attacker-controlled encode or decode-and-re-encode flow can write beyond the logical output span, corrupt process memory, and terminate the process. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"d126fa9a14843a0b","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Host.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Host.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jjfr-hcj7-qf5w","versionConstraint":">=2.1.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-jjfr-hcj7-qf5w","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106115","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106115","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-jjfr-hcj7-qf5w","https://nvd.nist.gov/vuln/detail/CVE-2026-106115","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jjfr-hcj7-qf5w","description":"ImageSharp: TIFF CCITT T6 encoder writes beyond an undersized output buffer"},"relatedVulnerabilities":[{"id":"CVE-2026-106115","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106115","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106115","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"urls":["https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-jjfr-hcj7-qf5w"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106115","description":"ImageSharp is a 2D graphics library. From 2.1.0 until 4.1.2, the TIFF CCITT Group 4 encoder allocates Width times rowsPerStrip bytes even though T6BitCompressor.CompressStrip can emit encoded row data and two 12-bit end-of-facsimile-block codes beyond that capacity. TiffCcittCompressor.WriteCode performs unchecked writes, and a decode-and-re-encode flow can inherit TiffCompression.CcittGroup4Fax and one-bit metadata from attacker-supplied input. The resulting out-of-bounds writes can corrupt memory and terminate the process. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"7e5602eec3aa6866","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Core.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Core.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jjfr-hcj7-qf5w","versionConstraint":">=2.1.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-jjfr-hcj7-qf5w","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106115","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106115","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-jjfr-hcj7-qf5w","https://nvd.nist.gov/vuln/detail/CVE-2026-106115","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jjfr-hcj7-qf5w","description":"ImageSharp: TIFF CCITT T6 encoder writes beyond an undersized output buffer"},"relatedVulnerabilities":[{"id":"CVE-2026-106115","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106115","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106115","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"urls":["https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-jjfr-hcj7-qf5w"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106115","description":"ImageSharp is a 2D graphics library. From 2.1.0 until 4.1.2, the TIFF CCITT Group 4 encoder allocates Width times rowsPerStrip bytes even though T6BitCompressor.CompressStrip can emit encoded row data and two 12-bit end-of-facsimile-block codes beyond that capacity. TiffCcittCompressor.WriteCode performs unchecked writes, and a decode-and-re-encode flow can inherit TiffCompression.CcittGroup4Fax and one-bit metadata from attacker-supplied input. The resulting out-of-bounds writes can corrupt memory and terminate the process. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"b7db03e28182d0f4","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jjfr-hcj7-qf5w","versionConstraint":">=2.1.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-jjfr-hcj7-qf5w","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106115","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106115","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-jjfr-hcj7-qf5w","https://nvd.nist.gov/vuln/detail/CVE-2026-106115","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jjfr-hcj7-qf5w","description":"ImageSharp: TIFF CCITT T6 encoder writes beyond an undersized output buffer"},"relatedVulnerabilities":[{"id":"CVE-2026-106115","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106115","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106115","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"urls":["https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-jjfr-hcj7-qf5w"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106115","description":"ImageSharp is a 2D graphics library. From 2.1.0 until 4.1.2, the TIFF CCITT Group 4 encoder allocates Width times rowsPerStrip bytes even though T6BitCompressor.CompressStrip can emit encoded row data and two 12-bit end-of-facsimile-block codes beyond that capacity. TiffCcittCompressor.WriteCode performs unchecked writes, and a decode-and-re-encode flow can inherit TiffCompression.CcittGroup4Fax and one-bit metadata from attacker-supplied input. The resulting out-of-bounds writes can corrupt memory and terminate the process. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"b82005f3f0f7ef42","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.SignalR.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.SignalR.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jjfr-hcj7-qf5w","versionConstraint":">=2.1.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-jjfr-hcj7-qf5w","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106115","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106115","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-jjfr-hcj7-qf5w","https://nvd.nist.gov/vuln/detail/CVE-2026-106115","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jjfr-hcj7-qf5w","description":"ImageSharp: TIFF CCITT T6 encoder writes beyond an undersized output buffer"},"relatedVulnerabilities":[{"id":"CVE-2026-106115","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106115","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106115","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"urls":["https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-jjfr-hcj7-qf5w"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106115","description":"ImageSharp is a 2D graphics library. From 2.1.0 until 4.1.2, the TIFF CCITT Group 4 encoder allocates Width times rowsPerStrip bytes even though T6BitCompressor.CompressStrip can emit encoded row data and two 12-bit end-of-facsimile-block codes beyond that capacity. TiffCcittCompressor.WriteCode performs unchecked writes, and a decode-and-re-encode flow can inherit TiffCompression.CcittGroup4Fax and one-bit metadata from attacker-supplied input. The resulting out-of-bounds writes can corrupt memory and terminate the process. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"bdf04c568ca09005","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Http.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Http.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jjfr-hcj7-qf5w","versionConstraint":">=2.1.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-jjfr-hcj7-qf5w","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106115","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106115","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-jjfr-hcj7-qf5w","https://nvd.nist.gov/vuln/detail/CVE-2026-106115","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jjfr-hcj7-qf5w","description":"ImageSharp: TIFF CCITT T6 encoder writes beyond an undersized output buffer"},"relatedVulnerabilities":[{"id":"CVE-2026-106115","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106115","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106115","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"urls":["https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-jjfr-hcj7-qf5w"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106115","description":"ImageSharp is a 2D graphics library. From 2.1.0 until 4.1.2, the TIFF CCITT Group 4 encoder allocates Width times rowsPerStrip bytes even though T6BitCompressor.CompressStrip can emit encoded row data and two 12-bit end-of-facsimile-block codes beyond that capacity. TiffCcittCompressor.WriteCode performs unchecked writes, and a decode-and-re-encode flow can inherit TiffCompression.CcittGroup4Fax and one-bit metadata from attacker-supplied input. The resulting out-of-bounds writes can corrupt memory and terminate the process. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"7056b49d651734b2","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Api.V3.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Api.V3.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jjfr-hcj7-qf5w","versionConstraint":">=2.1.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-jjfr-hcj7-qf5w","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106115","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106115","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"risk":0.2625,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-jjfr-hcj7-qf5w","https://nvd.nist.gov/vuln/detail/CVE-2026-106115","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"High","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jjfr-hcj7-qf5w","description":"ImageSharp: TIFF CCITT T6 encoder writes beyond an undersized output buffer"},"relatedVulnerabilities":[{"id":"CVE-2026-106115","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106115","cwe":"CWE-787","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106115","date":"2026-10-08","epss":0.0035,"percentile":0.26597}],"urls":["https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-jjfr-hcj7-qf5w"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106115","description":"ImageSharp is a 2D graphics library. From 2.1.0 until 4.1.2, the TIFF CCITT Group 4 encoder allocates Width times rowsPerStrip bytes even though T6BitCompressor.CompressStrip can emit encoded row data and two 12-bit end-of-facsimile-block codes beyond that capacity. TiffCcittCompressor.WriteCode performs unchecked writes, and a decode-and-re-encode flow can inherit TiffCompression.CcittGroup4Fax and one-bit metadata from attacker-supplied input. The resulting out-of-bounds writes can corrupt memory and terminate the process. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"6921667c3af65467","cpes":["cpe:2.3:a:coreutils:coreutils:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:apk/alpine/coreutils@9.11-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/base64"},{"path":"/bin/cat"},{"path":"/bin/chgrp"},{"path":"/bin/chmod"},{"path":"/bin/chown"},{"path":"/bin/coreutils"},{"path":"/bin/cp"},{"path":"/bin/date"},{"path":"/bin/dd"},{"path":"/bin/df"},{"path":"/bin/echo"},{"path":"/bin/false"},{"path":"/bin/link"},{"path":"/bin/ln"},{"path":"/bin/ls"},{"path":"/bin/mkdir"},{"path":"/bin/mknod"},{"path":"/bin/mktemp"},{"path":"/bin/mv"},{"path":"/bin/nice"},{"path":"/bin/printenv"},{"path":"/bin/pwd"},{"path":"/bin/rm"},{"path":"/bin/rmdir"},{"path":"/bin/sleep"},{"path":"/bin/stat"},{"path":"/bin/stty"},{"path":"/bin/sync"},{"path":"/bin/touch"},{"path":"/bin/true"},{"path":"/bin/uname"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/["},{"path":"/usr/bin/b2sum"},{"path":"/usr/bin/base32"},{"path":"/usr/bin/basename"},{"path":"/usr/bin/basenc"},{"path":"/usr/bin/cksum"},{"path":"/usr/bin/comm"},{"path":"/usr/bin/csplit"},{"path":"/usr/bin/cut"},{"path":"/usr/bin/dir"},{"path":"/usr/bin/dircolors"},{"path":"/usr/bin/dirname"},{"path":"/usr/bin/du"},{"path":"/usr/bin/expand"},{"path":"/usr/bin/expr"},{"path":"/usr/bin/factor"},{"path":"/usr/bin/fold"},{"path":"/usr/bin/head"},{"path":"/usr/bin/hostid"},{"path":"/usr/bin/id"},{"path":"/usr/bin/install"},{"path":"/usr/bin/join"},{"path":"/usr/bin/logname"},{"path":"/usr/bin/md5sum"},{"path":"/usr/bin/mkfifo"},{"path":"/usr/bin/nl"},{"path":"/usr/bin/nohup"},{"path":"/usr/bin/nproc"},{"path":"/usr/bin/numfmt"},{"path":"/usr/bin/od"},{"path":"/usr/bin/paste"},{"path":"/usr/bin/pathchk"},{"path":"/usr/bin/pinky"},{"path":"/usr/bin/pr"},{"path":"/usr/bin/printf"},{"path":"/usr/bin/ptx"},{"path":"/usr/bin/readlink"},{"path":"/usr/bin/realpath"},{"path":"/usr/bin/seq"},{"path":"/usr/bin/sha1sum"},{"path":"/usr/bin/sha224sum"},{"path":"/usr/bin/sha256sum"},{"path":"/usr/bin/sha384sum"},{"path":"/usr/bin/shred"},{"path":"/usr/bin/shuf"},{"path":"/usr/bin/sort"},{"path":"/usr/bin/split"},{"path":"/usr/bin/stdbuf"},{"path":"/usr/bin/sum"},{"path":"/usr/bin/tac"},{"path":"/usr/bin/tail"},{"path":"/usr/bin/tee"},{"path":"/usr/bin/test"},{"path":"/usr/bin/timeout"},{"path":"/usr/bin/tr"},{"path":"/usr/bin/truncate"},{"path":"/usr/bin/tsort"},{"path":"/usr/bin/tty"},{"path":"/usr/bin/unexpand"},{"path":"/usr/bin/uniq"},{"path":"/usr/bin/unlink"},{"path":"/usr/bin/users"},{"path":"/usr/bin/vdir"},{"path":"/usr/bin/wc"},{"path":"/usr/bin/who"},{"path":"/usr/bin/whoami"},{"path":"/usr/bin/yes"},{"path":"/usr/libexec"},{"path":"/usr/libexec/coreutils"},{"path":"/usr/libexec/coreutils/libstdbuf.so"},{"path":"/usr/sbin"},{"path":"/usr/sbin/chroot"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"16361c4de507bb4c","cpes":["cpe:2.3:a:coreutils-env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_env:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-env","purl":"pkg:apk/alpine/coreutils-env@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/env"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c43a637992609b6","cpes":["cpe:2.3:a:coreutils-fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-fmt","purl":"pkg:apk/alpine/coreutils-fmt@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/fmt"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"157238390cea3b89","cpes":["cpe:2.3:a:coreutils-sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-sha512sum","purl":"pkg:apk/alpine/coreutils-sha512sum@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/sha512sum"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"bdf04c568ca09005","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Http.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Http.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gwg2-r3hj-4w44","versionConstraint":">=1.0.0-beta0001,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-gwg2-r3hj-4w44","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106114","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106114","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"risk":0.18849000000000002,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-gwg2-r3hj-4w44","https://nvd.nist.gov/vuln/detail/CVE-2026-106114","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/8de892a7623aa8a09ba2333b624c8d2eb98325df","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gwg2-r3hj-4w44","description":"ImageSharp: ICC CLUT parsing allocates from unvalidated channel and grid dimensions"},"relatedVulnerabilities":[{"id":"CVE-2026-106114","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106114","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106114","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"urls":["https://github.com/SixLabors/ImageSharp/commit/8de892a7623aa8a09ba2333b624c8d2eb98325df","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-gwg2-r3hj-4w44"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106114","description":"ImageSharp is a 2D graphics library. From 1.0.0-beta0001 until 4.1.2, ICC CLUT parsing calculates allocation sizes from attacker-declared channel and grid dimensions before confirming that the profile contains the declared values. IccDataReader.ReadClutF32 can request a large float array, and earlier public IccProfile.Entries parsing paths can allocate a large jagged representation, from a short truncated profile. In version 4, automatic image conversion reaches the parser when DecoderOptions.ColorProfileHandling is Convert; the default Preserve mode avoids that conversion path. The demonstrated impact is memory pressure and input-validation failure, not unhandled process termination. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"7056b49d651734b2","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Api.V3.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Api.V3.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gwg2-r3hj-4w44","versionConstraint":">=1.0.0-beta0001,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-gwg2-r3hj-4w44","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106114","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106114","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"risk":0.18849000000000002,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-gwg2-r3hj-4w44","https://nvd.nist.gov/vuln/detail/CVE-2026-106114","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/8de892a7623aa8a09ba2333b624c8d2eb98325df","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gwg2-r3hj-4w44","description":"ImageSharp: ICC CLUT parsing allocates from unvalidated channel and grid dimensions"},"relatedVulnerabilities":[{"id":"CVE-2026-106114","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106114","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106114","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"urls":["https://github.com/SixLabors/ImageSharp/commit/8de892a7623aa8a09ba2333b624c8d2eb98325df","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-gwg2-r3hj-4w44"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106114","description":"ImageSharp is a 2D graphics library. From 1.0.0-beta0001 until 4.1.2, ICC CLUT parsing calculates allocation sizes from attacker-declared channel and grid dimensions before confirming that the profile contains the declared values. IccDataReader.ReadClutF32 can request a large float array, and earlier public IccProfile.Entries parsing paths can allocate a large jagged representation, from a short truncated profile. In version 4, automatic image conversion reaches the parser when DecoderOptions.ColorProfileHandling is Convert; the default Preserve mode avoids that conversion path. The demonstrated impact is memory pressure and input-validation failure, not unhandled process termination. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"7e5602eec3aa6866","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Core.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Core.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gwg2-r3hj-4w44","versionConstraint":">=1.0.0-beta0001,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-gwg2-r3hj-4w44","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106114","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106114","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"risk":0.18849000000000002,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-gwg2-r3hj-4w44","https://nvd.nist.gov/vuln/detail/CVE-2026-106114","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/8de892a7623aa8a09ba2333b624c8d2eb98325df","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gwg2-r3hj-4w44","description":"ImageSharp: ICC CLUT parsing allocates from unvalidated channel and grid dimensions"},"relatedVulnerabilities":[{"id":"CVE-2026-106114","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106114","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106114","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"urls":["https://github.com/SixLabors/ImageSharp/commit/8de892a7623aa8a09ba2333b624c8d2eb98325df","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-gwg2-r3hj-4w44"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106114","description":"ImageSharp is a 2D graphics library. From 1.0.0-beta0001 until 4.1.2, ICC CLUT parsing calculates allocation sizes from attacker-declared channel and grid dimensions before confirming that the profile contains the declared values. IccDataReader.ReadClutF32 can request a large float array, and earlier public IccProfile.Entries parsing paths can allocate a large jagged representation, from a short truncated profile. In version 4, automatic image conversion reaches the parser when DecoderOptions.ColorProfileHandling is Convert; the default Preserve mode avoids that conversion path. The demonstrated impact is memory pressure and input-validation failure, not unhandled process termination. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"d126fa9a14843a0b","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Host.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Host.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gwg2-r3hj-4w44","versionConstraint":">=1.0.0-beta0001,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-gwg2-r3hj-4w44","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106114","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106114","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"risk":0.18849000000000002,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-gwg2-r3hj-4w44","https://nvd.nist.gov/vuln/detail/CVE-2026-106114","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/8de892a7623aa8a09ba2333b624c8d2eb98325df","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gwg2-r3hj-4w44","description":"ImageSharp: ICC CLUT parsing allocates from unvalidated channel and grid dimensions"},"relatedVulnerabilities":[{"id":"CVE-2026-106114","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106114","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106114","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"urls":["https://github.com/SixLabors/ImageSharp/commit/8de892a7623aa8a09ba2333b624c8d2eb98325df","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-gwg2-r3hj-4w44"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106114","description":"ImageSharp is a 2D graphics library. From 1.0.0-beta0001 until 4.1.2, ICC CLUT parsing calculates allocation sizes from attacker-declared channel and grid dimensions before confirming that the profile contains the declared values. IccDataReader.ReadClutF32 can request a large float array, and earlier public IccProfile.Entries parsing paths can allocate a large jagged representation, from a short truncated profile. In version 4, automatic image conversion reaches the parser when DecoderOptions.ColorProfileHandling is Convert; the default Preserve mode avoids that conversion path. The demonstrated impact is memory pressure and input-validation failure, not unhandled process termination. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"b82005f3f0f7ef42","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.SignalR.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.SignalR.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gwg2-r3hj-4w44","versionConstraint":">=1.0.0-beta0001,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-gwg2-r3hj-4w44","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106114","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106114","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"risk":0.18849000000000002,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-gwg2-r3hj-4w44","https://nvd.nist.gov/vuln/detail/CVE-2026-106114","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/8de892a7623aa8a09ba2333b624c8d2eb98325df","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gwg2-r3hj-4w44","description":"ImageSharp: ICC CLUT parsing allocates from unvalidated channel and grid dimensions"},"relatedVulnerabilities":[{"id":"CVE-2026-106114","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106114","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106114","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"urls":["https://github.com/SixLabors/ImageSharp/commit/8de892a7623aa8a09ba2333b624c8d2eb98325df","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-gwg2-r3hj-4w44"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106114","description":"ImageSharp is a 2D graphics library. From 1.0.0-beta0001 until 4.1.2, ICC CLUT parsing calculates allocation sizes from attacker-declared channel and grid dimensions before confirming that the profile contains the declared values. IccDataReader.ReadClutF32 can request a large float array, and earlier public IccProfile.Entries parsing paths can allocate a large jagged representation, from a short truncated profile. In version 4, automatic image conversion reaches the parser when DecoderOptions.ColorProfileHandling is Convert; the default Preserve mode avoids that conversion path. The demonstrated impact is memory pressure and input-validation failure, not unhandled process termination. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"b7db03e28182d0f4","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gwg2-r3hj-4w44","versionConstraint":">=1.0.0-beta0001,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-gwg2-r3hj-4w44","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106114","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106114","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"risk":0.18849000000000002,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-gwg2-r3hj-4w44","https://nvd.nist.gov/vuln/detail/CVE-2026-106114","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/8de892a7623aa8a09ba2333b624c8d2eb98325df","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gwg2-r3hj-4w44","description":"ImageSharp: ICC CLUT parsing allocates from unvalidated channel and grid dimensions"},"relatedVulnerabilities":[{"id":"CVE-2026-106114","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106114","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106114","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"urls":["https://github.com/SixLabors/ImageSharp/commit/8de892a7623aa8a09ba2333b624c8d2eb98325df","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-gwg2-r3hj-4w44"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106114","description":"ImageSharp is a 2D graphics library. From 1.0.0-beta0001 until 4.1.2, ICC CLUT parsing calculates allocation sizes from attacker-declared channel and grid dimensions before confirming that the profile contains the declared values. IccDataReader.ReadClutF32 can request a large float array, and earlier public IccProfile.Entries parsing paths can allocate a large jagged representation, from a short truncated profile. In version 4, automatic image conversion reaches the parser when DecoderOptions.ColorProfileHandling is Convert; the default Preserve mode avoids that conversion path. The demonstrated impact is memory pressure and input-validation failure, not unhandled process termination. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"d126fa9a14843a0b","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Host.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Host.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wmxv-xphr-5c9g","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-wmxv-xphr-5c9g","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106116","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106116","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"risk":0.18849000000000002,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-wmxv-xphr-5c9g","https://nvd.nist.gov/vuln/detail/CVE-2026-106116","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/92b12d72550ebb6be5b1e22e559c361fd863a6ec","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wmxv-xphr-5c9g","description":"ImageSharp: BigTIFF IFD count can keep a decoder thread in a non-progressing loop"},"relatedVulnerabilities":[{"id":"CVE-2026-106116","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106116","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106116","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"urls":["https://github.com/SixLabors/ImageSharp/commit/92b12d72550ebb6be5b1e22e559c361fd863a6ec","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-wmxv-xphr-5c9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106116","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, ExifReader.ReadValues64 trusts the 64-bit BigTIFF IFD entry count and iterates once per declared entry. When fewer than 20 bytes remain, ExifReader.ReadValue64 returns without advancing the stream or terminating the outer loop, so a small malformed BigTIFF can keep one decoder thread executing for an attacker-controlled duration. This report does not claim worker-pool exhaustion. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"bdf04c568ca09005","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Http.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Http.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wmxv-xphr-5c9g","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-wmxv-xphr-5c9g","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106116","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106116","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"risk":0.18849000000000002,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-wmxv-xphr-5c9g","https://nvd.nist.gov/vuln/detail/CVE-2026-106116","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/92b12d72550ebb6be5b1e22e559c361fd863a6ec","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wmxv-xphr-5c9g","description":"ImageSharp: BigTIFF IFD count can keep a decoder thread in a non-progressing loop"},"relatedVulnerabilities":[{"id":"CVE-2026-106116","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106116","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106116","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"urls":["https://github.com/SixLabors/ImageSharp/commit/92b12d72550ebb6be5b1e22e559c361fd863a6ec","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-wmxv-xphr-5c9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106116","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, ExifReader.ReadValues64 trusts the 64-bit BigTIFF IFD entry count and iterates once per declared entry. When fewer than 20 bytes remain, ExifReader.ReadValue64 returns without advancing the stream or terminating the outer loop, so a small malformed BigTIFF can keep one decoder thread executing for an attacker-controlled duration. This report does not claim worker-pool exhaustion. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"b82005f3f0f7ef42","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.SignalR.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.SignalR.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wmxv-xphr-5c9g","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-wmxv-xphr-5c9g","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106116","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106116","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"risk":0.18849000000000002,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-wmxv-xphr-5c9g","https://nvd.nist.gov/vuln/detail/CVE-2026-106116","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/92b12d72550ebb6be5b1e22e559c361fd863a6ec","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wmxv-xphr-5c9g","description":"ImageSharp: BigTIFF IFD count can keep a decoder thread in a non-progressing loop"},"relatedVulnerabilities":[{"id":"CVE-2026-106116","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106116","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106116","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"urls":["https://github.com/SixLabors/ImageSharp/commit/92b12d72550ebb6be5b1e22e559c361fd863a6ec","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-wmxv-xphr-5c9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106116","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, ExifReader.ReadValues64 trusts the 64-bit BigTIFF IFD entry count and iterates once per declared entry. When fewer than 20 bytes remain, ExifReader.ReadValue64 returns without advancing the stream or terminating the outer loop, so a small malformed BigTIFF can keep one decoder thread executing for an attacker-controlled duration. This report does not claim worker-pool exhaustion. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"b7db03e28182d0f4","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wmxv-xphr-5c9g","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-wmxv-xphr-5c9g","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106116","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106116","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"risk":0.18849000000000002,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-wmxv-xphr-5c9g","https://nvd.nist.gov/vuln/detail/CVE-2026-106116","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/92b12d72550ebb6be5b1e22e559c361fd863a6ec","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wmxv-xphr-5c9g","description":"ImageSharp: BigTIFF IFD count can keep a decoder thread in a non-progressing loop"},"relatedVulnerabilities":[{"id":"CVE-2026-106116","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106116","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106116","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"urls":["https://github.com/SixLabors/ImageSharp/commit/92b12d72550ebb6be5b1e22e559c361fd863a6ec","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-wmxv-xphr-5c9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106116","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, ExifReader.ReadValues64 trusts the 64-bit BigTIFF IFD entry count and iterates once per declared entry. When fewer than 20 bytes remain, ExifReader.ReadValue64 returns without advancing the stream or terminating the outer loop, so a small malformed BigTIFF can keep one decoder thread executing for an attacker-controlled duration. This report does not claim worker-pool exhaustion. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"7056b49d651734b2","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Api.V3.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Api.V3.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wmxv-xphr-5c9g","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-wmxv-xphr-5c9g","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106116","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106116","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"risk":0.18849000000000002,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-wmxv-xphr-5c9g","https://nvd.nist.gov/vuln/detail/CVE-2026-106116","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/92b12d72550ebb6be5b1e22e559c361fd863a6ec","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wmxv-xphr-5c9g","description":"ImageSharp: BigTIFF IFD count can keep a decoder thread in a non-progressing loop"},"relatedVulnerabilities":[{"id":"CVE-2026-106116","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106116","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106116","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"urls":["https://github.com/SixLabors/ImageSharp/commit/92b12d72550ebb6be5b1e22e559c361fd863a6ec","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-wmxv-xphr-5c9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106116","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, ExifReader.ReadValues64 trusts the 64-bit BigTIFF IFD entry count and iterates once per declared entry. When fewer than 20 bytes remain, ExifReader.ReadValue64 returns without advancing the stream or terminating the outer loop, so a small malformed BigTIFF can keep one decoder thread executing for an attacker-controlled duration. This report does not claim worker-pool exhaustion. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"7e5602eec3aa6866","cpes":["cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:sixlabors_imagesharp:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp_.net:3.1.12:*:*:*:*:*:*:*","cpe:2.3:a:six_labors:sixlabors_imagesharp:3.1.12:*:*:*:*:*:*:*"],"name":"SixLabors.ImageSharp","purl":"pkg:nuget/SixLabors.ImageSharp@3.1.12","type":"dotnet","version":"3.1.12","language":"dotnet","licenses":[],"locations":[{"path":"/app/radarr/bin/Radarr.Core.deps.json","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/Radarr.Core.deps.json","annotations":{"evidence":"primary"}},{"path":"/app/radarr/bin/SixLabors.ImageSharp.dll","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/app/radarr/bin/SixLabors.ImageSharp.dll","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wmxv-xphr-5c9g","versionConstraint":">=2.0.0,<=4.1.1 (semantic)"},"matcher":"dotnet-matcher","searchedBy":{"package":{"name":"SixLabors.ImageSharp","version":"3.1.12"},"language":"dotnet","namespace":"github:language:dotnet"}}],"vulnerability":{"id":"GHSA-wmxv-xphr-5c9g","fix":{"state":"fixed","versions":["4.1.2"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"4.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106116","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106116","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"risk":0.18849000000000002,"urls":["https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-wmxv-xphr-5c9g","https://nvd.nist.gov/vuln/detail/CVE-2026-106116","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/commit/92b12d72550ebb6be5b1e22e559c361fd863a6ec","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"],"severity":"Medium","namespace":"github:language:dotnet","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wmxv-xphr-5c9g","description":"ImageSharp: BigTIFF IFD count can keep a decoder thread in a non-progressing loop"},"relatedVulnerabilities":[{"id":"CVE-2026-106116","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106116","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106116","date":"2026-10-08","epss":0.00366,"percentile":0.28364}],"urls":["https://github.com/SixLabors/ImageSharp/commit/92b12d72550ebb6be5b1e22e559c361fd863a6ec","https://github.com/SixLabors/ImageSharp/pull/3187","https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-wmxv-xphr-5c9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106116","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, ExifReader.ReadValues64 trusts the 64-bit BigTIFF IFD entry count and iterates once per declared entry. When fewer than 20 bytes remain, ExifReader.ReadValue64 returns without advancing the stream or terminating the outer loop, so a small malformed BigTIFF can keep one decoder thread executing for an attacker-controlled duration. This report does not claim worker-pool exhaustion. This issue is fixed in version 4.1.2."}]},{"artifact":{"id":"fef07e9c95ea2bda","cpes":["cpe:2.3:a:busybox:busybox:1.37.0-r31:*:*:*:*:*:*:*"],"name":"busybox","purl":"pkg:apk/alpine/busybox@1.37.0-r31?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"1.37.0-r31","language":"","licenses":["GPL-2.0-only"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/busybox"},{"path":"/etc"},{"path":"/etc/securetty"},{"path":"/etc/busybox-paths.d"},{"path":"/etc/busybox-paths.d/busybox"},{"path":"/etc/logrotate.d"},{"path":"/etc/logrotate.d/acpid"},{"path":"/etc/network"},{"path":"/etc/network/if-down.d"},{"path":"/etc/network/if-post-down.d"},{"path":"/etc/network/if-post-up.d"},{"path":"/etc/network/if-pre-down.d"},{"path":"/etc/network/if-pre-up.d"},{"path":"/etc/network/if-up.d"},{"path":"/etc/network/if-up.d/dad"},{"path":"/etc/udhcpc"},{"path":"/etc/udhcpc/udhcpc.conf"},{"path":"/sbin"},{"path":"/usr"},{"path":"/usr/sbin"},{"path":"/usr/share"},{"path":"/usr/share/udhcpc"},{"path":"/usr/share/udhcpc/default.script"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"busybox"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-60876","versionConstraint":"<= 1.37.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:busybox:busybox:1.37.0:*:*:*:*:*:*:*"],"package":{"name":"busybox","version":"1.37.0-r31"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-60876","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-60876","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-60876","date":"2026-10-08","epss":0.00291,"percentile":0.19874}],"risk":0.16732499999999997,"urls":["https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092","https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm","https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-60876","description":"BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20)."},"relatedVulnerabilities":[]},{"artifact":{"id":"915155597fcdee9a","cpes":["cpe:2.3:a:busybox-binsh:busybox-binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox-binsh:busybox_binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox_binsh:busybox-binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox_binsh:busybox_binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox:busybox-binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox:busybox_binsh:1.37.0-r31:*:*:*:*:*:*:*"],"name":"busybox-binsh","purl":"pkg:apk/alpine/busybox-binsh@1.37.0-r31?arch=x86_64&distro=alpine-3.24.2&upstream=busybox","type":"apk","version":"1.37.0-r31","language":"","licenses":["GPL-2.0-only"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/sh"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"busybox"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-60876","versionConstraint":"<= 1.37.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:busybox:busybox:1.37.0:*:*:*:*:*:*:*"],"package":{"name":"busybox","version":"1.37.0-r31"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-60876","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-60876","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-60876","date":"2026-10-08","epss":0.00291,"percentile":0.19874}],"risk":0.16732499999999997,"urls":["https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092","https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm","https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-60876","description":"BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20)."},"relatedVulnerabilities":[]},{"artifact":{"id":"8a9ef44e1018f213","cpes":["cpe:2.3:a:ssl-client:ssl-client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl-client:ssl_client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl_client:ssl-client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl_client:ssl_client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl:ssl-client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl:ssl_client:1.37.0-r31:*:*:*:*:*:*:*"],"name":"ssl_client","purl":"pkg:apk/alpine/ssl_client@1.37.0-r31?arch=x86_64&distro=alpine-3.24.2&upstream=busybox","type":"apk","version":"1.37.0-r31","language":"","licenses":["GPL-2.0-only"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssl_client"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"busybox"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-60876","versionConstraint":"<= 1.37.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:busybox:busybox:1.37.0:*:*:*:*:*:*:*"],"package":{"name":"busybox","version":"1.37.0-r31"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-60876","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-60876","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-60876","date":"2026-10-08","epss":0.00291,"percentile":0.19874}],"risk":0.16732499999999997,"urls":["https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092","https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm","https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-60876","description":"BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20)."},"relatedVulnerabilities":[]},{"artifact":{"id":"6921667c3af65467","cpes":["cpe:2.3:a:coreutils:coreutils:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:apk/alpine/coreutils@9.11-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/base64"},{"path":"/bin/cat"},{"path":"/bin/chgrp"},{"path":"/bin/chmod"},{"path":"/bin/chown"},{"path":"/bin/coreutils"},{"path":"/bin/cp"},{"path":"/bin/date"},{"path":"/bin/dd"},{"path":"/bin/df"},{"path":"/bin/echo"},{"path":"/bin/false"},{"path":"/bin/link"},{"path":"/bin/ln"},{"path":"/bin/ls"},{"path":"/bin/mkdir"},{"path":"/bin/mknod"},{"path":"/bin/mktemp"},{"path":"/bin/mv"},{"path":"/bin/nice"},{"path":"/bin/printenv"},{"path":"/bin/pwd"},{"path":"/bin/rm"},{"path":"/bin/rmdir"},{"path":"/bin/sleep"},{"path":"/bin/stat"},{"path":"/bin/stty"},{"path":"/bin/sync"},{"path":"/bin/touch"},{"path":"/bin/true"},{"path":"/bin/uname"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/["},{"path":"/usr/bin/b2sum"},{"path":"/usr/bin/base32"},{"path":"/usr/bin/basename"},{"path":"/usr/bin/basenc"},{"path":"/usr/bin/cksum"},{"path":"/usr/bin/comm"},{"path":"/usr/bin/csplit"},{"path":"/usr/bin/cut"},{"path":"/usr/bin/dir"},{"path":"/usr/bin/dircolors"},{"path":"/usr/bin/dirname"},{"path":"/usr/bin/du"},{"path":"/usr/bin/expand"},{"path":"/usr/bin/expr"},{"path":"/usr/bin/factor"},{"path":"/usr/bin/fold"},{"path":"/usr/bin/head"},{"path":"/usr/bin/hostid"},{"path":"/usr/bin/id"},{"path":"/usr/bin/install"},{"path":"/usr/bin/join"},{"path":"/usr/bin/logname"},{"path":"/usr/bin/md5sum"},{"path":"/usr/bin/mkfifo"},{"path":"/usr/bin/nl"},{"path":"/usr/bin/nohup"},{"path":"/usr/bin/nproc"},{"path":"/usr/bin/numfmt"},{"path":"/usr/bin/od"},{"path":"/usr/bin/paste"},{"path":"/usr/bin/pathchk"},{"path":"/usr/bin/pinky"},{"path":"/usr/bin/pr"},{"path":"/usr/bin/printf"},{"path":"/usr/bin/ptx"},{"path":"/usr/bin/readlink"},{"path":"/usr/bin/realpath"},{"path":"/usr/bin/seq"},{"path":"/usr/bin/sha1sum"},{"path":"/usr/bin/sha224sum"},{"path":"/usr/bin/sha256sum"},{"path":"/usr/bin/sha384sum"},{"path":"/usr/bin/shred"},{"path":"/usr/bin/shuf"},{"path":"/usr/bin/sort"},{"path":"/usr/bin/split"},{"path":"/usr/bin/stdbuf"},{"path":"/usr/bin/sum"},{"path":"/usr/bin/tac"},{"path":"/usr/bin/tail"},{"path":"/usr/bin/tee"},{"path":"/usr/bin/test"},{"path":"/usr/bin/timeout"},{"path":"/usr/bin/tr"},{"path":"/usr/bin/truncate"},{"path":"/usr/bin/tsort"},{"path":"/usr/bin/tty"},{"path":"/usr/bin/unexpand"},{"path":"/usr/bin/uniq"},{"path":"/usr/bin/unlink"},{"path":"/usr/bin/users"},{"path":"/usr/bin/vdir"},{"path":"/usr/bin/wc"},{"path":"/usr/bin/who"},{"path":"/usr/bin/whoami"},{"path":"/usr/bin/yes"},{"path":"/usr/libexec"},{"path":"/usr/libexec/coreutils"},{"path":"/usr/libexec/coreutils/libstdbuf.so"},{"path":"/usr/sbin"},{"path":"/usr/sbin/chroot"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56391","versionConstraint":">= 9.5, <= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.0884925,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[]},{"artifact":{"id":"16361c4de507bb4c","cpes":["cpe:2.3:a:coreutils-env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_env:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-env","purl":"pkg:apk/alpine/coreutils-env@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/env"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56391","versionConstraint":">= 9.5, <= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.0884925,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c43a637992609b6","cpes":["cpe:2.3:a:coreutils-fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-fmt","purl":"pkg:apk/alpine/coreutils-fmt@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/fmt"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56391","versionConstraint":">= 9.5, <= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.0884925,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[]},{"artifact":{"id":"157238390cea3b89","cpes":["cpe:2.3:a:coreutils-sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-sha512sum","purl":"pkg:apk/alpine/coreutils-sha512sum@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/sha512sum"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56391","versionConstraint":">= 9.5, <= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.0884925,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[]},{"artifact":{"id":"6921667c3af65467","cpes":["cpe:2.3:a:coreutils:coreutils:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:apk/alpine/coreutils@9.11-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/base64"},{"path":"/bin/cat"},{"path":"/bin/chgrp"},{"path":"/bin/chmod"},{"path":"/bin/chown"},{"path":"/bin/coreutils"},{"path":"/bin/cp"},{"path":"/bin/date"},{"path":"/bin/dd"},{"path":"/bin/df"},{"path":"/bin/echo"},{"path":"/bin/false"},{"path":"/bin/link"},{"path":"/bin/ln"},{"path":"/bin/ls"},{"path":"/bin/mkdir"},{"path":"/bin/mknod"},{"path":"/bin/mktemp"},{"path":"/bin/mv"},{"path":"/bin/nice"},{"path":"/bin/printenv"},{"path":"/bin/pwd"},{"path":"/bin/rm"},{"path":"/bin/rmdir"},{"path":"/bin/sleep"},{"path":"/bin/stat"},{"path":"/bin/stty"},{"path":"/bin/sync"},{"path":"/bin/touch"},{"path":"/bin/true"},{"path":"/bin/uname"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/["},{"path":"/usr/bin/b2sum"},{"path":"/usr/bin/base32"},{"path":"/usr/bin/basename"},{"path":"/usr/bin/basenc"},{"path":"/usr/bin/cksum"},{"path":"/usr/bin/comm"},{"path":"/usr/bin/csplit"},{"path":"/usr/bin/cut"},{"path":"/usr/bin/dir"},{"path":"/usr/bin/dircolors"},{"path":"/usr/bin/dirname"},{"path":"/usr/bin/du"},{"path":"/usr/bin/expand"},{"path":"/usr/bin/expr"},{"path":"/usr/bin/factor"},{"path":"/usr/bin/fold"},{"path":"/usr/bin/head"},{"path":"/usr/bin/hostid"},{"path":"/usr/bin/id"},{"path":"/usr/bin/install"},{"path":"/usr/bin/join"},{"path":"/usr/bin/logname"},{"path":"/usr/bin/md5sum"},{"path":"/usr/bin/mkfifo"},{"path":"/usr/bin/nl"},{"path":"/usr/bin/nohup"},{"path":"/usr/bin/nproc"},{"path":"/usr/bin/numfmt"},{"path":"/usr/bin/od"},{"path":"/usr/bin/paste"},{"path":"/usr/bin/pathchk"},{"path":"/usr/bin/pinky"},{"path":"/usr/bin/pr"},{"path":"/usr/bin/printf"},{"path":"/usr/bin/ptx"},{"path":"/usr/bin/readlink"},{"path":"/usr/bin/realpath"},{"path":"/usr/bin/seq"},{"path":"/usr/bin/sha1sum"},{"path":"/usr/bin/sha224sum"},{"path":"/usr/bin/sha256sum"},{"path":"/usr/bin/sha384sum"},{"path":"/usr/bin/shred"},{"path":"/usr/bin/shuf"},{"path":"/usr/bin/sort"},{"path":"/usr/bin/split"},{"path":"/usr/bin/stdbuf"},{"path":"/usr/bin/sum"},{"path":"/usr/bin/tac"},{"path":"/usr/bin/tail"},{"path":"/usr/bin/tee"},{"path":"/usr/bin/test"},{"path":"/usr/bin/timeout"},{"path":"/usr/bin/tr"},{"path":"/usr/bin/truncate"},{"path":"/usr/bin/tsort"},{"path":"/usr/bin/tty"},{"path":"/usr/bin/unexpand"},{"path":"/usr/bin/uniq"},{"path":"/usr/bin/unlink"},{"path":"/usr/bin/users"},{"path":"/usr/bin/vdir"},{"path":"/usr/bin/wc"},{"path":"/usr/bin/who"},{"path":"/usr/bin/whoami"},{"path":"/usr/bin/yes"},{"path":"/usr/libexec"},{"path":"/usr/libexec/coreutils"},{"path":"/usr/libexec/coreutils/libstdbuf.so"},{"path":"/usr/sbin"},{"path":"/usr/sbin/chroot"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56392","versionConstraint":"= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56392","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56392","cwe":"CWE-122","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56392","date":"2026-10-08","epss":0.00186,"percentile":0.07525}],"risk":0.083235,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56392","description":"GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"},"relatedVulnerabilities":[]},{"artifact":{"id":"16361c4de507bb4c","cpes":["cpe:2.3:a:coreutils-env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_env:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-env","purl":"pkg:apk/alpine/coreutils-env@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/env"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56392","versionConstraint":"= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56392","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56392","cwe":"CWE-122","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56392","date":"2026-10-08","epss":0.00186,"percentile":0.07525}],"risk":0.083235,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56392","description":"GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"},"relatedVulnerabilities":[]},{"artifact":{"id":"0c43a637992609b6","cpes":["cpe:2.3:a:coreutils-fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-fmt","purl":"pkg:apk/alpine/coreutils-fmt@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/fmt"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56392","versionConstraint":"= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56392","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56392","cwe":"CWE-122","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56392","date":"2026-10-08","epss":0.00186,"percentile":0.07525}],"risk":0.083235,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56392","description":"GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"},"relatedVulnerabilities":[]},{"artifact":{"id":"157238390cea3b89","cpes":["cpe:2.3:a:coreutils-sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-sha512sum","purl":"pkg:apk/alpine/coreutils-sha512sum@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/sha512sum"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:60835c04508c8df784615465dfd04be26fd3099726c558936f146a0fb2205c97","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56392","versionConstraint":"= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56392","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56392","cwe":"CWE-122","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56392","date":"2026-10-08","epss":0.00186,"percentile":0.07525}],"risk":0.083235,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56392","description":"GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"},"relatedVulnerabilities":[]}],"grade":"F","score":"0.00","as_of":"2026-10-09T22:46:50.518Z","grype_db_version":"2026-10-09T06:32:32.000Z"}